PCNSE Secure Access and VPN Practice Question
Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?
⚠ Common exam trap
Test-takers frequently confuse user authentication methods (RADIUS, SAML, LDAP) with device-to-device IPsec tunnel authentication, which only supports pre-shared keys and certificates on Palo Alto firewalls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate
Option A (Certificate) is correct because Palo Alto Networks firewalls support certificate-based authentication for IPSec VPN IKE peers, where each firewall presents an X.509 certificate and validates the peer's certificate against a trusted CA profile during IKE Phase 1. Option E (Pre-shared key) is correct because PSK authentication is a native, commonly used IKE Phase 1 authentication method for site-to-site IPSec tunnels between Palo Alto firewalls, configured under the IKE Gateway's authentication settings. Options B (RADIUS), C (SAML), and D (LDAP) are not valid IKE peer authentication methods for IPSec tunnel establishment; these are user authentication mechanisms used for GlobalProtect, administrative access, or User-ID, and they operate at the application/user layer rather than authenticating the IKE gateway peer itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Certificate
Why this is correct
Certificate-based authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, using X.509 certificates exchanged during IKE to authenticate peers. This satisfies the scenario's requirement for a supported method, since both firewalls can validate each other's identity via a trusted certificate authority rather than pre-shared keys.
- ✗
RADIUS
Why it's wrong here
RADIUS authenticates users against an external AAA server; it does not authenticate a peer firewall during IKE, where pre-shared keys, certificates or XAuth apply. RADIUS is correct for granting remote users or administrators access, not for establishing the tunnel itself between two firewalls.
- ✗
SAML
Why it's wrong here
SAML is a browser-based single sign-on federation standard for user sessions, not a mechanism two firewalls use to authenticate each other during IKE negotiation. It is the right choice for authenticating users to web applications or GlobalProtect portals, not for site-to-site tunnel peer authentication.
- ✗
LDAP
Why it's wrong here
LDAP is a directory lookup protocol for user authentication, not a peer authentication method for establishing an IPSec tunnel between firewalls. It is correctly used for GlobalProtect or administrative login against a directory, where user credentials rather than device certificates or pre-shared keys are verified.
- ✓
Pre-shared key
Why this is correct
Pre-shared key authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, satisfying the site-to-site tunnel setup requirement. Both peers authenticate using the same secret value configured locally, with no certificate infrastructure needed. This makes it a valid method alongside certificate-based authentication for firewall-to-firewall IPSec VPN establishment.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.