Courseiva
Secure Access and VPN →easyMultiple Select

PCNSE Secure Access and VPN Practice Question

Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?

⚠ Common exam trap

Test-takers frequently confuse user authentication methods (RADIUS, SAML, LDAP) with device-to-device IPsec tunnel authentication, which only supports pre-shared keys and certificates on Palo Alto firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate

Option A (Certificate) is correct because Palo Alto Networks firewalls support certificate-based authentication for IPSec VPN IKE peers, where each firewall presents an X.509 certificate and validates the peer's certificate against a trusted CA profile during IKE Phase 1. Option E (Pre-shared key) is correct because PSK authentication is a native, commonly used IKE Phase 1 authentication method for site-to-site IPSec tunnels between Palo Alto firewalls, configured under the IKE Gateway's authentication settings. Options B (RADIUS), C (SAML), and D (LDAP) are not valid IKE peer authentication methods for IPSec tunnel establishment; these are user authentication mechanisms used for GlobalProtect, administrative access, or User-ID, and they operate at the application/user layer rather than authenticating the IKE gateway peer itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Certificate

    Why this is correct

    Certificate-based authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, using X.509 certificates exchanged during IKE to authenticate peers. This satisfies the scenario's requirement for a supported method, since both firewalls can validate each other's identity via a trusted certificate authority rather than pre-shared keys.

  • ✗

    RADIUS

    Why it's wrong here

    RADIUS authenticates users against an external AAA server; it does not authenticate a peer firewall during IKE, where pre-shared keys, certificates or XAuth apply. RADIUS is correct for granting remote users or administrators access, not for establishing the tunnel itself between two firewalls.

  • ✗

    SAML

    Why it's wrong here

    SAML is a browser-based single sign-on federation standard for user sessions, not a mechanism two firewalls use to authenticate each other during IKE negotiation. It is the right choice for authenticating users to web applications or GlobalProtect portals, not for site-to-site tunnel peer authentication.

  • ✗

    LDAP

    Why it's wrong here

    LDAP is a directory lookup protocol for user authentication, not a peer authentication method for establishing an IPSec tunnel between firewalls. It is correctly used for GlobalProtect or administrative login against a directory, where user credentials rather than device certificates or pre-shared keys are verified.

  • ✓

    Pre-shared key

    Why this is correct

    Pre-shared key authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, satisfying the site-to-site tunnel setup requirement. Both peers authenticate using the same secret value configured locally, with no certificate infrastructure needed. This makes it a valid method alongside certificate-based authentication for firewall-to-firewall IPSec VPN establishment.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.