nerdexam
Palo_Alto_Networks

PCNSE · Question #848

A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the firewall team is…

The correct answer is B. IKEv2 with Hybrid Key exchange C. IKEv2 with Post-Quantum Pre-shared Keys. Quantum-related attack protection requires cryptography resistant to quantum computing, such as post-quantum algorithms. In PAN-OS 11.2, IKEv2 with Hybrid Key Exchange (Option B) combines classical and quantum-resistant algorithms for key exchange, enhancing VPN security. IKEv2…

Submitted by fernanda_arg· Apr 18, 2026Deploy and Configure

Question

A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the firewall team is reviewing the cryptography used by any devices they manage. The firewall architect is reviewing the Palo Alto Networks NGFWs for their VPN tunnel configurations. It is noted in the review that the NGFWs are running PAN-OS 11.2. Which two NGFW settings could the firewall architect recommend to deploy protections per the new policy? (Choose two)

Options

  • AIKEv1 only to deactivate the use of public key encryption
  • BIKEv2 with Hybrid Key exchange
  • CIKEv2 with Post-Quantum Pre-shared Keys
  • DIPsec with Hybrid ID exchange

How the community answered

(37 responses)
  • A
    16% (6)
  • B
    73% (27)
  • D
    11% (4)

Explanation

Quantum-related attack protection requires cryptography resistant to quantum computing, such as post-quantum algorithms. In PAN-OS 11.2, IKEv2 with Hybrid Key Exchange (Option B) combines classical and quantum-resistant algorithms for key exchange, enhancing VPN security. IKEv2 with Post-Quantum Pre-shared Keys (PPK) (Option C) uses pre-shared keys designed to resist quantum attacks, supported in IKEv2 configurations.

Topics

#Post-Quantum Cryptography#IKEv2#VPN Configuration#PAN-OS 11.2 Features

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice