PCNSE · Question #848
A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the firewall team is…
The correct answer is B. IKEv2 with Hybrid Key exchange C. IKEv2 with Post-Quantum Pre-shared Keys. Quantum-related attack protection requires cryptography resistant to quantum computing, such as post-quantum algorithms. In PAN-OS 11.2, IKEv2 with Hybrid Key Exchange (Option B) combines classical and quantum-resistant algorithms for key exchange, enhancing VPN security. IKEv2…
Question
A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the firewall team is reviewing the cryptography used by any devices they manage. The firewall architect is reviewing the Palo Alto Networks NGFWs for their VPN tunnel configurations. It is noted in the review that the NGFWs are running PAN-OS 11.2. Which two NGFW settings could the firewall architect recommend to deploy protections per the new policy? (Choose two)
Options
- AIKEv1 only to deactivate the use of public key encryption
- BIKEv2 with Hybrid Key exchange
- CIKEv2 with Post-Quantum Pre-shared Keys
- DIPsec with Hybrid ID exchange
How the community answered
(37 responses)- A16% (6)
- B73% (27)
- D11% (4)
Explanation
Quantum-related attack protection requires cryptography resistant to quantum computing, such as post-quantum algorithms. In PAN-OS 11.2, IKEv2 with Hybrid Key Exchange (Option B) combines classical and quantum-resistant algorithms for key exchange, enhancing VPN security. IKEv2 with Post-Quantum Pre-shared Keys (PPK) (Option C) uses pre-shared keys designed to resist quantum attacks, supported in IKEv2 configurations.
Topics
Community Discussion
No community discussion yet for this question.