nerdexam
Palo_Alto_NetworksPalo_Alto_Networks

PCNSE · Question #848

PCNSE Question #848: Real Exam Question with Answer & Explanation

Sign in or unlock PCNSE to reveal the answer and full explanation for question #848. The question stem and answer options stay visible for context.

Submitted by fernanda_arg· Apr 18, 2026Deploy and Configure

Question

A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the firewall team is reviewing the cryptography used by any devices they manage. The firewall architect is reviewing the Palo Alto Networks NGFWs for their VPN tunnel configurations. It is noted in the review that the NGFWs are running PAN-OS 11.2. Which two NGFW settings could the firewall architect recommend to deploy protections per the new policy? (Choose two)

Options

  • AIKEv1 only to deactivate the use of public key encryption
  • BIKEv2 with Hybrid Key exchange
  • CIKEv2 with Post-Quantum Pre-shared Keys
  • DIPsec with Hybrid ID exchange

Unlock PCNSE to see the answer

You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Post-Quantum Cryptography#IKEv2#VPN Configuration#PAN-OS 11.2 Features
Full PCNSE PracticeBrowse All PCNSE Questions