Basic Concept: PAN-OS supports post-quantum VPN options for IKEv2 through post-quantum pre-shared keys and post-quantum key encapsulation mechanisms configured in IKE/IKE Crypto settings.
Why A and D are Correct: The correct actions enable IKEv2 with PQ PPK and configure PQ KEM with crypto-profile rounds, which are the PAN-OS mechanisms for quantum-resistant VPN key establishment.
Why B is Wrong: Ensure Authentication is set to “certificate,” then import a post-quantum derived certificate. relates to VPN configuration, but it does not address the specific PAN-OS requirement for selectors, tunnel interface functions, routing, or Security policy in this scenario.
Why C is Wrong: Select IKE v2 Preferred, enable the Advanced Options PQ KEM, then add one or more “Rounds.” relates to VPN configuration, but it does not address the specific PAN-OS requirement for selectors, tunnel interface functions, routing, or Security policy in this scenario.
Submit