Be able to select the correct SSO methods, build authentication policy rules for multi-zone designs, and predict enforcement for unknown users. The single most important thing: know which methods provide SSO and how authentication policy handles unidentified source users.
Start practicing
Securing Users and Applications with Authentication — choose a session length
Free · No account required
Domain overview
This domain covers how PAN-OS identifies users and enforces policy against them: authentication profiles, authentication policy rules, SSO via Kerberos and SAML, multi-factor authentication, and GlobalProtect components. Questions are scenario-based, asking you to pick valid SSO methods, design authentication policies across zones, and predict enforcement when user identity is unknown.
Exam objectives
Kerberos and SAML as SSO methods feeding User-ID and authentication policy
Authentication policy rules matching source zone, source user, and destination, with actions like web-form or browser-challenge
User-ID agents, Terminal Services agents, and GlobalProtect for mapping IP addresses to usernames
GlobalProtect infrastructure components: portals, gateways, and agents, plus their authentication and HIP roles
Assuming all authentication methods support SSO; only Kerberos and SAML do, while local database and RADIUS/LDAP alone do not.
Forgetting that unknown source-user traffic hits authentication policy rules and can be challenged or denied rather than silently allowed.
Confusing GlobalProtect portal and gateway roles, and treating the agent as a server-side infrastructure component instead of the endpoint client.
Click any question to see the full explanation and answer options, or start a focused practice session above.
After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?
2An organization has deployed GlobalProtect with certificate authentication. Users on macOS report that after updating their client, they cannot connect and see error 'Certificate validation failed: The certificate hash does not match.' What is the most likely cause?
3Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?
4Which THREE factors should be considered when designing an authentication policy for a multi-zone environment with varied security requirements? (Choose THREE.)
5Arrange the steps to deploy a new Panorama template to a managed firewall.
6Match each security profile type to its purpose.
7A company has configured multi-factor authentication (MFA) via an authentication sequence using LDAP and RADIUS. Users authenticate successfully with LDAP but the MFA prompt from RADIUS does not appear. What is the most likely cause?
8A company wants to authenticate users who are accessing internal applications from the internet through a firewall. The users should be prompted once per session. Which authentication solution best meets this requirement?
9An administrator has configured an authentication profile with LDAP and sets the authentication sequence to 'continue on failure'. A user enters an incorrect password first, then correct. Will the user be authenticated?
10Which of the following is required for SAML-based single sign-on to work with a Palo Alto Networks firewall acting as the service provider?
11A network engineer is troubleshooting an authentication issue where users in a specific group are not being prompted for credentials, even though the authentication policy matches their traffic. The firewall logs show that the traffic is allowed by the security policy. What is the most likely cause?
12Refer to the exhibit. A user at IP 10.10.1.11 is unable to access internal resources that require authentication. The firewall logs show 'no user mapping' for traffic from this IP. Which step should the administrator take first?
13An administrator wants to enforce authentication for SSL decrypted traffic so that only authenticated users can access decrypted content. Which firewall feature should be configured?
14Users are unable to authenticate via Captive Portal. The firewall receives authentication requests but they time out. What should be checked first?
15To reduce the number of authentication prompts for users accessing multiple applications through the firewall, which configuration is recommended?
16A company needs to authenticate remote users accessing internal web applications via GlobalProtect portal and wants to use SAML with Azure AD for MFA. Which component must be configured on the firewall?
17Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)
18Which TWO are prerequisites for using Authentication Policy? (Choose two.)
19Refer to the exhibit. What happens when a user with an unknown identity (source-user unknown) tries to access resources in 192.168.1.0/24?
20Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?
21An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?
22A company wants to enforce multi-factor authentication (MFA) for all administrative access to the Palo Alto Networks firewall. They have a RADIUS server configured with MFA capability (e.g., RSA SecurID). The firewall is currently using local authentication for admin accounts. What must be configured to enforce MFA for admin access?
23A company wants to enforce multi-factor authentication (MFA) for employees accessing a specific internal application through the firewall. Which two configurations are required on the Palo Alto Networks firewall? (Choose two.)
24A network security engineer is configuring an authentication profile on a Palo Alto Networks firewall to allow administrators to log in using their Active Directory credentials. The engineer wants to ensure that only members of the 'NetOps' group can access the firewall. Which setting in the authentication profile should be configured to enforce this?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to select the correct SSO methods, build authentication policy rules for multi-zone designs, and predict enforcement for unknown users. The single most important thing: know which methods provide SSO and how authentication policy handles unidentified source users.
The Courseiva PCNSE question bank contains 24 questions in the Securing Users and Applications with Authentication domain, covering the 6% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Users and Applications with Authentication domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included