Courseiva

PCNSA Device Management and Services Practice Question

An administrator needs to allow administrators to authenticate to the firewall's web interface using an external LDAP directory at ldap.corp.example.com, while still allowing a local break-glass account. The directory uses a bind DN of cn=svc-bind,ou=service,dc=corp,dc=example,dc=com. After configuring the LDAP server profile under Device > Server Profiles > LDAP, authentication still fails for directory users. Which additional step is required?

⚠ Common exam trap

The trap here is assuming that defining an LDAP server profile is sufficient to enable directory logins, when an authentication profile must also be created and applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an authentication profile that references the LDAP server profile and assign it to the management interface under Device > Setup > Management > Authentication Settings.

LDAP authentication on PAN-OS requires two objects: a server profile describing the directory connection, and an authentication profile that references it and defines the login method and permitted groups. Assigning the authentication profile to the management interface enables directory logins for the web UI. Local accounts remain available unless explicitly disabled, which preserves break-glass access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the LDAP server to the firewall's DNS server list under Device > Setup > Services so the hostname ldap.corp.example.com resolves for authentication.

    Why it's wrong here

    DNS resolution is necessary if the LDAP server profile uses a hostname, but the firewall's management DNS list is typically already configured and resolution is not the missing link in this scenario. Even with correct name resolution, the absence of an authentication profile means the web UI never attempts LDAP authentication. Adding DNS entries does not create the login binding.

  • ✗

    Enable 'LDAP Authentication' under Device > Setup > Management > Management Interface Settings to activate directory logins for the web UI.

    Why it's wrong here

    There is no standalone 'LDAP Authentication' toggle in the management interface settings; authentication is activated by assigning an authentication profile. The server profile alone does not trigger LDAP logins. The administrator must create an authentication profile that references the LDAP server profile and apply it to the management interface, which is the actual missing configuration.

  • ✗

    Import the LDAP server's root CA certificate under Device > Certificate Management so the firewall can validate the bind DN.

    Why it's wrong here

    Importing a CA certificate is only needed when LDAP is used over TLS and the server certificate must be validated. It does not enable authentication on its own, and the bind DN is validated by the directory, not by a certificate. Without an authentication profile referencing the server profile, logins still fail even with a trusted certificate present.

  • ✓

    Create an authentication profile that references the LDAP server profile and assign it to the management interface under Device > Setup > Management > Authentication Settings.

    Why this is correct

    An LDAP server profile defines how to reach the directory, but it does not by itself enable authentication. An authentication profile binds the server profile to a login method and can include an allow list of permitted groups. Assigning that authentication profile to the management interface activates directory logins for the web UI while preserving local accounts for break-glass access.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.