PCNSE Practice Question: Securing Users and Applications with Authentication
A company has configured multi-factor authentication (MFA) via an authentication sequence using LDAP and RADIUS. Users authenticate successfully with LDAP but the MFA prompt from RADIUS does not appear. What is the most likely cause?
⚠ Common exam trap
In Palo Alto Networks, the default behavior for authentication sequences is 'continue on failure', which means the firewall only moves to the next authentication factor if the current one fails. If LDAP succeeds, it never attempts RADIUS. Candidates often assume that simply adding multiple methods enforces all factors, but the sequence must be set to 'continue on success' or 'require all' to enforce MFA properly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authentication sequence must be configured to 'require all' or 'continue on success' to enforce each factor.
When using an authentication sequence in Palo Alto Networks firewalls, the sequence must be configured with the 'require all' or 'continue on success' option to enforce each factor in order. With 'continue on success', after LDAP succeeds, the firewall proceeds to the next factor (RADIUS MFA). If the sequence is set to 'continue on failure' (the default), the firewall stops after the first successful authentication and never attempts the second factor, so the MFA prompt never appears.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The authentication sequence must be configured to 'require all' or 'continue on success' to enforce each factor.
Why this is correct
To require all factors in the sequence, the sequence type must be set to 'require all' or 'continue on success' so each factor is attempted regardless of previous success.
- ✗
The RADIUS server profile has the wrong shared secret.
Why it's wrong here
This would cause RADIUS authentication to fail, but the LDAP success would still complete the sequence if set to continue on failure.
- ✗
The authentication policy only covers HTTP applications.
Why it's wrong here
The authentication policy's application match does not affect which authentication factors are invoked.
- ✗
The authentication sequence is set to 'continue on failure' and the LDAP authentication succeeds.
Why it's wrong here
'Continue on failure' means if the first factor fails, it tries the next. If LDAP succeeds, the sequence stops and RADIUS is never attempted.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.