Courseiva
Secure Access and VPN →easyMultiple Choice

PCNSE Secure Access and VPN Practice Question

A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?

⚠ Common exam trap

The trap here is focusing on authentication or routing issues when the user can already connect, overlooking the need for a security policy to permit access to internal resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security policy allowing traffic from the GlobalProtect zone to the internal zone is missing or misconfigured.

In GlobalProtect, after a user connects, their traffic is subject to security policies. The GlobalProtect zone is typically used for incoming VPN traffic. A security policy must allow traffic from the GlobalProtect zone to the internal zone or resources. Without this policy, the user can authenticate and establish a tunnel but cannot access internal resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The GlobalProtect portal is not configured to push the correct routes to the clients.

    Why it's wrong here

    If the portal did not push routes, users might not have access to internal networks, but they would still be able to connect. However, the question states they cannot access any internal resources, which could be due to routing. But the more likely cause is a missing security policy, as routing issues would typically affect all traffic, not just internal resources.

  • ✗

    The GlobalProtect gateway is not configured with a certificate for SSL/TLS.

    Why it's wrong here

    If the gateway lacked a certificate, SSL/TLS connections would fail, and users would not be able to connect. Since users can connect, the certificate is properly configured. This is not the cause of the access issue.

  • ✓

    The security policy allowing traffic from the GlobalProtect zone to the internal zone is missing or misconfigured.

    Why this is correct

    After a user connects via GlobalProtect, traffic from the user is placed in a security zone (typically the GlobalProtect zone). A security policy must explicitly allow traffic from that zone to the internal resources. If the policy is missing or incorrect, the user can connect but cannot access resources. This is a common oversight.

  • ✗

    The LDAP authentication profile is not properly mapped to the GlobalProtect gateway.

    Why it's wrong here

    If the LDAP authentication profile were not mapped, the user would not be able to authenticate at all. Since users can authenticate and connect, the authentication profile is working. The issue is likely with authorization, not authentication.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.