PCNSE Practice Question: Securing Users and Applications with Authentication
A company wants to enforce multi-factor authentication (MFA) for employees accessing a specific internal application through the firewall. Which two configurations are required on the Palo Alto Networks firewall? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse authentication policy rules with security policy rules, or assume that MFA always requires GlobalProtect or SAML, when in fact the firewall can enforce MFA directly via captive portal using an authentication profile and policy rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define an authentication profile that includes an MFA method
Option A is correct because an authentication profile on the Palo Alto Networks firewall defines the authentication methods, including MFA (such as RADIUS with OTP, or a SAML/MFA provider), and is the object that the firewall uses to challenge users for credentials and a second factor. Option C is correct because an authentication policy rule is what actually enforces authentication for matching traffic; it references the authentication profile and can be scoped to the specific internal application (via destination/URL category or application), so without this rule no MFA challenge is triggered. Option B is not required because a SAML identity provider is only one possible MFA mechanism and is not mandatory for enforcing MFA; the firewall can use other methods such as RADIUS with OTP. Option D is not required because GlobalProtect is a remote-access VPN/client solution, not a prerequisite for authenticating users to an internal application through the firewall. Option E is not required because SSL decryption is used for inspecting encrypted traffic, not for enforcing MFA authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define an authentication profile that includes an MFA method
Why this is correct
An authentication profile defines the authentication service and MFA factors the firewall uses to verify users. Referencing it in an authentication policy enforces MFA for the internal application, satisfying the stem's requirement to enforce multi-factor authentication for that specific application.
- ✗
Configure a SAML identity provider
Why it's wrong here
Authentication policy with MFA requires the firewall to act as a SAML service provider, referencing an external identity provider; configuring the IdP itself happens on that IdP, not the firewall. It is tempting because SAML IdP integration is genuinely required for Captive Portal and GlobalProtect authentication, but the firewall-side task is creating the authentication profile and policy.
- ✓
Create an authentication policy rule that references the application
Why this is correct
An authentication policy rule matches traffic by source, destination and application, then applies the authentication profile and MFA. This satisfies the stem's requirement to enforce MFA specifically for employees accessing the named internal application through the firewall.
- ✗
Install the GlobalProtect client on user endpoints
Why it's wrong here
GlobalProtect client installation is unnecessary for browser-based access to an internal application via Captive Portal authentication policy, which needs no endpoint agent. It is tempting because GlobalProtect with MFA is the standard remote-access design, but that scenario requires the client; here the requirement is firewall authentication policy plus MFA.
- ✗
Enable SSL decryption on the firewall
Why it's wrong here
SSL decryption exposes encrypted traffic for inspection; it does not authenticate users or enforce MFA. It is tempting because decryption is needed to inspect TLS sessions, but MFA enforcement requires user identification and authentication policy, not decryption of the application flow.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.