Courseiva

PCNSE Captive Portal Session Practice Question

An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?

⚠ Common exam trap

PCNSE often tests whether candidates overlook client-side browser settings (like cookie rejection) and instead blame server-side timeouts or LDAP issues, even when the symptoms clearly point to session persistence failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user's browser is set to reject all cookies.

Captive portal authentication relies on a browser cookie to maintain the authenticated session after the initial login. If the user's browser rejects all cookies, the portal cannot store the session token, so each subsequent request appears unauthenticated and the user is prompted to log in again. The initial login succeeds because credentials are validated, but the session cannot persist without the cookie.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user's browser is set to reject all cookies.

    Why this is correct

    Correct. If the browser rejects cookies, the initial authentication may succeed (the captive portal page often does not require a cookie for login), but subsequent HTTP requests lack the session cookie, causing the firewall to re-prompt for credentials on each request.

  • ✗

    The LDAP server is overloaded and timing out.

    Why it's wrong here

    LDAP overload would produce authentication failures or timeouts, not successful logins followed by repeated prompts. The stem states credentials are accepted initially, so the directory is reachable. Overload is tempting because it explains intermittent authentication, but it cannot cause re-prompting after a valid session is established.

  • ✗

    The captive portal page is not being cached by the browser.

    Why it's wrong here

    Browser caching affects page load performance, not session persistence; the portal page already loads correctly. Repeated prompts stem from session state being lost, typically through cookie handling or timeout mismatch. Caching is tempting as a client-side explanation, but it cannot invalidate an authenticated session.

  • ✗

    The session timeout on the captive portal authentication profile is set too low (e.g., 5 minutes).

    Why it's wrong here

    Incorrect. The stem states that the authentication profile has a session timeout of 60 minutes. If the captive portal authentication profile timeout were set to 5 minutes, it would contradict the given information; the issue is not a low timeout but a failure to maintain the session.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.