An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?
Correct. If the browser rejects cookies, the initial authentication may succeed (the captive portal page often does not require a cookie for login), but subsequent HTTP requests lack the session cookie, causing the firewall to re-prompt for credentials on each request.
Why this answer
Captive portal authentication relies on a browser cookie to maintain the authenticated session after the initial login. If the user's browser rejects all cookies, the portal cannot store the session token, so each subsequent request appears unauthenticated and the user is prompted to log in again. The initial login succeeds because credentials are validated, but the session cannot persist without the cookie.
Exam trap
PCNSE often tests whether candidates overlook client-side browser settings (like cookie rejection) and instead blame server-side timeouts or LDAP issues, even when the symptoms clearly point to session persistence failure.
How to eliminate wrong answers
Option B is wrong because an overloaded LDAP server would cause authentication failures or timeouts, not repeated prompts after a successful login. Option C is wrong because caching the captive portal page is unrelated to session persistence; the issue is cookie storage, not page caching. Option D is wrong because the question states the session timeout is 60 minutes, and the prompts occur every few minutes, so a low timeout is not the cause (and the stated timeout is not low).