Courseiva

CCNA Securing Users and Applications with Authentication Questions

24 questions · Securing Users and Applications with Authentication · All types, answers revealed

1
MCQmedium

An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?

A.The user's browser is set to reject all cookies.
B.The LDAP server is overloaded and timing out.
C.The captive portal page is not being cached by the browser.
D.The session timeout on the captive portal authentication profile is set too low (e.g., 5 minutes).
AnswerA

Correct. If the browser rejects cookies, the initial authentication may succeed (the captive portal page often does not require a cookie for login), but subsequent HTTP requests lack the session cookie, causing the firewall to re-prompt for credentials on each request.

Why this answer

Captive portal authentication relies on a browser cookie to maintain the authenticated session after the initial login. If the user's browser rejects all cookies, the portal cannot store the session token, so each subsequent request appears unauthenticated and the user is prompted to log in again. The initial login succeeds because credentials are validated, but the session cannot persist without the cookie.

Exam trap

PCNSE often tests whether candidates overlook client-side browser settings (like cookie rejection) and instead blame server-side timeouts or LDAP issues, even when the symptoms clearly point to session persistence failure.

How to eliminate wrong answers

Option B is wrong because an overloaded LDAP server would cause authentication failures or timeouts, not repeated prompts after a successful login. Option C is wrong because caching the captive portal page is unrelated to session persistence; the issue is cookie storage, not page caching. Option D is wrong because the question states the session timeout is 60 minutes, and the prompts occur every few minutes, so a low timeout is not the cause (and the stated timeout is not low).

2
Multi-Selecthard

Which THREE factors should be considered when designing an authentication policy for a multi-zone environment with varied security requirements? (Choose THREE.)

Select 3 answers
A.Source zone
B.User-ID
C.Schedule
D.Application ID
E.Destination zone
AnswersA, C, E

Source zone is a key condition in authentication policies.

Why this answer

A is correct because source zone is a critical factor in authentication policy design, as it determines which traffic entering from specific zones (e.g., Untrust, DMZ) must be authenticated. In a multi-zone environment, different zones have varying trust levels, so authentication policies must be scoped to source zones to enforce access controls appropriately. Without source zone consideration, traffic from low-trust zones could bypass authentication, violating security requirements.

Exam trap

The trap here is that candidates often confuse User-ID as a design factor for authentication policies, when in fact User-ID is a post-authentication mapping mechanism, not a condition that defines when authentication is triggered.

3
MCQeasy

A company wants to authenticate users who are accessing internal applications from the internet through a firewall. The users should be prompted once per session. Which authentication solution best meets this requirement?

A.SAML authentication with single sign-on.
B.LDAP authentication with a timeout.
C.Captive Portal with session cookie.
D.RADIUS authentication with one-time passwords.
AnswerA

SAML authentication with single sign-on satisfies the once-per-session constraint by issuing a signed assertion after the initial Microsoft Entra ID login, which the firewall validates for subsequent application requests without re-prompting. This differs from per-request authentication methods such as captive portal or client certificate checks that re-authenticate each connection.

Why this answer

SAML authentication with single sign-on (SSO) allows users to authenticate once per session via an external identity provider (IdP). The firewall validates the SAML assertion and maintains the session, so users are not prompted again until the session expires or is terminated. This meets the requirement of a single prompt per session without re-authentication.

Exam trap

The trap here is that candidates often confuse 'session cookie' (Option C) with single sign-on, but Captive Portal cookies only cover the firewall's own session tracking and do not provide federated authentication across multiple applications, whereas SAML SSO does.

How to eliminate wrong answers

Option B is wrong because LDAP authentication with a timeout does not inherently provide single sign-on; it requires the firewall to prompt for credentials on each new session or after timeout, not once per session. Option C is wrong because Captive Portal with session cookie still prompts the user for credentials at the start of each new TCP connection or after cookie expiration, and it does not provide true session-level single sign-on across applications. Option D is wrong because RADIUS authentication with one-time passwords (OTP) requires a new OTP for each authentication attempt, which would prompt the user multiple times per session, not once.

4
MCQmedium

Which of the following is required for SAML-based single sign-on to work with a Palo Alto Networks firewall acting as the service provider?

A.The identity provider's metadata must be imported into the firewall.
B.A certificate from a public CA for the SAML identity provider.
C.The firewall must be configured as a SAML identity provider.
D.User-ID must be configured to poll the SAML identity provider.
AnswerA

Importing the identity provider's metadata supplies the firewall with the IdP's signing certificate, entity ID and SSO endpoint, which it needs to validate SAML assertions and redirect authentication requests. Without this trust anchor, the service provider cannot verify responses, so the metadata import satisfies the SAML configuration requirement.

Why this answer

For SAML-based single sign-on (SSO) with a Palo Alto Networks firewall acting as the service provider (SP), the firewall must trust the identity provider (IdP). This trust is established by importing the IdP's SAML metadata (which includes the IdP's entity ID, single sign-on URL, and signing certificate) into the firewall. Without this metadata, the firewall cannot validate SAML assertions from the IdP, making authentication impossible.

Exam trap

The trap here is that candidates often assume a public CA certificate is required for SAML trust (Option B), but in reality, SAML uses a direct trust model where the SP explicitly trusts the IdP's self-signed certificate via metadata import, not through a public PKI hierarchy.

How to eliminate wrong answers

Option B is wrong because the certificate used for SAML signing by the IdP does not need to come from a public CA; it can be a self-signed certificate, as the trust is established via the metadata import, not via a public CA chain. Option C is wrong because the firewall is acting as the service provider (SP), not the identity provider (IdP); configuring it as an IdP would be for scenarios where the firewall itself authenticates users, not for SP-initiated SSO. Option D is wrong because User-ID does not need to poll the SAML IdP; SAML SSO provides user identity information directly in the SAML assertion, which the firewall can use to map to a User-ID without polling.

5
Drag & Dropmedium

Arrange the steps to deploy a new Panorama template to a managed firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for deploying a new Panorama template to a managed firewall is: first, create the template; second, add configuration objects such as interfaces and zones; third, assign the template to the relevant device group; and finally, commit the template to push the configuration to the managed firewalls. This order ensures that the template exists, contains the desired settings, is linked to the correct devices, and is then applied.

6
MCQeasy

A company wants to enforce multi-factor authentication (MFA) for all administrative access to the Palo Alto Networks firewall. They have a RADIUS server configured with MFA capability (e.g., RSA SecurID). The firewall is currently using local authentication for admin accounts. What must be configured to enforce MFA for admin access?

A.Create a security policy to allow RADIUS traffic from the firewall to the RADIUS server.
B.Enable MFA in the User-ID agent configuration.
C.Create an authentication profile using RADIUS with MFA enabled and assign it to the admin accounts.
D.Configure an authentication enforcement rule in the authentication policy.
AnswerC

An authentication profile binds admin logins to the RADIUS server, so the firewall forwards credentials and the RSA SecurID challenge is enforced. Assigning it to admin accounts replaces local authentication, satisfying the requirement that all administrative access use MFA.

Why this answer

To enforce MFA for administrative access on a Palo Alto Networks firewall, you must create an authentication profile that uses RADIUS (or another MFA-capable server) and then assign that profile to the admin accounts. The authentication profile defines how the firewall authenticates administrators, and when it points to an MFA-enabled RADIUS server, the firewall will require the second factor. Assigning the profile to admin accounts ensures that all administrative logins go through MFA.

Exam trap

PCNSE often tests the difference between authentication profiles for administrative access and authentication policies for user traffic; candidates may incorrectly choose an authentication enforcement rule, which applies to user traffic, not admin access.

How to eliminate wrong answers

Option A is wrong because a security policy allowing RADIUS traffic is necessary for the firewall to communicate with the RADIUS server, but it does not enforce MFA for admin access; it only permits the traffic. Option B is wrong because MFA is not configured in the User-ID agent; the User-ID agent is used for mapping IP addresses to users, not for admin authentication. Option D is wrong because authentication enforcement rules are used in authentication policies for user traffic (e.g., for captive portal or web authentication), not for administrative access to the firewall itself.

7
MCQhard

A company needs to authenticate remote users accessing internal web applications via GlobalProtect portal and wants to use SAML with Azure AD for MFA. Which component must be configured on the firewall?

A.LDAP server profile for user lookup
B.Server certificate for the portal
C.Authentication profile referencing the SAML IdP profile
D.SSL decryption rule
AnswerC

An authentication profile binds the SAML IdP profile to the GlobalProtect portal, enabling the firewall to redirect users to Microsoft Entra ID for MFA. The IdP profile alone holds the certificate and metadata but cannot be referenced directly by the portal; the authentication profile is the required linking object.

Why this answer

SAML authentication for GlobalProtect requires an authentication profile that references a SAML identity provider (IdP) profile. The firewall uses this profile to redirect users to Azure AD for SAML-based MFA, then validates the SAML assertion returned. Without this profile, the firewall cannot initiate or complete the SAML exchange.

Exam trap

The trap here is that candidates often confuse the need for a server certificate (required for TLS) with the authentication method itself, or assume LDAP is needed for user identity, but SAML authentication is configured solely through the authentication profile and SAML IdP profile, not through LDAP or SSL decryption.

How to eliminate wrong answers

Option A is wrong because an LDAP server profile is used for direct user lookup or authentication against an LDAP directory, not for SAML-based authentication with Azure AD; SAML relies on token exchange, not LDAP binds. Option B is wrong because a server certificate for the portal is required for TLS encryption of the GlobalProtect portal, but it does not enable SAML authentication or MFA; it secures the transport layer only. Option D is wrong because SSL decryption rules are used to inspect encrypted traffic, not to configure authentication methods; they have no role in SAML or MFA integration.

8
Multi-Selecthard

Which TWO are prerequisites for using Authentication Policy? (Choose two.)

Select 2 answers
A.User-ID is configured
B.The firewall is in transparent mode
C.SSL decryption is enabled
D.A security policy rule exists with user attributes
E.An authentication profile is configured
AnswersA, E

Authentication Policy enforces user- and group-based rules, so it requires User-ID to map source IP addresses to directory identities before any policy can match. Without User-ID configured, the firewall cannot resolve usernames or groups, leaving the policy unevaluable. This satisfies the stem's prerequisite constraint directly.

Why this answer

Authentication Policy in PAN-OS requires User-ID to be configured (option A) because the policy matches traffic based on user and group mappings that User-ID provides; without an active User-ID source (such as an agent, syslog listener, or server monitoring), the firewall has no user-to-IP mapping to enforce authentication rules. It also requires an authentication profile (option E), since the Authentication Policy references an authentication profile to define the authentication method (e.g., LDAP, RADIUS, SAML, Kerberos, or local database) and the authentication portal settings used to challenge users. Option B is incorrect because transparent mode is not required—Authentication Policy works in L3, L2, virtual wire, and tap modes.

Option C is incorrect because SSL decryption is not a prerequisite; it is only needed to identify users in encrypted traffic, not to use Authentication Policy itself. Option D is incorrect because a security policy rule with user attributes is not required to create or use Authentication Policy; Authentication Policy is evaluated before security policy and generates the user mapping that security rules may later reference.

Exam trap

The trap here is that candidates often confuse prerequisites with features that enhance security (like SSL decryption) or confuse the order of configuration steps, thinking a security rule with user attributes must exist before the authentication policy can be used.

9
Multi-Selectmedium

A company wants to enforce multi-factor authentication (MFA) for employees accessing a specific internal application through the firewall. Which two configurations are required on the Palo Alto Networks firewall? (Choose two.)

Select 2 answers
A.Define an authentication profile that includes an MFA method
B.Configure a SAML identity provider
C.Create an authentication policy rule that references the application
D.Install the GlobalProtect client on user endpoints
E.Enable SSL decryption on the firewall
AnswersA, C

An authentication profile defines the authentication service and MFA factors the firewall uses to verify users. Referencing it in an authentication policy enforces MFA for the internal application, satisfying the stem's requirement to enforce multi-factor authentication for that specific application.

Why this answer

Option A is correct because an authentication profile on the Palo Alto Networks firewall defines the authentication methods, including MFA (such as RADIUS with OTP, or a SAML/MFA provider), and is the object that the firewall uses to challenge users for credentials and a second factor. Option C is correct because an authentication policy rule is what actually enforces authentication for matching traffic; it references the authentication profile and can be scoped to the specific internal application (via destination/URL category or application), so without this rule no MFA challenge is triggered. Option B is not required because a SAML identity provider is only one possible MFA mechanism and is not mandatory for enforcing MFA; the firewall can use other methods such as RADIUS with OTP.

Option D is not required because GlobalProtect is a remote-access VPN/client solution, not a prerequisite for authenticating users to an internal application through the firewall. Option E is not required because SSL decryption is used for inspecting encrypted traffic, not for enforcing MFA authentication.

Exam trap

The trap here is that candidates often confuse authentication policy rules with security policy rules, or assume that MFA always requires GlobalProtect or SAML, when in fact the firewall can enforce MFA directly via captive portal using an authentication profile and policy rule.

10
MCQhard

After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?

A.The IdP does not support IdP-initiated SAML flow
B.The user mapping agent is not configured
C.The firewall and IdP system clocks are out of sync
D.The SAML identity provider certificate is expired
AnswerC

Clock skew between the firewall and IdP invalidates the assertion's NotBefore/NotOnOrAfter conditions, so signature validation fails despite successful IdP authentication. The portal rejects the assertion as invalid because its timestamp falls outside the permitted window, satisfying the stem's 'invalid saml assertion' constraint. Synchronising both systems via NTP resolves the repeated credential prompts.

Why this answer

The firewall logs show 'saml-auth-success' (meaning the IdP successfully authenticated the user and issued a SAML assertion), but the portal log shows 'user-login-failure: invalid saml assertion'. This indicates the firewall received the assertion but rejected it as invalid. The most common cause for a validly signed assertion to be rejected is clock skew between the firewall and the IdP, because SAML assertions contain timestamps (NotBefore and NotOnOrAfter conditions) that are checked against the local system clock.

If the clocks differ by more than the allowed skew (typically 5 minutes), the assertion is considered invalid even though it was correctly signed.

Exam trap

The trap here is that candidates see 'saml-auth-success' and assume the authentication succeeded end-to-end, but they miss that the firewall's portal log rejection indicates a validation failure on the assertion itself, not a failure at the IdP.

How to eliminate wrong answers

Option A is wrong because IdP-initiated SAML flow is not required for GlobalProtect; GlobalProtect uses SP-initiated SAML flow, where the firewall (service provider) redirects the user to the IdP. The error here is about assertion validation, not about which party initiated the flow. Option B is wrong because the user mapping agent is used for mapping IP addresses to usernames for policy enforcement, not for SAML authentication validation; the error occurs during the SAML assertion validation phase, before any user mapping would occur.

Option D is wrong because if the IdP certificate were expired, the firewall would fail to validate the signature on the SAML assertion and would log a signature validation error, not an 'invalid saml assertion' error; the logs show 'saml-auth-success' from the IdP side, meaning the certificate was valid at the time of signing.

11
MCQeasy

An administrator has configured an authentication profile with LDAP and sets the authentication sequence to 'continue on failure'. A user enters an incorrect password first, then correct. Will the user be authenticated?

A.Yes, because the sequence continues on failure and the second attempt succeeds.
B.Yes, but only if the LDAP server is configured for multiple attempts.
C.No, because the first failure blocks authentication.
D.No, because the sequence stops on success, but the first attempt failed.
AnswerD

Correct. The authentication sequence 'continue on failure' only moves to the next method if the current method fails due to a server error (timeout, unreachable). An incorrect password is a successful authentication attempt that returns a negative result; therefore, the sequence stops, and the user is not authenticated. The second correct password is never tried.

Why this answer

The authentication sequence 'continue on failure' only proceeds to the next authentication method if the current method fails (e.g., server timeout or unreachable). It does NOT retry the same LDAP server with a different password. Since the first attempt failed due to an incorrect password, the sequence stops, and the user is not authenticated.

The second correct password is never attempted because the failure is treated as a final rejection, not a retry opportunity.

Exam trap

The trap here is that candidates confuse 'continue on failure' (which moves to the next authentication method after a server error) with a retry mechanism for incorrect passwords, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because 'continue on failure' does not mean the user can retry with a different password on the same LDAP server; it only moves to the next authentication method (e.g., another LDAP server or local database) if the first method fails due to a connectivity or server error, not due to invalid credentials. Option B is wrong because the LDAP server configuration for multiple attempts is irrelevant; the Palo Alto Networks firewall's authentication sequence controls retries, and the sequence does not retry the same server with a corrected password. Option C is wrong because the first failure does not block authentication in all cases; it blocks authentication only because the failure is due to invalid credentials, not because the sequence stops unconditionally.

12
MCQmedium

A network security engineer is configuring an authentication profile on a Palo Alto Networks firewall to allow administrators to log in using their Active Directory credentials. The engineer wants to ensure that only members of the 'NetOps' group can access the firewall. Which setting in the authentication profile should be configured to enforce this?

A.Allow List
B.User Domain
C.Kerberos Keytab
D.Authentication Sequence
AnswerA

The Allow List in an authentication profile specifies which users or groups are permitted to authenticate. By adding the 'NetOps' group to the Allow List, only members of that group can successfully authenticate. This directly enforces the group-based access restriction described in the scenario.

Why this answer

The Allow List in an authentication profile explicitly permits only specified users or groups to authenticate. By adding the 'NetOps' group, the firewall will check group membership during authentication and allow only those users. Other settings like authentication sequence, user domain, or Kerberos keytab do not provide this group-based restriction.

Exam trap

The trap here is confusing the authentication sequence with the Allow List, assuming that the sequence itself can enforce group membership.

13
MCQeasy

An administrator wants to enforce authentication for SSL decrypted traffic so that only authenticated users can access decrypted content. Which firewall feature should be configured?

A.SSL Inbound Inspection
B.Authentication Policy
C.User-ID agent
D.SSL Forward Proxy
AnswerB

Authentication Policy enforces user-based access control after SSL decryption, matching traffic against Microsoft Entra ID, LDAP or local user groups. It satisfies the stem's constraint that only authenticated users reach decrypted content, unlike decryption profiles or URL filtering, which act on traffic regardless of identity.

Why this answer

Authentication Policy is the correct feature because it allows the firewall to enforce user authentication specifically for SSL decrypted traffic. By configuring an Authentication Policy, the firewall can require users to authenticate before accessing decrypted content, ensuring that only authenticated users can proceed. This is distinct from SSL decryption profiles, which handle the decryption itself but not user access control.

Exam trap

The trap here is that candidates often confuse SSL Forward Proxy (which handles decryption) with Authentication Policy (which handles user access control), leading them to select the decryption feature instead of the authentication enforcement feature.

How to eliminate wrong answers

Option A is wrong because SSL Inbound Inspection is used to decrypt inbound traffic destined for protected servers, not to enforce authentication for decrypted content. Option C is wrong because the User-ID agent is responsible for mapping users to IP addresses for visibility and policy enforcement, but it does not enforce authentication for decrypted traffic. Option D is wrong because SSL Forward Proxy decrypts outbound SSL traffic for inspection, but it does not enforce user authentication; it only enables decryption.

14
Matchingmedium

Match each security profile type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Detects and blocks malware in traffic

Prevents spyware and command-and-control traffic

Blocks exploits targeting known vulnerabilities

Controls access to websites based on category

Blocks specific file types from being transferred

Why these pairings

The correct matches are: Antivirus scans for malware, Anti-Spyware protects against spyware, Vulnerability Protection prevents exploitation. URL Filtering categorizes URLs, and File Blocking blocks file types. Options D and E swap these definitions.

15
MCQhard

Refer to the exhibit. What happens when a user with an unknown identity (source-user unknown) tries to access resources in 192.168.1.0/24?

A.The traffic is blocked because the source-user is 'unknown'.
B.The traffic is allowed without authentication because the source-user is 'unknown'.
C.The user is prompted to authenticate via the configured authentication profile.
D.The user is redirected to the captive portal.
AnswerC

Unknown source users trigger the configured authentication profile, forcing a Captive Portal or authentication challenge before access to 192.168.1.0/24 is granted. This satisfies the security policy's requirement to identify unrecognised traffic, since the rule matches unknown source-user and applies the profile rather than silently permitting or dropping the session.

Why this answer

When a user with an unknown identity (source-user unknown) attempts to access resources in 192.168.1.0/24 and the policy rule action is 'allow-authentication', the firewall prompts the user to authenticate via the configured authentication profile. Option A is incorrect because the action is not 'deny', so traffic is not blocked solely due to unknown source-user. Option B is incorrect because the traffic is not allowed without authentication; the 'allow-authentication' action requires successful authentication.

Option D is incorrect because the action is specifically 'allow-authentication' which triggers an authentication prompt using the configured method (which may be captive portal, but the term 'redirect to captive portal' is less precise than 'prompted to authenticate').

16
MCQeasy

A company has configured multi-factor authentication (MFA) via an authentication sequence using LDAP and RADIUS. Users authenticate successfully with LDAP but the MFA prompt from RADIUS does not appear. What is the most likely cause?

A.The authentication sequence must be configured to 'require all' or 'continue on success' to enforce each factor.
B.The RADIUS server profile has the wrong shared secret.
C.The authentication policy only covers HTTP applications.
D.The authentication sequence is set to 'continue on failure' and the LDAP authentication succeeds.
AnswerA

To require all factors in the sequence, the sequence type must be set to 'require all' or 'continue on success' so each factor is attempted regardless of previous success.

Why this answer

When using an authentication sequence in Palo Alto Networks firewalls, the sequence must be configured with the 'require all' or 'continue on success' option to enforce each factor in order. With 'continue on success', after LDAP succeeds, the firewall proceeds to the next factor (RADIUS MFA). If the sequence is set to 'continue on failure' (the default), the firewall stops after the first successful authentication and never attempts the second factor, so the MFA prompt never appears.

Exam trap

In Palo Alto Networks, the default behavior for authentication sequences is 'continue on failure', which means the firewall only moves to the next authentication factor if the current one fails. If LDAP succeeds, it never attempts RADIUS. Candidates often assume that simply adding multiple methods enforces all factors, but the sequence must be set to 'continue on success' or 'require all' to enforce MFA properly.

How to eliminate wrong answers

Option B is wrong because a wrong shared secret on the RADIUS server profile would cause the RADIUS authentication to fail or timeout, but the MFA prompt might still appear (the firewall would attempt to contact the RADIUS server). Option C is wrong because authentication policies are not limited to HTTP applications; they can be configured for any application or service, and the question does not specify an HTTP-only scenario. Option D is wrong because if the authentication sequence is set to 'continue on failure', the firewall would stop after the first successful authentication (LDAP) and never proceed to RADIUS, which matches the symptom but is not the most likely cause—the sequence must be explicitly configured to continue on success or require all to enforce multiple factors.

17
Multi-Selecteasy

Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?

Select 2 answers
A.LDAP
B.Local Database
C.Kerberos
D.RADIUS
E.SAML
AnswersC, E

Kerberos uses ticket-granting tickets issued by a domain controller, so a user who has already authenticated to the domain presents a service ticket to the firewall transparently. This delivers SSO because the firewall trusts the KDC's tickets instead of prompting for credentials again.

Why this answer

Kerberos (option C) supports SSO because it uses ticket-based authentication where the client obtains a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC) and presents it to the firewall without re-entering credentials. SAML (option E) supports SSO by exchanging signed XML assertions between an identity provider (IdP) and the firewall, enabling browser-based federated single sign-on.

Exam trap

The trap here is that candidates often assume RADIUS or LDAP support SSO because they are common authentication protocols, but neither provides the ticket or assertion exchange required for true single sign-on; only Kerberos and SAML implement SSO mechanisms in Palo Alto firewalls.

18
MCQeasy

To reduce the number of authentication prompts for users accessing multiple applications through the firewall, which configuration is recommended?

A.Increase the authentication timeout value
B.Enable session cookies in the authentication policy
C.Use certificate-based authentication
D.Disable authentication for commonly used applications
AnswerB

Session cookies let the firewall cache a user's authentication result, so subsequent application access reuses that session instead of re-prompting. This directly satisfies the stem's constraint of reducing authentication prompts across multiple applications, provided cookie lifetime and timeout settings are tuned appropriately.

Why this answer

Enabling session cookies in the authentication policy allows the firewall to store a session cookie on the user's browser after the first successful authentication. This cookie is then presented for subsequent requests to different applications, eliminating repeated authentication prompts. The firewall validates the cookie against the existing user session, providing a seamless single sign-on (SSO) experience without requiring re-authentication for each application.

Exam trap

The trap here is that candidates often confuse increasing the authentication timeout (Option A) with reducing prompts, but timeout only extends the session lifespan, not the number of prompts per application; the key is the session cookie mechanism that ties all application requests to a single authenticated session.

How to eliminate wrong answers

Option A is wrong because increasing the authentication timeout value only extends the duration a user remains authenticated, but it does not prevent repeated prompts when accessing multiple applications; each new application request still triggers authentication unless a session cookie is used. Option C is wrong because certificate-based authentication eliminates passwords but does not inherently reduce the number of authentication prompts across multiple applications; each application still requires a separate certificate exchange unless combined with session cookies. Option D is wrong because disabling authentication for commonly used applications bypasses security controls entirely, leaving those applications unprotected and violating the principle of least privilege.

19
MCQhard

An organization has deployed GlobalProtect with certificate authentication. Users on macOS report that after updating their client, they cannot connect and see error 'Certificate validation failed: The certificate hash does not match.' What is the most likely cause?

A.The certificate pinning configuration on the gateway has a hash mismatch
B.The root CA certificate is not trusted on the client
C.The CRL is not reachable
D.The GlobalProtect gateway certificate is expired
AnswerA

Certificate pinning enforces specific hash; client update may change the hash.

Why this answer

The error 'Certificate validation failed: The certificate hash does not match' specifically indicates a certificate pinning mismatch. GlobalProtect certificate pinning allows the gateway to enforce that the client's certificate matches a specific hash (SHA-256 fingerprint). When the client updates, its certificate may change (e.g., due to a new key pair or renewal), causing the hash stored in the gateway's pinning configuration to no longer match, resulting in this exact error.

Exam trap

The trap here is that candidates often confuse certificate pinning failures with general certificate validation issues (like trust or expiry), but the specific error message 'certificate hash does not match' is unique to pinning and not to standard PKI validation steps.

How to eliminate wrong answers

Option B is wrong because if the root CA certificate were not trusted on the client, the error would typically be 'untrusted root' or 'certificate not trusted', not a hash mismatch. Option C is wrong because an unreachable CRL would cause a revocation check failure (e.g., 'CRL not available' or 'certificate revoked'), not a hash mismatch. Option D is wrong because an expired gateway certificate would produce an 'expired certificate' error, not a hash mismatch; the hash mismatch error is specific to the client certificate's fingerprint not matching the pinned value.

20
MCQhard

Refer to the exhibit. A user at IP 10.10.1.11 is unable to access internal resources that require authentication. The firewall logs show 'no user mapping' for traffic from this IP. Which step should the administrator take first?

A.Configure an authentication policy to trigger captive portal for that IP.
B.Verify that the User-ID agent has network access to the client at 10.10.1.11.
C.Check the Kerberos keytab file.
D.Manually create a static mapping for IP 10.10.1.11.
AnswerB

Verifying the User-ID agent's network access to 10.10.1.11 directly addresses the missing user mapping, since the agent must reach the client to query its logged-in sessions. Without that connectivity, no mapping is generated, so the firewall logs 'no user mapping' and authentication-dependent access fails.

Why this answer

The 'no user mapping' error indicates that the firewall cannot correlate the IP address (10.10.1.11) with a username. The first step is to verify that the User-ID agent can reach the client, because without network connectivity, the agent cannot collect user mappings via probing (e.g., WMI, NetBIOS, or terminal services). Option B directly addresses this root cause.

Exam trap

The trap here is that candidates often jump to configuring authentication policies or static mappings without first verifying the basic connectivity between the User-ID agent and the client, which is the most common root cause of missing user mappings.

How to eliminate wrong answers

Option A is wrong because configuring an authentication policy to trigger captive portal would require the user to actively authenticate, but the issue is that the firewall already lacks a user mapping for the IP; captive portal is a separate mechanism and not the first troubleshooting step. Option C is wrong because checking the Kerberos keytab file is relevant only if the firewall is configured for Kerberos-based authentication (e.g., for GlobalProtect or captive portal), but the core problem is missing user mapping, not a keytab misconfiguration. Option D is wrong because manually creating a static mapping is a workaround, not a diagnostic step; the administrator should first determine why the User-ID agent is not mapping the IP dynamically.

21
MCQhard

A network engineer is troubleshooting an authentication issue where users in a specific group are not being prompted for credentials, even though the authentication policy matches their traffic. The firewall logs show that the traffic is allowed by the security policy. What is the most likely cause?

A.The users are in a group that is excluded from authentication in the authentication profile.
B.The captive portal is not enabled on the interface.
C.The user-ID agent is not configured to include that group.
D.The authentication policy is placed after the security rule that allows the traffic.
AnswerA

Group exclusion would apply to the authentication profile, not prevent the prompt altogether.

Why this answer

When an authentication policy matches traffic but users in a specific group are not prompted for credentials, the most likely cause is that the group is excluded from authentication in the authentication profile. An authentication profile can include an allow list/exclusion list; users in an excluded group are not prompted for authentication even though the authentication policy matches. Authentication policies are evaluated before security policies, so a security policy allowing the traffic does not bypass authentication.

Exam trap

Candidates often assume security policies are evaluated before authentication policies, but in Palo Alto Networks firewalls, authentication policies are evaluated first. A matching authentication policy enforces authentication before security policy evaluation, so placing the authentication policy after a security rule does not bypass authentication.

How to eliminate wrong answers

Option A is wrong because if a group is excluded from authentication in the authentication profile, the firewall would not prompt for credentials for that group, but the logs would show the traffic as allowed by security policy without any authentication attempt, which is not the described scenario where users are not prompted despite the policy matching. Option B is wrong because captive portal not being enabled on the interface would prevent the authentication challenge from being presented, but the question states the authentication policy matches the traffic, implying the policy is configured and applied; captive portal is a separate setting that enables the browser-based authentication prompt, but its absence would cause a different symptom (no prompt at all) rather than the traffic being allowed without authentication. Option C is wrong because the User-ID agent not including a group affects user mapping and identification, not the enforcement of authentication policies; the authentication policy can still match based on source IP or other criteria, and the lack of group inclusion would not prevent the authentication prompt from being triggered.

22
MCQmedium

Users are unable to authenticate via Captive Portal. The firewall receives authentication requests but they time out. What should be checked first?

A.The certificate used for the Captive Portal page
B.The session timeout for authenticated users
C.The authentication sequence settings in the Captive Portal configuration
D.The User-ID agent mapping
AnswerC

Authentication requests reach the firewall but time out, indicating the firewall cannot reach an authentication service. The authentication sequence defines which servers are queried and in what order, so a misconfigured or unreachable sequence entry is the first thing to verify.

Why this answer

When the firewall receives authentication requests but they time out, the most common cause is a misconfigured authentication sequence. The authentication sequence defines the order of authentication methods (e.g., local database, RADIUS, LDAP) and their timeout settings. If the sequence is incorrect or the servers are unreachable, the firewall will wait for a response until the timeout expires, causing the Captive Portal authentication to fail.

Checking this first isolates the issue efficiently before investigating other components.

Exam trap

The trap here is that candidates often jump to checking the certificate (Option A) because Captive Portal uses HTTPS, but the timeout symptom specifically indicates a backend authentication server issue, not a certificate problem.

How to eliminate wrong answers

Option A is wrong because a certificate issue would typically cause SSL/TLS errors or browser warnings, not authentication request timeouts; the firewall would still process the request but the page might not load securely. Option B is wrong because session timeout controls how long an authenticated user remains active, not the initial authentication process; changing it would not affect the timeout of authentication requests. Option D is wrong because the User-ID agent mapping is used to map IP addresses to usernames after authentication, not to process the initial Captive Portal authentication requests; a timeout during authentication points to the authentication server or sequence, not the mapping agent.

23
Multi-Selectmedium

Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)

Select 3 answers
A.Firewall management interface
B.GlobalProtect Gateway
C.GlobalProtect Client
D.GlobalProtect Portal
E.Authentication server
AnswersB, C, D

The GlobalProtect gateway is a core infrastructure component, terminating client tunnels and enforcing security policy for remote users. It satisfies the stem's requirement by providing the data-plane endpoint that agents connect to, distinct from the portal's configuration role. Gateways can be deployed on firewalls or dedicated appliances, scaling across multiple regions.

Why this answer

The three core components of the GlobalProtect infrastructure are the GlobalProtect Portal (D), the GlobalProtect Gateway (B), and the GlobalProtect Client (C). The Portal (D) is the entry point that hosts the agent configuration and delivers settings, client certificates, and the list of available gateways to endpoints. The Gateway (B) is the security enforcement point that provides the actual tunnel (SSL or IPSec) and applies security, decryption, and HIP policies to traffic.

The Client (C) is the endpoint software (GlobalProtect app) installed on user devices that authenticates to the portal, retrieves configuration, and establishes the tunnel to a gateway. The firewall management interface (A) is only the administrative web UI/CLI used to configure the firewall and is not itself a GlobalProtect infrastructure component, and an authentication server (E) is an external identity source (e.g., LDAP, RADIUS, SAML IdP) that GlobalProtect can reference for user authentication but is not a GlobalProtect component.

Exam trap

The trap here is that candidates often confuse external dependencies (like authentication servers or management interfaces) with the core GlobalProtect components, leading them to select options that are not part of the defined infrastructure.

24
MCQeasy

Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?

A.SAML identity provider profile
B.LDAP server profile
C.RADIUS server
D.Kerberos realm
AnswerA

SAML-Auth requires a SAML identity provider profile because the firewall acts as service provider, validating assertions signed by the external IdP. This profile supplies the IdP's certificate and metadata needed to verify signatures, satisfying the exhibit's requirement for SAML-based authentication rather than local or certificate-based methods.

Why this answer

The exhibit shows a SAML-based authentication flow where the firewall redirects the user to an external identity provider (IdP) for authentication. The authentication profile 'SAML-Auth' must reference a SAML identity provider profile to define the IdP metadata, entity ID, SSO URL, and certificate binding. Without this profile, the firewall cannot initiate or validate SAML assertions, making option A the only correct choice.

Exam trap

Palo Alto Networks emphasizes the distinction between authentication profiles (which define the authentication method) and server profiles (which define server connections). Candidates often mistakenly select LDAP or RADIUS profiles instead of the SAML identity provider profile required for SAML-based authentication.

How to eliminate wrong answers

Option B is wrong because LDAP server profiles are used for direct LDAP bind authentication against an on-premises directory, not for SAML-based federated authentication. Option C is wrong because RADIUS server profiles are used for RADIUS-based authentication (e.g., with 802.1X or VPN), which does not support SAML assertions or IdP redirection. Option D is wrong because Kerberos realms are used for Kerberos-based authentication (typically with Active Directory in a domain environment), not for SAML identity provider configuration.

Ready to test yourself?

Try a timed practice session using only Securing Users and Applications with Authentication questions.