PCNSE Practice Question: Securing Users and Applications with Authentication
Exhibit
portal "Corporate-Portal" {
authentication-profile "SAML-Auth"
...
}Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?
⚠ Common exam trap
Palo Alto Networks emphasizes the distinction between authentication profiles (which define the authentication method) and server profiles (which define server connections). Candidates often mistakenly select LDAP or RADIUS profiles instead of the SAML identity provider profile required for SAML-based authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SAML identity provider profile
The exhibit shows a SAML-based authentication flow where the firewall redirects the user to an external identity provider (IdP) for authentication. The authentication profile 'SAML-Auth' must reference a SAML identity provider profile to define the IdP metadata, entity ID, SSO URL, and certificate binding. Without this profile, the firewall cannot initiate or validate SAML assertions, making option A the only correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SAML identity provider profile
Why this is correct
SAML-Auth requires a SAML identity provider profile because the firewall acts as service provider, validating assertions signed by the external IdP. This profile supplies the IdP's certificate and metadata needed to verify signatures, satisfying the exhibit's requirement for SAML-based authentication rather than local or certificate-based methods.
- ✗
LDAP server profile
Why it's wrong here
An LDAP server profile binds to a directory for credential or group lookup, whereas a SAML authentication profile authenticates via a SAML identity provider, not LDAP. It is tempting because LDAP profiles are commonly paired with authentication profiles for group mapping, and would be correct if the profile authenticated users directly against the directory.
- ✗
RADIUS server
Why it's wrong here
A RADIUS server provides authentication against a RADIUS database, which the SAML authentication profile does not query; SAML profiles reference an identity provider via a SAML server entry. It is tempting because RADIUS is the standard choice for 802.1X and captive-portal user authentication, and would be correct if the profile were RADIUS-based rather than SAML.
- ✗
Kerberos realm
Why it's wrong here
A Kerberos realm authenticates users against Active Directory via Kerberos tickets, which a SAML authentication profile does not use; SAML profiles require a SAML identity provider server entry. It is tempting because Kerberos realms are configured for User-ID and web-form authentication against AD, and would be correct for those methods instead.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.