Courseiva

PCNSE Practice Question: Securing Users and Applications with Authentication

Exhibit

portal "Corporate-Portal" {
    authentication-profile "SAML-Auth"
    ...
}

Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?

⚠ Common exam trap

Palo Alto Networks emphasizes the distinction between authentication profiles (which define the authentication method) and server profiles (which define server connections). Candidates often mistakenly select LDAP or RADIUS profiles instead of the SAML identity provider profile required for SAML-based authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAML identity provider profile

The exhibit shows a SAML-based authentication flow where the firewall redirects the user to an external identity provider (IdP) for authentication. The authentication profile 'SAML-Auth' must reference a SAML identity provider profile to define the IdP metadata, entity ID, SSO URL, and certificate binding. Without this profile, the firewall cannot initiate or validate SAML assertions, making option A the only correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SAML identity provider profile

    Why this is correct

    SAML-Auth requires a SAML identity provider profile because the firewall acts as service provider, validating assertions signed by the external IdP. This profile supplies the IdP's certificate and metadata needed to verify signatures, satisfying the exhibit's requirement for SAML-based authentication rather than local or certificate-based methods.

  • ✗

    LDAP server profile

    Why it's wrong here

    An LDAP server profile binds to a directory for credential or group lookup, whereas a SAML authentication profile authenticates via a SAML identity provider, not LDAP. It is tempting because LDAP profiles are commonly paired with authentication profiles for group mapping, and would be correct if the profile authenticated users directly against the directory.

  • ✗

    RADIUS server

    Why it's wrong here

    A RADIUS server provides authentication against a RADIUS database, which the SAML authentication profile does not query; SAML profiles reference an identity provider via a SAML server entry. It is tempting because RADIUS is the standard choice for 802.1X and captive-portal user authentication, and would be correct if the profile were RADIUS-based rather than SAML.

  • ✗

    Kerberos realm

    Why it's wrong here

    A Kerberos realm authenticates users against Active Directory via Kerberos tickets, which a SAML authentication profile does not use; SAML profiles require a SAML identity provider server entry. It is tempting because Kerberos realms are configured for User-ID and web-form authentication against AD, and would be correct for those methods instead.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.