PCNSE Practice Question: Securing Users and Applications with Authentication
To reduce the number of authentication prompts for users accessing multiple applications through the firewall, which configuration is recommended?
⚠ Common exam trap
Many exam-takers confuse increasing the authentication timeout (Option A) with reducing prompts, but timeout only extends the session lifespan, not the number of prompts per application; the key is the session cookie mechanism that ties all application requests to a single authenticated session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable session cookies in the authentication policy
Enabling session cookies in the authentication policy allows the firewall to store a session cookie on the user's browser after the first successful authentication. This cookie is then presented for subsequent requests to different applications, eliminating repeated authentication prompts. The firewall validates the cookie against the existing user session, providing a seamless single sign-on (SSO) experience without requiring re-authentication for each application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the authentication timeout value
Why it's wrong here
Extending the authentication timeout lengthens how long an existing session stays authenticated, yet each new application session still triggers its own prompt, so the count is unchanged. It is tempting because timeouts govern session lifetime, and a longer value would be correct for keeping idle users signed in.
- ✓
Enable session cookies in the authentication policy
Why this is correct
Session cookies let the firewall cache a user's authentication result, so subsequent application access reuses that session instead of re-prompting. This directly satisfies the stem's constraint of reducing authentication prompts across multiple applications, provided cookie lifetime and timeout settings are tuned appropriately.
- ✗
Use certificate-based authentication
Why it's wrong here
Certificate-based authentication still prompts per application unless the firewall maps the certificate to a user and applies authentication policy; it does not itself suppress repeated captive-portal challenges. It is tempting because certificates remove password entry, and they would be correct for strong client identity, but not for reducing prompt frequency.
- ✗
Disable authentication for commonly used applications
Why it's wrong here
Disabling authentication for common applications removes the prompt entirely but also removes user identification, so policy can no longer enforce per-user rules. It is tempting because it visibly cuts prompts, and it would be correct only where those applications genuinely need no identity-based control.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.