Courseiva

PCNSE Practice Question: Securing Users and Applications with Authentication

Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)

⚠ Common exam trap

Many candidates confuse external dependencies (like authentication servers or management interfaces) with the core GlobalProtect components, leading them to select options that are not part of the defined infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GlobalProtect Gateway

The three core components of the GlobalProtect infrastructure are the GlobalProtect Portal (D), the GlobalProtect Gateway (B), and the GlobalProtect Client (C). The Portal (D) is the entry point that hosts the agent configuration and delivers settings, client certificates, and the list of available gateways to endpoints. The Gateway (B) is the security enforcement point that provides the actual tunnel (SSL or IPSec) and applies security, decryption, and HIP policies to traffic. The Client (C) is the endpoint software (GlobalProtect app) installed on user devices that authenticates to the portal, retrieves configuration, and establishes the tunnel to a gateway. The firewall management interface (A) is only the administrative web UI/CLI used to configure the firewall and is not itself a GlobalProtect infrastructure component, and an authentication server (E) is an external identity source (e.g., LDAP, RADIUS, SAML IdP) that GlobalProtect can reference for user authentication but is not a GlobalProtect component.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall management interface

    Why it's wrong here

    The firewall management interface configures the gateway and portal but is not itself a GlobalProtect infrastructure component; the infrastructure comprises the portal, gateway and agent. It is tempting because administrators do use it to configure GlobalProtect, yet the question asks what constitutes the infrastructure, not where settings live.

  • ✓

    GlobalProtect Gateway

    Why this is correct

    The GlobalProtect gateway is a core infrastructure component, terminating client tunnels and enforcing security policy for remote users. It satisfies the stem's requirement by providing the data-plane endpoint that agents connect to, distinct from the portal's configuration role. Gateways can be deployed on firewalls or dedicated appliances, scaling across multiple regions.

  • ✓

    GlobalProtect Client

    Why this is correct

    The GlobalProtect Client is the endpoint software installed on user devices, satisfying the infrastructure requirement for a component that initiates tunnels to the portal and gateway. It authenticates users via Microsoft Entra ID or certificates, then establishes the VPN connection, making it an essential piece of the GlobalProtect architecture alongside the portal and gateway.

  • ✓

    GlobalProtect Portal

    Why this is correct

    The GlobalProtect portal is a core infrastructure component, hosting the client configuration and authentication profiles that gateways rely on. It satisfies the stem's requirement by acting as the central entry point where endpoints authenticate via Microsoft Entra ID and retrieve the gateway list, enabling initial agent provisioning across the deployment.

  • ✗

    Authentication server

    Why it's wrong here

    An authentication server is an external identity source that GlobalProtect can query; it is not a GlobalProtect infrastructure component. It is tempting because portal and gateway authentication depends on it, but the infrastructure comprises the portal, gateways, and agents, with authentication servers configured separately.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.