PCNSE Practice Question: Securing Users and Applications with Authentication
Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)
⚠ Common exam trap
Many candidates confuse external dependencies (like authentication servers or management interfaces) with the core GlobalProtect components, leading them to select options that are not part of the defined infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GlobalProtect Gateway
The three core components of the GlobalProtect infrastructure are the GlobalProtect Portal (D), the GlobalProtect Gateway (B), and the GlobalProtect Client (C). The Portal (D) is the entry point that hosts the agent configuration and delivers settings, client certificates, and the list of available gateways to endpoints. The Gateway (B) is the security enforcement point that provides the actual tunnel (SSL or IPSec) and applies security, decryption, and HIP policies to traffic. The Client (C) is the endpoint software (GlobalProtect app) installed on user devices that authenticates to the portal, retrieves configuration, and establishes the tunnel to a gateway. The firewall management interface (A) is only the administrative web UI/CLI used to configure the firewall and is not itself a GlobalProtect infrastructure component, and an authentication server (E) is an external identity source (e.g., LDAP, RADIUS, SAML IdP) that GlobalProtect can reference for user authentication but is not a GlobalProtect component.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall management interface
Why it's wrong here
The firewall management interface configures the gateway and portal but is not itself a GlobalProtect infrastructure component; the infrastructure comprises the portal, gateway and agent. It is tempting because administrators do use it to configure GlobalProtect, yet the question asks what constitutes the infrastructure, not where settings live.
- ✓
GlobalProtect Gateway
Why this is correct
The GlobalProtect gateway is a core infrastructure component, terminating client tunnels and enforcing security policy for remote users. It satisfies the stem's requirement by providing the data-plane endpoint that agents connect to, distinct from the portal's configuration role. Gateways can be deployed on firewalls or dedicated appliances, scaling across multiple regions.
- ✓
GlobalProtect Client
Why this is correct
The GlobalProtect Client is the endpoint software installed on user devices, satisfying the infrastructure requirement for a component that initiates tunnels to the portal and gateway. It authenticates users via Microsoft Entra ID or certificates, then establishes the VPN connection, making it an essential piece of the GlobalProtect architecture alongside the portal and gateway.
- ✓
GlobalProtect Portal
Why this is correct
The GlobalProtect portal is a core infrastructure component, hosting the client configuration and authentication profiles that gateways rely on. It satisfies the stem's requirement by acting as the central entry point where endpoints authenticate via Microsoft Entra ID and retrieve the gateway list, enabling initial agent provisioning across the deployment.
- ✗
Authentication server
Why it's wrong here
An authentication server is an external identity source that GlobalProtect can query; it is not a GlobalProtect infrastructure component. It is tempting because portal and gateway authentication depends on it, but the infrastructure comprises the portal, gateways, and agents, with authentication servers configured separately.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.