PCNSE Deploy and Configure Firewalls Practice Question
Which THREE of the following are mandatory components for GlobalProtect client connectivity?
⚠ Common exam trap
Many candidates confuse optional features like client certificates or DNS suffixes with mandatory components, but the exam specifically tests that only the portal, gateway, and authentication profile are required for the client to establish connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication profile.
Option A (Authentication profile) is correct because the GlobalProtect portal and/or gateway must reference an authentication profile to authenticate users before granting access, making it a mandatory component for client connectivity. Option D (Gateway configuration) is correct because the GlobalProtect gateway is the actual security enforcement point that terminates the client tunnel and provides access to protected resources; without it, clients cannot establish connectivity. Option E (Portal configuration) is correct because the portal is the initial connection point that delivers client configuration and gateway information to the GlobalProtect agent, and it is required for the client to discover and connect to gateways. Option B (Client certificate) is not mandatory because certificate-based authentication is only one possible method; username/password or other authentication methods can be used instead. Option C (DNS suffix) is not mandatory because it is an optional configuration setting used for split-DNS or internal name resolution, not a requirement for establishing GlobalProtect connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authentication profile.
Why this is correct
An authentication profile is mandatory because GlobalProtect must verify user identity before granting tunnel access. It binds the portal or gateway to a specific authentication method, such as LDAP, SAML or Kerberos, satisfying the requirement that every client connection is authenticated. Without it, no user credential validation occurs and connectivity cannot be established.
- ✗
Client certificate.
Why it's wrong here
A client certificate is optional in GlobalProtect; authentication can rely on user credentials, SAML, or machine certificates instead. It is tempting because certificate-based authentication is a valid configuration, but it is a selectable method rather than a mandatory component for client connectivity.
- ✗
DNS suffix.
Why it's wrong here
A DNS suffix is not mandatory; the portal and gateway can be reached by FQDN or IP without one. It is tempting because split-tunnel and internal name resolution often depend on a suffix, but that is a design choice, not a prerequisite for establishing the tunnel.
- ✓
Gateway configuration.
Why this is correct
A gateway configuration is mandatory because it terminates the GlobalProtect tunnel and enforces security policy for connected clients. The portal directs clients to a gateway, but without at least one gateway defined, no VPN tunnel can be established.
- ✓
Portal configuration.
Why this is correct
A portal configuration is mandatory because it defines the GlobalProtect portal that clients connect to first, delivering agent configuration and the list of available gateways. Without a portal, clients cannot discover or authenticate to any gateway, so connectivity cannot be established.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.