Courseiva

PCNSE Practice Question: Securing Users and Applications with Authentication

Which TWO are prerequisites for using Authentication Policy? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse prerequisites with features that enhance security (like SSL decryption) or confuse the order of configuration steps, thinking a security rule with user attributes must exist before the authentication policy can be used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User-ID is configured

Authentication Policy in PAN-OS requires User-ID to be configured (option A) because the policy matches traffic based on user and group mappings that User-ID provides; without an active User-ID source (such as an agent, syslog listener, or server monitoring), the firewall has no user-to-IP mapping to enforce authentication rules. It also requires an authentication profile (option E), since the Authentication Policy references an authentication profile to define the authentication method (e.g., LDAP, RADIUS, SAML, Kerberos, or local database) and the authentication portal settings used to challenge users. Option B is incorrect because transparent mode is not required—Authentication Policy works in L3, L2, virtual wire, and tap modes. Option C is incorrect because SSL decryption is not a prerequisite; it is only needed to identify users in encrypted traffic, not to use Authentication Policy itself. Option D is incorrect because a security policy rule with user attributes is not required to create or use Authentication Policy; Authentication Policy is evaluated before security policy and generates the user mapping that security rules may later reference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    User-ID is configured

    Why this is correct

    Authentication Policy enforces user- and group-based rules, so it requires User-ID to map source IP addresses to directory identities before any policy can match. Without User-ID configured, the firewall cannot resolve usernames or groups, leaving the policy unevaluable. This satisfies the stem's prerequisite constraint directly.

  • ✗

    The firewall is in transparent mode

    Why it's wrong here

    Authentication Policy requires a Layer 3 routed or virtual-wire deployment to intercept and redirect user authentication; transparent mode does not support it. Transparent mode is tempting because it forwards traffic without IP changes, but it cannot host the authentication portal.

  • ✗

    SSL decryption is enabled

    Why it's wrong here

    Authentication Policy operates on user and group identity in security rules; SSL decryption is not required for it to function. Decryption is tempting because it exposes application-layer identity in encrypted traffic, which matters for App-ID, not for user-based policy enforcement.

  • ✗

    A security policy rule exists with user attributes

    Why it's wrong here

    Authentication Policy is evaluated before security policy rules, so a rule containing user attributes is not a prerequisite. It is tempting because user-based rules are the goal, but the policy itself supplies the user mapping that those rules then reference.

  • ✓

    An authentication profile is configured

    Why this is correct

    Authentication policy enforces rules that reference an authentication profile, which defines the authentication service, method, and certificate settings. Without a configured profile, the policy has no authentication mechanism to apply, so creating one is a genuine prerequisite. The profile supplies the parameters the policy then maps to users and zones.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.