Courseiva

PCNSE Practice Question: Securing Users and Applications with Authentication

Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?

⚠ Common exam trap

Watch out — candidates often assume RADIUS or LDAP support SSO because they are common authentication protocols, but neither provides the ticket or assertion exchange required for true single sign-on; only Kerberos and SAML implement SSO mechanisms in Palo Alto firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kerberos

Kerberos (option C) supports SSO because it uses ticket-based authentication where the client obtains a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC) and presents it to the firewall without re-entering credentials. SAML (option E) supports SSO by exchanging signed XML assertions between an identity provider (IdP) and the firewall, enabling browser-based federated single sign-on.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LDAP

    Why it's wrong here

    LDAP authenticates credentials against a directory but returns no Kerberos or SAML ticket, so the firewall cannot accept an existing session token for SSO. It tempts because LDAP is the usual directory source for user and group lookups, and it would be correct for plain directory-based authentication without SSO.

  • ✗

    Local Database

    Why it's wrong here

    The local database stores credentials on the firewall itself, so every login requires the user to re-enter a username and password; no external identity provider issues a reusable session token. It tempts as a fallback when no directory or IdP is reachable, which is exactly when SSO is impossible.

  • ✓

    Kerberos

    Why this is correct

    Kerberos uses ticket-granting tickets issued by a domain controller, so a user who has already authenticated to the domain presents a service ticket to the firewall transparently. This delivers SSO because the firewall trusts the KDC's tickets instead of prompting for credentials again.

  • ✗

    RADIUS

    Why it's wrong here

    RADIUS authenticates each session against a shared secret and returns accept or reject, without issuing a Kerberos ticket the firewall can consume for SSO. It tempts because RADIUS is the standard choice for 802.1X and MFA-backed authentication, but that is authentication, not single sign-on.

  • ✓

    SAML

    Why this is correct

    SAML is a browser-based federation standard, so the firewall can redirect users to an external identity provider and accept signed assertions, granting SSO without re-prompting for credentials. This satisfies the SSO requirement by federating authentication rather than validating credentials directly against a local user database.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.