PCNSE Practice Question: Securing Users and Applications with Authentication
Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?
⚠ Common exam trap
Watch out — candidates often assume RADIUS or LDAP support SSO because they are common authentication protocols, but neither provides the ticket or assertion exchange required for true single sign-on; only Kerberos and SAML implement SSO mechanisms in Palo Alto firewalls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kerberos
Kerberos (option C) supports SSO because it uses ticket-based authentication where the client obtains a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC) and presents it to the firewall without re-entering credentials. SAML (option E) supports SSO by exchanging signed XML assertions between an identity provider (IdP) and the firewall, enabling browser-based federated single sign-on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LDAP
Why it's wrong here
LDAP authenticates credentials against a directory but returns no Kerberos or SAML ticket, so the firewall cannot accept an existing session token for SSO. It tempts because LDAP is the usual directory source for user and group lookups, and it would be correct for plain directory-based authentication without SSO.
- ✗
Local Database
Why it's wrong here
The local database stores credentials on the firewall itself, so every login requires the user to re-enter a username and password; no external identity provider issues a reusable session token. It tempts as a fallback when no directory or IdP is reachable, which is exactly when SSO is impossible.
- ✓
Kerberos
Why this is correct
Kerberos uses ticket-granting tickets issued by a domain controller, so a user who has already authenticated to the domain presents a service ticket to the firewall transparently. This delivers SSO because the firewall trusts the KDC's tickets instead of prompting for credentials again.
- ✗
RADIUS
Why it's wrong here
RADIUS authenticates each session against a shared secret and returns accept or reject, without issuing a Kerberos ticket the firewall can consume for SSO. It tempts because RADIUS is the standard choice for 802.1X and MFA-backed authentication, but that is authentication, not single sign-on.
- ✓
SAML
Why this is correct
SAML is a browser-based federation standard, so the firewall can redirect users to an external identity provider and accept signed assertions, granting SSO without re-prompting for credentials. This satisfies the SSO requirement by federating authentication rather than validating credentials directly against a local user database.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.