PCNSE Practice Question: Securing Users and Applications with Authentication
You are a network security engineer for a multinational corporation with users in different regions. The company uses GlobalProtect for remote access and requires multi-factor authentication (MFA) using a mobile app for all users. Recently, users in the Asia-Pacific region have reported intermittent failures when authenticating via GlobalProtect. The symptoms include: after entering credentials on the GlobalProtect portal, the authentication challenge from the MFA provider times out after 30 seconds, and the user is disconnected. Users in other regions do not experience this issue. The GlobalProtect gateways and portals are configured with Authentication Profile that uses an LDAP server for primary authentication and an MFA vendor as authentication sequence. The MFA provider sends push notifications to users' mobile devices. The firewall logs show no errors related to LDAP or MFA, but the GlobalProtect logs indicate authentication timeouts. The firewall is located in the central data center, and the MFA provider's servers are in the United States. What should you do to resolve this issue?
⚠ Common exam trap
Many exam-takers assume the issue is with the MFA method or provider latency, leading them to choose option A or D, when in fact the problem is a misconfigured timeout value that is easily adjustable within the GlobalProtect portal and gateway settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the authentication timeout in the GlobalProtect portal and gateway configuration from 30 seconds to 60 seconds.
The authentication timeout in the GlobalProtect portal and gateway configuration defaults to 30 seconds, which is insufficient when high latency exists between the firewall (central data center) and the MFA provider's servers (United States). Users in the Asia-Pacific region experience additional network latency, causing the MFA push notification challenge to exceed the 30-second timeout. Increasing the timeout to 60 seconds accommodates this latency without altering the authentication method or requiring additional infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the authentication sequence to use a shorter MFA method like SMS instead of push notifications.
Why it's wrong here
SMS may also experience similar latency or even longer delays; the core issue is the timeout duration, not the method.
- ✗
Disable MFA for the Asia-Pacific region users temporarily until the MFA provider improves their latency.
Why it's wrong here
This violates the company's MFA requirement and introduces a security risk.
- ✓
Increase the authentication timeout in the GlobalProtect portal and gateway configuration from 30 seconds to 60 seconds.
Why this is correct
Increasing the timeout accommodates the higher latency for users in Asia-Pacific, allowing the MFA push to complete.
- ✗
Deploy a secondary MFA server instance in the Asia-Pacific region to reduce latency.
Why it's wrong here
Deploying a secondary MFA server instance in Asia-Pacific does not address the root cause, because the timeout occurs during the authentication sequence on the firewall itself, which is located in the central data centre and must communicate with the MFA provider’s servers in the United States; latency between the user’s mobile device and a local MFA server is irrelevant when the firewall’s own connection to the MFA provider is the bottleneck. This option is tempting because geographically distributing MFA servers reduces push-notification latency for end users, which would be the correct choice if the MFA provider’s servers were the direct source of the timeout, but here the firewall’s outbound connection to the US-based MFA provider is the failing link.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.