ExamGecko
Question list
Search
Search

Related questions











Question 298 - PCNSE discussion

Report
Export

Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the firewall? (Choose three.)

A.
RADIUS
Answers
A.
RADIUS
B.
TACACS+
Answers
B.
TACACS+
C.
Kerberos
Answers
C.
Kerberos
D.
LDAP
Answers
D.
LDAP
E.
SAML
Answers
E.
SAML
Suggested answer: A, B, E

Explanation:

According to the Palo Alto Networks documentation1, the firewall can use three external authentication services to authenticate admins into the Palo Alto Networks NGFW without creating administrator accounts on the firewall: RADIUS, TACACS+, and SAML. These services allow the firewall to verify the credentials of admins against an external server and grant them access based on their assigned roles and permissions. Therefore, the correct answer is A, B, and E.

The other options are not external authentication services that the firewall can use to authenticate admins:

Kerberos: This option is not an external authentication service that the firewall can use to authenticate admins. Kerberos is a protocol that allows users to access network resources using a single sign-on mechanism. The firewall can use

Kerberos to authenticate users for GlobalProtect VPN or Captive Portal, but not for admin access2.

LDAP: This option is not an external authentication service that the firewall can use to authenticate admins. LDAP is a protocol that allows querying and modifying directory services over a network. The firewall can use LDAP to retrieve user and group information from an external server, but not to authenticate admins3.

Reference: 1: https://docs.paloaltonetworks.com/pan-os/9-1/pan-osadmin/authentication/authentication-types/external-authentication-services 2:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authenticationtypes/kerberos-authentication 3:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-osadmin/user-id/map-ip-addresses-to-users/map-ip-addresses-to-users-using-an-ldap-server

asked 23/09/2024
Lazar Marinovic
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first