Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 46 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 46
Topic #: 1
[All PCNSE Questions]

Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)

  • A. Kerberos
  • B. PAP
  • C. SAML
  • D. TACACS+
  • E. RADIUS
  • F. LDAP
Show Suggested Answer Hide Answer
Suggested Answer: CDE 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Dabouncer
Highly Voted 5 years, 7 months ago
The answer should be C, D, and E https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication
upvoted 16 times
...
kerberos
Highly Voted 4 years, 3 months ago
The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor-Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall.
upvoted 10 times
...
bing2021
Most Recent 4 months, 2 weeks ago
Selected Answer: CDE
ldap is not matching questions.
upvoted 1 times
...
Marshpillowz
10 months ago
Selected Answer: CDE
C, D and E are correct
upvoted 1 times
...
JRKhan
10 months, 2 weeks ago
Selected Answer: CDE
CDE are correct. With LDAP, you have to define the admin user locally otherwise there is no other way to assign a role to the user. With Radius, tacacs and saml the firewall can utilise the received VSAs or SAML attributes to map to the roles locally defined on the firewall.
upvoted 2 times
...
awtsuritacuna
1 year, 11 months ago
The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor-Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication
upvoted 2 times
...
1Adrian1
2 years, 7 months ago
A,C.F is the correct answer
upvoted 1 times
...
confusion
2 years, 9 months ago
Selected Answer: CDE
Without defining user only CDE
upvoted 2 times
...
lgkhan
3 years ago
Selected Answer: CDE
CDE are the correct answers.
upvoted 2 times
...
vj77
3 years, 6 months ago
LDAP is also an answer. I don't understand why NOT, CDEF should be correct. I did LDAP for admin users myself. correct me if I'm wrong. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-ldap-authentication
upvoted 1 times
confusion
2 years, 9 months ago
Ldap requires user to be defined on the FW for authentication and question asks without configuring user.
upvoted 1 times
[Removed]
9 months, 2 weeks ago
no it doesn’t. I have LDAP and RADIUS auth profile and only local admin under administrators :)
upvoted 1 times
...
...
eyelasers1
2 years, 9 months ago
Per https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html , LDAP can only be used for authentication. The authorization requires that there be a local admin account.
upvoted 2 times
...
...
rocioha
3 years, 8 months ago
C-D-E https://origin-docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-local-or-external-authentication-for-firewall-administrators.html
upvoted 1 times
...
hpbdcb
3 years, 12 months ago
"...without defining a corresponding admin account on the local firewall?" so what?! it talks about "authenticate" only! So that means we do not talk about "authorization" here (i.e. role mapping). When it comes to authentication only all of them could be used: ACDEF but.. is that what they wanna see here? more likely they wanna know which can be used without any need to create a local account at all (i.e even authorization) and that leads to: CDE according to: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-local-or-external-authentication-for-firewall-administrators.html#id7484db35-8218-421b-9847-eab796beea99 so most likely CDE is what they wanna see here - imho
upvoted 4 times
...
PacketFairy
4 years ago
RADIUS does not need an admin configured. VSAs (Vendor specific attributes) would be used. I log in as Jack, RADIUS sends back a success and a VSA value. If that value corresponds to read/write administrator, I get logged in as a superuser. There are VSAs for read only and user (Global protect access but not admin). I am unsure what other Auth methods can use VSA or a similar mechanisim. If admin users are configured with RADIUS, no need for VSA.
upvoted 1 times
...
lol1000
4 years ago
c, d, e https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html
upvoted 1 times
...
kambata
4 years ago
Correct answer is C, D and E, please !
upvoted 1 times
...
DaveDK
4 years, 2 months ago
The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor-Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. For details, see:
upvoted 1 times
...
jin3209
4 years, 4 months ago
what is the right answer for the exam alone? ACF or CDE?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...