nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #201

What two authentication methods on the Palo Alto Networks firewalls support authentication and authorization for role-based access control? (Choose two.)

The correct answer is A. SAML B. TACACS+. The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML…

Authentication and Authorization

Question

What two authentication methods on the Palo Alto Networks firewalls support authentication and authorization for role-based access control? (Choose two.)

Options

  • ASAML
  • BTACACS+
  • CLDAP
  • DKerberos

How the community answered

(62 responses)
  • A
    79% (49)
  • C
    8% (5)
  • D
    13% (8)

Explanation

The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage- firewall-administrators/administrative-authentication.html

Topics

#SAML#TACACS+#RBAC#authentication methods

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice