nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #123

After a recent security audit, a company is required to enforce more strict validation for all certificate-based authentication, including for GlobalProtect clients. An engineer observes the…

The correct answer is D. Certificate profile. A Certificate Profile (D) is the PAN-OS configuration object that defines how the firewall validates certificates presented by clients or peers during authentication. It specifies which CA certificates are trusted, and critically, it contains the settings for certificate…

Authentication Management

Question

After a recent security audit, a company is required to enforce more strict validation for all certificate-based authentication, including for GlobalProtect clients. An engineer observes the firewall accepting certificates from a recently compromised intermediate certificate authority (CA). The engineer needs to update the firewall configuration to use an Online Certificate Status Protocol (OCSP) responder to check for revoked certificates in real time. In which configuration object would the engineer enable OCSP verification for the CAs used in the authentication process?

Options

  • AAuthentication sequence
  • BDecryption profile
  • CSSL/TLS service profile
  • DCertificate profile

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    15% (4)
  • C
    7% (2)
  • D
    74% (20)

Explanation

A Certificate Profile (D) is the PAN-OS configuration object that defines how the firewall validates certificates presented by clients or peers during authentication. It specifies which CA certificates are trusted, and critically, it contains the settings for certificate revocation checking - including enabling OCSP and specifying the OCSP responder URL. When the firewall performs certificate-based authentication (e.g., for GlobalProtect clients), it references the Certificate Profile to determine whether to check revocation status via OCSP and how to perform that check. An Authentication sequence (A) chains together multiple authentication methods but does not contain certificate validation settings. A Decryption profile (B) governs SSL/TLS inspection behavior for decrypted traffic, not authentication certificate validation. An SSL/TLS service profile (C) defines inbound TLS protocol parameters for firewall-hosted services but does not configure OCSP revocation checking for authenticating CAs.

Topics

#OCSP#Certificate Profiles#GlobalProtect#Authentication

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice