nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #27

An engineer is implementing a new rollout of SAML for administrator authentication across a company's Palo Alto Networks NGFWs. User authentication on company firewalls is currently performed with…

The correct answer is B. Create an authentication sequence that orders the RADIUS profile first followed by the SAML C. Create and apply an authentication profile using the SAML Identity Provider Server Profile. To run SAML and RADIUS in parallel during a transition period, two things are needed. First (Answer C), you must create an Authentication Profile that references the SAML Identity Provider Server Profile - this is the fundamental step that enables SAML as a valid authentication…

Configure and Manage Administrator Authentication

Question

An engineer is implementing a new rollout of SAML for administrator authentication across a company's Palo Alto Networks NGFWs. User authentication on company firewalls is currently performed with RADIUS, which will remain available for six months, until it is decommissioned. The company wants both authentication types to be running in parallel during the transition to SAML. Which two actions meet the criteria? (Choose two.)

Options

  • ACreate a testing and rollback plan for the transition from Radius to SAML, as the two
  • BCreate an authentication sequence that orders the RADIUS profile first followed by the SAML
  • CCreate and apply an authentication profile using the SAML Identity Provider Server Profile,
  • DCreate and add the "SAML Identity Provider" Server Profile to the authentication profile for the

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    81% (29)
  • D
    14% (5)

Explanation

To run SAML and RADIUS in parallel during a transition period, two things are needed. First (Answer C), you must create an Authentication Profile that references the SAML Identity Provider Server Profile - this is the fundamental step that enables SAML as a valid authentication method on the firewall. Second (Answer B), you create an Authentication Sequence that lists the RADIUS profile first and the SAML profile second. An authentication sequence allows the firewall to attempt multiple authentication methods in a defined order, so RADIUS continues working for existing users while SAML is simultaneously available for administrators being migrated. Answer A describes a process plan, not a firewall configuration. Answer D is incomplete as written and does not establish parallel operation.

Topics

#SAML Authentication#RADIUS Authentication#Authentication Profiles#Authentication Sequences

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice