nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #28

An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panor

Sign in or unlock NGFW-ENGINEER to reveal the answer and full explanation for question #28. The question stem and answer options stay visible for context.

GlobalProtect Configuration and Management

Question

An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy. Which approach ensures continuous, secure connectivity and consistent policy enforcement?

Options

  • AUse a wildcard certificate from a public CA, disable all revocation checks to reduce latency, and
  • BDistribute root and intermediate CAs via Panorama template, use distinct certificate profiles for
  • CConfigure a single certificate profile for both user and machine certificates. Rely solely on CRLs
  • DDeploy self-signed certificates on each firewall, allow IP-based authentication to override

Unlock NGFW-ENGINEER to see the answer

You've previewed enough free NGFW-ENGINEER questions. Unlock NGFW-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#GlobalProtect#Certificate Authentication#Panorama#PKI Management
Full NGFW-ENGINEER Practice