NGFW-ENGINEER · Question #28
An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panor
Sign in or unlock NGFW-ENGINEER to reveal the answer and full explanation for question #28. The question stem and answer options stay visible for context.
Question
An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy. Which approach ensures continuous, secure connectivity and consistent policy enforcement?
Options
- AUse a wildcard certificate from a public CA, disable all revocation checks to reduce latency, and
- BDistribute root and intermediate CAs via Panorama template, use distinct certificate profiles for
- CConfigure a single certificate profile for both user and machine certificates. Rely solely on CRLs
- DDeploy self-signed certificates on each firewall, allow IP-based authentication to override
Unlock NGFW-ENGINEER to see the answer
You've previewed enough free NGFW-ENGINEER questions. Unlock NGFW-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.