nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #36

In an authentication sequence, what happens if the "Continue on client cert failure" option is enabled?

The correct answer is A. The firewall will skip client certificate authentication and proceed to the next authentication profile. In Palo Alto Networks authentication sequences, client certificate authentication can be configured as one step in a multi-factor or multi-method sequence. When 'Continue on client cert failure' is enabled, the firewall treats a client certificate failure (e.g., missing…

User-ID and Authentication

Question

In an authentication sequence, what happens if the "Continue on client cert failure" option is enabled?

Options

  • AThe firewall will skip client certificate authentication and proceed to the next authentication profile
  • BThe firewall will deny access if the client certificate is invalid.
  • CThe firewall will prompt the user to provide a valid client certificate.
  • DThe firewall will log the failure and terminate the session.

How the community answered

(17 responses)
  • A
    94% (16)
  • C
    6% (1)

Explanation

In Palo Alto Networks authentication sequences, client certificate authentication can be configured as one step in a multi-factor or multi-method sequence. When 'Continue on client cert failure' is enabled, the firewall treats a client certificate failure (e.g., missing, invalid, or untrusted certificate) as a non-fatal event and moves forward to the next authentication profile in the sequence rather than immediately denying access. This allows fallback to username/password or other methods. Without this option enabled, a cert failure would block the authentication attempt entirely.

Topics

#Authentication Profiles#Client Certificates#Authentication Sequence#Firewall Configuration

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice