nerdexam
Palo_Alto_Networks

PCNSA · Question #127

Which three types of authentication services can be used to authenticate user traffic flowing through the firewalls data plane? (Choose three )

The correct answer is B. SAML 2.0 D. Kerberos E. TACACS+. For authenticating user traffic on the data plane (e.g., Captive Portal, GlobalProtect, Authentication policy), Palo Alto Networks supports SAML 2.0 (B), Kerberos (D), and TACACS+ (E). SAML 1.0 (C) is not supported - only the current SAML 2.0 standard is. Plain TACACS (A…

Submitted by diego_uy· Apr 18, 2026Securing Traffic

Question

Which three types of authentication services can be used to authenticate user traffic flowing through the firewalls data plane? (Choose three )

Options

  • ATACACS
  • BSAML 2.0
  • CSAML 1.0
  • DKerberos
  • ETACACS+

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    88% (38)
  • C
    9% (4)

Explanation

For authenticating user traffic on the data plane (e.g., Captive Portal, GlobalProtect, Authentication policy), Palo Alto Networks supports SAML 2.0 (B), Kerberos (D), and TACACS+ (E). SAML 1.0 (C) is not supported - only the current SAML 2.0 standard is. Plain TACACS (A, without the '+') refers to the original, largely obsolete protocol that is not supported; TACACS+ is the supported variant. RADIUS and LDAP are also valid options but were not listed as choices here.

Topics

#User Authentication#Data Plane Security#Authentication Protocols#Identity Management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice