nerdexam
Palo_Alto_Networks

PCNSA · Question #133

Which type of administrator account cannot be used to authenticate user traffic flowing through the firewall's data plane?

The correct answer is D. local user. A 'local user' in PAN-OS refers to a locally defined administrator account used exclusively for managing the firewall via the management plane (GUI, CLI, or API). These accounts have no role in authenticating end-user traffic passing through the data plane. Authentication…

Submitted by priya_blr· Apr 18, 2026Securing Traffic

Question

Which type of administrator account cannot be used to authenticate user traffic flowing through the firewall's data plane?

Options

  • AKerberos user
  • BSAML user
  • Clocal database user
  • Dlocal user

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (24)

Explanation

A 'local user' in PAN-OS refers to a locally defined administrator account used exclusively for managing the firewall via the management plane (GUI, CLI, or API). These accounts have no role in authenticating end-user traffic passing through the data plane. Authentication policies for data-plane traffic can reference authentication profiles backed by Kerberos (A), SAML (B), or a local user database (C)-the local database stores non-admin end-user credentials and is a valid authentication source for Captive Portal and Authentication policies. Local admin accounts (D) are strictly management plane constructs and cannot be referenced in authentication profiles for data-plane user traffic.

Topics

#User Authentication#Administrator Accounts#Data Plane#Management Plane

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice