nerdexam
Palo_Alto_Networks

PCNSC · Question #42

Which three user authentication services can be modified in to provide the Palo Alto Networks NGFW with both username and role names? (Choose three.)

The correct answer is B. SAML D. TACACS+ E. RADIUS. The administrative accounts are DEFINED on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML serv

User-ID, Decryption, and Authentication

Question

Which three user authentication services can be modified in to provide the Palo Alto Networks NGFW with both username and role names? (Choose three.)

Options

  • APAP
  • BSAML
  • CLDAP
  • DTACACS+
  • ERADIUS
  • FKerberos

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    87% (46)
  • C
    4% (2)
  • F
    2% (1)

Explanation

The administrative accounts are DEFINED on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. Kerberos, LDAP, and PAP required the admin account to be locally defined on the firewall.

Topics

#authentication services#SAML#TACACS+#RADIUS

Community Discussion

No community discussion yet for this question.

Full PCNSC Practice