nerdexam
Palo_Alto_Networks

PCNSE · Question #225

Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose…

The correct answer is C. SAML D. TACACS+ E. RADIUS. The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML…

Submitted by khalil_dz· Apr 18, 2026Deploy and Configure

Question

Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)

Options

  • AKerberos
  • BPAP
  • CSAML
  • DTACACS+
  • ERADIUS
  • FLDAP

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    89% (49)
  • F
    5% (3)

Explanation

The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage- firewall-administrators/administrative-authentication

Topics

#Admin Authentication#Remote Authentication#Authentication Services#NGFW Management

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice