nerdexam
Palo_Alto_Networks

PCNSE · Question #241

An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between Panorama and the managed firewalls and Log Collectors. How would the adminis

The correct answer is A. Use custom certificates. Using custom certificates (A) from the enterprise's own PKI is the correct approach for establishing a unique, organization-specific chain of trust for mutual authentication between Panorama and its managed devices. Custom certificates allow the administrator to replace the defau

Submitted by anjalisingh· Apr 18, 2026Deploy and Configure

Question

An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between Panorama and the managed firewalls and Log Collectors. How would the administrator establish the chain of trust?

Options

  • AUse custom certificates
  • BEnable LDAP or RADIUS integration
  • CSet up multi-factor authentication
  • DConfigure strong password authentication

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    7% (2)
  • C
    14% (4)
  • D
    3% (1)

Explanation

Using custom certificates (A) from the enterprise's own PKI is the correct approach for establishing a unique, organization-specific chain of trust for mutual authentication between Panorama and its managed devices. Custom certificates allow the administrator to replace the default Palo Alto Networks-signed certificates with certificates issued by the internal CA, ensuring both parties can cryptographically verify each other's identity. LDAP/RADIUS (B) handles user authentication, not device-to-device trust. Multi-factor authentication (C) and strong password authentication (D) are user access controls and do not address the device mutual authentication requirement.

Topics

#Custom Certificates#PKI#Mutual Authentication#Panorama Device Management

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice