nerdexam
Palo_Alto_Networks

PCNSE · Question #254

Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)

The correct answer is A. TACACS+ E. SAML F. RADIUS. External service The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes

Submitted by certguy· Apr 18, 2026Deploy and Configure

Question

Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)

Options

  • ATACACS+
  • BKerberos
  • CPAP
  • DLDAP
  • ESAML
  • FRADIUS

How the community answered

(33 responses)
  • A
    88% (29)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

External service The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor- Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. For details, see: Configure SAML Authentication Configure TACACS+ Authentication Configure RADIUS Authentication https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/firewall-administration/manage- firewall-administrators/administrative-authentication.html

Topics

#Authentication Services#User-ID#Role Mapping#External Authentication

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice