PCNSE · Question #320
An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object…
The correct answer is A. default-no-captive-portal. In Authentication Policy, enforcement objects define what action is taken when a user matches a rule. To exempt a specific group from authentication entirely (i.e., allow them through without any authentication challenge), the administrator must select the…
Question
An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object should they select?
Options
- Adefault-no-captive-portal
- Bdefault-authentication-bypass
- Cdefault-browser-challenge
- Ddefault-web-form
How the community answered
(40 responses)- A95% (38)
- B3% (1)
- C3% (1)
Explanation
In Authentication Policy, enforcement objects define what action is taken when a user matches a rule. To exempt a specific group from authentication entirely (i.e., allow them through without any authentication challenge), the administrator must select the 'default-no-captive-portal' enforcement object (A). This built-in object explicitly bypasses the captive portal and any authentication requirement for matching traffic. 'default-web-form' (D) and 'default-browser-challenge' (C) are used to prompt users for credentials, while 'default-authentication-bypass' (B) is not a standard PAN-OS authentication enforcement object name - the correct exemption object is 'default-no-captive-portal'.
Topics
Community Discussion
No community discussion yet for this question.