PCNSE · Question #402
An enterprise Information Security team has deployed policies based on AD groups to restrict user access to critical infrastructure systems. However, a recent phishing campaign against the organizatio
The correct answer is D. Configure a Captive Portal authentication policy that uses an authentication profile that references. To use Multi-Factor Authentication (MFA) for protecting sensitive services and applications, you must configure Captive Portal to display a web form for the first authentication factor and to record Authentication Timestamps. The firewall uses the timestamps to evaluate the timeo
Question
An enterprise Information Security team has deployed policies based on AD groups to restrict user access to critical infrastructure systems. However, a recent phishing campaign against the organization has prompted information Security to look for more controls that can secure access to critical assets. For users that need to access these systems, Information Security wants to use PAN-OS multi-factor authentication (MFA) integration to enforce MFA. What should the enterprise do to use PAN-OS MFA?
Options
- AUse a Credential Phishing agent to detect, prevent, and mitigate credential phishing campaigns.
- BCreate an authentication profile and assign another authentication factor to be used by a Captive
- CConfigure a Captive Portal authentication policy that uses an authentication sequence.
- DConfigure a Captive Portal authentication policy that uses an authentication profile that references
How the community answered
(47 responses)- A13% (6)
- B2% (1)
- C4% (2)
- D81% (38)
Explanation
To use Multi-Factor Authentication (MFA) for protecting sensitive services and applications, you must configure Captive Portal to display a web form for the first authentication factor and to record Authentication Timestamps. The firewall uses the timestamps to evaluate the timeouts for Authentication Policy rules. To enable additional authentication factors, you can integrate the firewall with MFA vendors through RADIUS or vendor APIs. After evaluating Authentication policy, the firewall evaluates Security policy, so you must configure rules for both policy types. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi- factor-authentication
Topics
Community Discussion
No community discussion yet for this question.