nerdexam
Palo_Alto_Networks

PCNSE · Question #454

A network administrator wants to deploy GlobalProtect with pre-logon for Windows 10 endpoints and follow Palo Alto Networks best practices. To install the certificate and key for an endpoint, which th

The correct answer is B. local computer store D. self-signed certificate E. machine certificate. For GlobalProtect pre-logon on Windows 10 endpoints, a machine certificate (which can be self-signed) along with its private key must be installed in the local computer store.

Submitted by layla.eg· Apr 18, 2026Deploy and Configure

Question

A network administrator wants to deploy GlobalProtect with pre-logon for Windows 10 endpoints and follow Palo Alto Networks best practices. To install the certificate and key for an endpoint, which three components are required? (Choose three.)

Exhibit

PCNSE question #454 exhibit

Options

  • Aserver certificate
  • Blocal computer store
  • Cprivate key
  • Dself-signed certificate
  • Emachine certificate

How the community answered

(47 responses)
  • A
    15% (7)
  • B
    79% (37)
  • C
    6% (3)

Why each option

For GlobalProtect pre-logon on Windows 10 endpoints, a machine certificate (which can be self-signed) along with its private key must be installed in the local computer store.

Aserver certificate

A server certificate is presented by the GlobalProtect gateway to the client for server authentication, not installed on the endpoint for client authentication.

Blocal computer storeCorrect

The local computer store on a Windows endpoint is the designated location for machine certificates used for system-level authentication, such as GlobalProtect pre-logon.

Cprivate key

While a private key is an integral part of any functional certificate, the options 'machine certificate' and 'self-signed certificate' already inherently include the requirement for their corresponding private keys to be present and usable.

Dself-signed certificateCorrect

A self-signed certificate can function as the machine certificate for GlobalProtect pre-logon, provided it is properly generated and the GlobalProtect gateway is configured to trust it.

Emachine certificateCorrect

A machine certificate is essential for GlobalProtect pre-logon, as it allows the endpoint to authenticate with the GlobalProtect gateway before a user logs in.

Concept tested: GlobalProtect pre-logon certificate requirements

Source: https://docs.paloaltonetworks.com/globalprotect/11-0/globalprotect-admin/globalprotect-quick-configs/pre-logon-windows-endpoints

Topics

#GlobalProtect#Pre-logon#Machine Certificates#Certificate Management

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice