nerdexam
Palo_Alto_Networks

PCNSE · Question #718

Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)

The correct answer is A. TACACS+ C. SAML D. RADIUS. TACACS+ (A), SAML (C), and RADIUS (D) are the three external authentication services that can authenticate firewall administrators without requiring a pre-created local administrator account on the firewall. These protocols support returning role/privilege information in the…

Submitted by femi9· Apr 18, 2026Deploy and Configure

Question

Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)

Options

  • ATACACS+
  • BKerberos
  • CSAML
  • DRADIUS
  • ELDAP

How the community answered

(53 responses)
  • A
    92% (49)
  • B
    2% (1)
  • E
    6% (3)

Explanation

TACACS+ (A), SAML (C), and RADIUS (D) are the three external authentication services that can authenticate firewall administrators without requiring a pre-created local administrator account on the firewall. These protocols support returning role/privilege information in the authentication response itself: RADIUS uses Vendor-Specific Attributes (VSAs) from Palo Alto Networks, TACACS+ returns admin role details from the server, and SAML carries attributes from the IdP that map to admin roles. Kerberos (B) and LDAP (E) can verify a user's identity, but PAN-OS still requires a matching local admin account on the firewall to determine the admin's role and access level - they authenticate credentials but do not carry authorization/role data back to the firewall.

Topics

#Admin Authentication#External Services#NGFW Configuration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice