nerdexam
Palo_Alto_Networks

SSE-ENGINEER · Question #18

Which statement is valid in relation to certificates used for GlobalProtect and pre-logon?

The correct answer is C. Certificates must be deployed in the Machine Certificate Store. For GlobalProtect with pre-logon, certificates must be installed in the Machine Certificate Store to ensure that authentication occurs before user login. This allows the GlobalProtect client to establish a VPN connection before the user logs in, enabling access to corporate…

Authentication and PKI

Question

Which statement is valid in relation to certificates used for GlobalProtect and pre-logon?

Options

  • AA public certificate authority (CA) must sign and validate all certificates used.
  • BThe certificate used for pre-logon must include both Subject and Subject-Alt fields.
  • CCertificates must be deployed in the Machine Certificate Store.
  • DThe GlobalProtect agent may be used to distribute pre-logon certificates.

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    73% (35)
  • D
    17% (8)

Explanation

For GlobalProtect with pre-logon, certificates must be installed in the Machine Certificate Store to ensure that authentication occurs before user login. This allows the GlobalProtect client to establish a VPN connection before the user logs in, enabling access to corporate resources such as domain controllers and authentication services. Using machine certificates ensures secure authentication and eliminates dependency on user credentials at the pre-logon stage.

Topics

#GlobalProtect#pre-logon#certificates#Machine Certificate Store

Community Discussion

No community discussion yet for this question.

Full SSE-ENGINEER Practice