Exam PCNSE All QuestionsBrowse all questions from this exam
Question 450

Which three authentication types can be used to authenticate users? (Choose three.)

    Correct Answer: A, C, E

    Local database authentication is a common method where authentication is managed within a local database stored on the server. Kerberos single sign-on is a network authentication protocol that uses tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner. Cloud authentication service refers to the methods of authenticating users using cloud-based services, which often include integration with SAML or other federated identity systems. GlobalProtect client and PingID are not considered as standalone authentication types; GlobalProtect is a VPN solution, and PingID is a multi-factor authentication service.

Discussion
djedeenOptions: ACE

ACE, Per the links below. Also, PingID is a provider but MFA would be the authentication type.

certprep2021Options: ACD

Not sure why everyone is giving different answers. It's also true many questions are wrongly answered here https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types/multi-factor-authentication#idbc927952-a47e-4bec-ab80-0605a47b4873

notsosavyy

GlobalProtect is not an authentication type. GlobalProtect is simply a client or a portal, not a type of authentication.

Nawda

not sure why... because ure wrong too lol

evdwOptions: ACE

Correct answer A,C,E https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/configure-an-authentication-profile-and-sequence#idf258e497-4998-4a70-8676-aa9aba521a44

COBrienOptions: ACE

ACE https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/configure-an-authentication-profile-and-sequence#idf258e497-4998-4a70-8676-aa9aba521a44

alinio11Options: ABC

It's ABC; PingID is a valid MFA option: "For end-user authentication via Authentication Policy, the firewall directly integrates with several MFA platforms (Duo v2, Okta Adaptive, PingID, and RSA SecurID), as well as integrating through RADIUS or SAML for all other MFA platforms."https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types/multi-factor-authentication#idbc927952-a47e-4bec-ab80-0605a47b4873

kewokil120Options: ACE

adding my vote

DenskyDenOptions: ACE

ACE. See link posted below.

0d2fdfaOptions: ACE

Checked it on the firewall Answer is A,C E

YL123Options: ABC

A and C should be no doubt since they are mentioned in the PAN doc. However, under the same doc --> SAML(https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types/saml#id111aea26-0c56-4499-8a26-ea2ee8f43639) It mentioned the PingFederate, which is the PingID.

MarshpillowzOptions: ACE

A, C and E seem logical to me

JRKhanOptions: ACE

Voting for ACE. PingID is one of the MFA platforms palo firewall and panorama can integrate with. Kerberos and cloud authentication service are the external services that firewall can use to authenticate along with local authentication.

MetgatzOptions: ACE

ACE is about type not vendors

MetgatzOptions: AC

ACE is about type not vendors

wallakaOptions: ACE

Agreeing with earlier votes. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/configure-an-authentication-profile-and-sequence#idf258e497-4998-4a70-8676-aa9aba521a44

KaspinasOptions: ABC

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types