Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard

A security auditor is reviewing the administrative access configuration on a Palo Alto Networks firewall. They observe that multiple administrators are using a shared local 'admin' account with a generic password. To improve security and accountability, which administrative access method should be implemented to ensure unique user authentication and centralized management of credentials?

  1. ALocal user database with individual accounts.
  2. BRADIUS authentication profile.
  3. CLDAP authentication profile.
  4. DSAML authentication profile.
Show answer & explanation

Correct answer: C. LDAP authentication profile.

To ensure unique user authentication and centralized management of credentials for multiple administrators, an LDAP authentication profile is the most suitable method. It integrates with existing directory services like Active Directory, allowing administrators to use their enterprise credentials and providing centralized control, auditing, and password policies, which is superior to local accounts or other methods for this scale.

Why the other options are wrong

  • A. While better than a shared account, managing individual local accounts on each firewall lacks centralization and scalability.
  • B. RADIUS can provide centralized authentication but is typically used for network access control or VPNs, and while possible for firewall admin, LDAP is generally preferred for integration with enterprise directories for user management.
  • D. SAML is primarily for single sign-on (SSO) web applications and cloud services, not typically the primary method for firewall administrative access credentials.

LDAP Admin Authentication

Using an LDAP authentication profile on a Palo Alto Networks firewall to authenticate administrative users against a centralized directory service.

  • Provides unique user accounts and centralized credential management.
  • Integrates with Active Directory and other LDAP-compatible directories.
  • Enhances security, accountability, and simplifies password management.

Memory trick: To manage all your admin 'keys' centrally, 'LDAP' lets your firewall 'look up' users in the main directory.

More Initial Configuration and Management questions