Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A security engineer is configuring administrative access to a new Palo Alto Networks firewall. The company policy dictates that all administrative logins must use a centralized authentication system and secure protocols. Which combination of settings should the engineer configure on the firewall to meet these requirements?
- ARADIUS server profile and SSH/HTTPS for management access.
- BLocal user database and HTTP/Telnet for management access.
- CLDAP server profile and SNMPv2c for management access.
- DTACACS+ server profile and FTP/HTTP for management access.
Show answer & explanationAnswer & explanation
Correct answer: A. RADIUS server profile and SSH/HTTPS for management access.
To use a centralized authentication system, an external authentication server profile (like RADIUS, LDAP, or TACACS+) must be configured. For secure protocols, SSH (for CLI) and HTTPS (for WebUI) are the standard choices for Palo Alto Networks firewalls.
Why the other options are wrong
- B. Local user database is not centralized. HTTP/Telnet are insecure protocols.
- C. LDAP is centralized, but SNMPv2c is for monitoring, not administrative login, and is less secure than SNMPv3.
- D. TACACS+ is centralized, but FTP/HTTP are insecure and not used for administrative login to the WebUI/CLI.
Secure Administrative Access
Configuring a Palo Alto Networks firewall to allow administrative logins using centralized authentication and encrypted protocols.
- Centralized auth: RADIUS, LDAP, TACACS+.
- Secure protocols: HTTPS (WebUI), SSH (CLI).
- Management profiles restrict access by IP/interface.
Memory trick: Centralized keys, encrypted doors: That's how admins get in.