Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NGFW-Engineer Exam - Topic 3 Question 23 Discussion

A PA-Series firewall with all licensable features is being installed. The customer's Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions.Which action meets the requirements in this scenario?
D) Deploy the explicit proxy with Kerberos authentication scheme.
A) Deploy the transparent proxy with Web Cache Communications Protocol (WCCP).
B) Deploy the Next-Generation Firewalls as normal and install the User-ID agent.
C) Deploy the Advanced URL Filtering license and captive portal.

Palo Alto Networks NGFW-Engineer Exam - Topic 3 Question 23 Discussion

Actual exam question for Palo Alto Networks's NGFW-Engineer exam
Question #: 23
Topic #: 3
[All NGFW-Engineer Questions]

A PA-Series firewall with all licensable features is being installed. The customer's Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions.

Which action meets the requirements in this scenario?

Show Suggested Answer Hide Answer
Suggested Answer: D

In this scenario, the customer requires that users do not directly access websites and that a security device (the firewall) manages the connection, while also ensuring that there is authentication back to the Active Directory (AD) servers for all sessions. The explicit proxy with Kerberos authentication is the best solution because:

The explicit proxy allows the firewall to intercept user web traffic and manage the connections on behalf of users.

Kerberos authentication ensures that the user's identity is validated against the Active Directory servers before the session is allowed, fulfilling the authentication requirement.


Contribute your Thoughts:

0/2000 characters
Luann
14 hours ago
I prefer B. User-ID agent is solid for tracking users.
upvoted 0 times
...
Juan
6 days ago
It uses Kerberos for authentication, fits the policy.
upvoted 0 times
...
Derrick
11 days ago
Why D?
upvoted 0 times
...
Juan
16 days ago
I think D is the best choice.
upvoted 0 times
...
Edna
21 days ago
Not sure if D is the right move; explicit proxies can be tricky.
upvoted 0 times
...
Denny
26 days ago
Wait, I didn't know Kerberos could be used like that!
upvoted 0 times
...
Ty
1 month ago
I disagree, B could work too with User-ID for AD integration.
upvoted 0 times
...
Buddy
1 month ago
A transparent proxy won't enforce the security policy properly.
upvoted 0 times
...
King
1 month ago
I think D is the best choice here. Kerberos is solid for authentication.
upvoted 0 times
...
Carin
2 months ago
Captive portal sounds familiar, but I’m not clear if it would handle the authentication back to Active Directory as needed.
upvoted 0 times
...
Tuyet
2 months ago
I practiced a similar question where we had to consider user identification methods. The User-ID agent could be relevant here, but I’m not convinced it fully meets the requirement.
upvoted 0 times
...
Lyndia
2 months ago
I'm not entirely sure, but I remember something about WCCP being used for transparent proxies. Does that fit the need for user authentication?
upvoted 0 times
...
Arleen
2 months ago
I think the explicit proxy option might be the right choice since it mentions Kerberos authentication, which aligns with the AD requirement.
upvoted 0 times
...

Save Cancel