<< Prev Question Next Question >>

Question 13/23

A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency.
Which approach best addresses these requirements while maintaining consistent policy enforcement?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (23q)
Question 1: Which configuration in the LACP tab will enable pre-negotiat...
Question 2: When deploying Palo Alto Networks NGFWs in a cloud service p...
Question 3: Which two zone types are valid when configuring a new securi...
Question 4: Which PAN-OS method of mapping users to IP addresses is the ...
Question 5: When integrating Kubernetes with Palo Alto Networks NGFWs, w...
Question 6: Which interface types should be used to configure link monit...
Question 7: Which statement applies to the relationship between Panorama...
Question 8: How does a Palo Alto Networks firewall choose the best route...
Question 9: What is a result of enabling split tunneling in the GlobalPr...
Question 10: Which forwarding methods can be used on the Objects tab when...
Question 11: An organization has configured GlobalProtect in a hybrid aut...
Question 12: In a hybrid cloud deployment, what is the primary function o...
Question 13: A large enterprise wants to implement certificate-based auth...
Question 14: A PA-Series firewall with all licensable features is being i...
Question 15: Which type of firewall resource can be assigned when configu...
Question 16: Which two statements apply to configuring required security ...
Question 17: An engineer is implementing a new rollout of SAML for admini...
Question 18: An NGFW engineer is configuring multiple Panorama-managed fi...
Question 19: In a Palo Alto Networks environment, GlobalProtect has been ...
Question 20: A multinational organization wants to use the Cloud Identity...
Question 21: To maintain security efficacy of its public cloud resources ...
Question 22: An NGFW engineer is establishing bidirectional connectivity ...
Question 23: What must be configured before a firewall administrator can ...