<< Prev Question Next Question >>

Question 9/28

A large enterprise wants to implement certificate-based authentication for both users and devices, using an on- premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency.
Which approach best addresses these requirements while maintaining consistent policy enforcement?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (28q)
Question 1: A multinational organization wants to use the Cloud Identity...
Question 2: Which two zone types are valid when configuring a new securi...
Question 3: A PA-Series firewall with all licensable features is being i...
Question 4: What is a result of enabling split tunneling in the GlobalPr...
Question 5: What are the phases of the Palo Alto Networks AI Runtime Sec...
Question 6: In an active/active high availability (HA) configuration wit...
Question 7: For which two purposes is an IP address configured on a tunn...
Question 8: What are two valid zone types that can be selected from the ...
Question 9: A large enterprise wants to implement certificate-based auth...
Question 10: Which configuration in the LACP tab will enable pre-negotiat...
Question 11: After an engineer configures an IPSec tunnel with a Cisco AS...
Question 12: An administrator plans to upgrade a pair of active/passive f...
Question 13: An engineer at a managed services provider is updating an ap...
Question 14: When considering the various methods for User-ID to learn us...
Question 15: What is the purpose of assigning an Admin Role Profile to a ...
Question 16: Which set of options is available for detailed logs when bui...
Question 17: A network security engineer needs to permit traffic between ...
Question 18: When configuring a Zone Protection profile, in which section...
Question 19: Which configuration step is required when implementing a new...
Question 20: An organization runs multiple Kubernetes clusters both on-pr...
Question 21: Which forwarding methods can be used on the Objects tab when...
Question 22: In a Palo Alto Networks environment, GlobalProtect has been ...
Question 23: What is a valid configurable limit for setting resource quot...
Question 24: An enterprise uses GlobalProtect with both user- and machine...
Question 25: A network architect is planning the deployment of a new IPSe...
Question 26: A firewall administrator uses Panorama to manage a fleet of ...
Question 27: An NGFW engineer is configuring multiple Layer 2 interfaces ...
Question 28: An engineer is implementing a new rollout of SAML for admini...