
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 2Objective 1
2.1 Implement Authentication Roles, Profiles, and Sequences NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 3)
Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
31questions here
7free pages
10concepts
40%of the exam
Questions 11–15
- 11
A security team wants to grant a group of junior administrators the ability to view configuration and monitor traffic, but they must not be able to make any changes. The firewall authenticates admins via SAML. What is the most efficient way to assign the appropriate access?
Select an answer first - 12
Which PAN-OS object is used to assign administrative permissions to a user based on their group membership?
Select an answer first - 13
A firewall administrator needs to configure administrative authentication against the company's LDAP server. The LDAP server uses a non-standard port and requires a bind account to search the directory. Which settings must be configured in the authentication profile?
Select an answer first - 14
An administrator is configuring an authentication sequence with three profiles: LDAP, RADIUS, and Local. The requirement is that if LDAP is unavailable, the firewall should try RADIUS, and if RADIUS is also unavailable, it should try Local. What is the correct configuration?
Select an answer first - 15
An administrator is configuring a RADIUS authentication profile. The RADIUS server requires a specific timeout value to avoid false failures during peak load. Which setting in the authentication profile controls this behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.