Exam NGFW-Engineer Topic 2 Question 64 Discussion
Actual exam question for Palo Alto Networks's NGFW-Engineer exam
Question #: 64
Topic #: 2
Question #: 64
Topic #: 2
A government agency needs to ensure that all user web access is explicitly mediated and authenticated.
The agency has the following requirements:
* Client browsers must be manually configured to send traffic to the firewall's IP address and a specific port.
* The firewall must support seamless single sign-on (SSO) with the users' existing Active Directory credentials.
Which feature set should the engineer configure to meet the agency's requirements?
The agency has the following requirements:
* Client browsers must be manually configured to send traffic to the firewall's IP address and a specific port.
* The firewall must support seamless single sign-on (SSO) with the users' existing Active Directory credentials.
Which feature set should the engineer configure to meet the agency's requirements?
Suggested Answer: A Vote an answer
Basic Concept: Explicit proxy requires client browsers to point to the firewall's proxy address and port.
Kerberos adds seamless Active Directory SSO for user authentication.
Why A is Correct: Web proxy in explicit mode with Kerberos authentication directly matches both manual proxy configuration and seamless AD authentication.
Why B is Wrong: Decryption policy that redirects users to a SAML identity provider for authentication is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why C is Wrong: Web proxy in transparent mode with an Authentication policy by using multi-factor authentication (MFA) is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why D is Wrong: User-ID agent integration with Authentication Portal for authentication is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Kerberos adds seamless Active Directory SSO for user authentication.
Why A is Correct: Web proxy in explicit mode with Kerberos authentication directly matches both manual proxy configuration and seamless AD authentication.
Why B is Wrong: Decryption policy that redirects users to a SAML identity provider for authentication is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why C is Wrong: Web proxy in transparent mode with an Authentication policy by using multi-factor authentication (MFA) is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why D is Wrong: User-ID agent integration with Authentication Portal for authentication is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
by April at Sep 20, 2026, 04:47 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).