Free Palo Alto Networks NGFW-Engineer Actual Exam Questions - Question 10 Discussion

Question No. 10
An engineer is implementing a new rollout of SAML for administrator authentication across a
company’s Palo Alto Networks NGFWs. User authentication on company firewalls is currently
performed with RADIUS, which will remain available for six months, until it is decommissioned. The
company wants both authentication types to be running in parallel during the transition to SAML.
Which two actions meet the criteria? (Choose two.)
Select all that apply, then reveal solution.
US
RT
Rizwan T.
2026-02-19

B Using an authentication sequence lets you try RADIUS first, then SAML, or vice versa, so both run side-by-side during the transition. D fits because you can add SAML into the existing RADIUS profile to support both without disruption.

0
UY
Usman Y.
2026-01-26

It’s B, since sequences let you try multiple auth methods in order.

0
UY
Usman Y.
2026-01-25

It’s B and D since you can combine both profiles in an auth sequence or nested profile.

0
UY
Usman Y.
2026-01-24

Makes sense that sequence or nesting works; I agree with B and D.

0
UI
Usman I.
2026-01-23

B/D? You can run both auth types together using an authentication sequence or by layering the SAML profile within the existing RADIUS profile. A and C don’t support parallel operation here.

0
RU
Ryan U.
2026-01-11

B and D look right since you can set up an authentication sequence or add multiple server profiles in one profile for parallel auth. A is wrong because you can run both at once. C alone doesn’t do parallel.

0