Free Palo Alto Networks NGFW-Engineer Actual Exam Questions - Question 10 Discussion
company’s Palo Alto Networks NGFWs. User authentication on company firewalls is currently
performed with RADIUS, which will remain available for six months, until it is decommissioned. The
company wants both authentication types to be running in parallel during the transition to SAML.
Which two actions meet the criteria? (Choose two.)
B Using an authentication sequence lets you try RADIUS first, then SAML, or vice versa, so both run side-by-side during the transition. D fits because you can add SAML into the existing RADIUS profile to support both without disruption.
It’s B, since sequences let you try multiple auth methods in order.
It’s B and D since you can combine both profiles in an auth sequence or nested profile.
Makes sense that sequence or nesting works; I agree with B and D.
B/D? You can run both auth types together using an authentication sequence or by layering the SAML profile within the existing RADIUS profile. A and C don’t support parallel operation here.
B and D look right since you can set up an authentication sequence or add multiple server profiles in one profile for parallel auth. A is wrong because you can run both at once. C alone doesn’t do parallel.