View all questions & answers for the Palo Alto Next-Generation Firewall Engineer Exam Materials exam


Palo Alto Next-Generation Firewall Engineer Exam Materials-Question 12 Discussion
Comment Image Comment Image Comment Image

A PA-Series firewall with all licensable features is being installed. The customer’s Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions. Which action meets the requirements in this scenario? (Choose one answer)

  • A. Deploy the transparent proxy with Web Cache Communications Protocol (WCCP).
  • B. Deploy the Next-Generation Firewalls as normal and install the User-ID agent.
  • C. Deploy the Advanced URL Filtering license and captive portal.
  • D. Deploy the explicit proxy with Kerberos authentication scheme.
Correct Answer: D

Brave-Dump Clients Votes

D 100%

Comments



Anonymous User 2026-09-28 23:04:45

Selected Answers: D


Under explicit proxy, the firewall can require the client to authenticate directly to the proxy before requests are served, using Basic, NTLM, or Kerberos authentication methods