View all questions & answers for the Palo Alto Next-Generation Firewall Engineer Exam Materials exam


Palo Alto Next-Generation Firewall Engineer Exam Materials-Question 146 Discussion
Comment Image Comment Image Comment Image

An organization is preparing to consolidate its user identity management into an Okta SAML-based solution. Currently, firewalls use a RADIUS server for Authentication Portal authentication. During the migration phase, both authentication methods need to coexist. The desired behavior is for the firewall to attempt SAML authentication first and only use RADIUS if the SAML identity provider (IdP) is unreachable. Which two configuration objects should an administrator create to enable this phased migration for Authentication Portal? (Choose two answers)

  • A. Single authentication profile that includes both the SAML and RADIUS server profiles in a failover list
  • B. New authentication profile configured to use the company's SAML IdP server profile
  • C. Authentication sequence that orders the new SAML authentication profile before the existing RADIUS authentication profile
  • D. Multi-factor authentication (MFA) enablement on the existing RADIUS profile linked to the SAML IdP
Correct Answer: B,C

Brave-Dump Clients Votes

B 100%

Comments



Anonymous User 2026-08-01 19:36:25

Selected Answers: B


SAML cannot configure with Auth sequence