ファイアウォールで管理者アカウントを作成せずに、パロアルトネットワーク NGFW に管理者を認証するためにファイアウォールが使用できる 3 つの外部認証サービスはどれですか? (3つ選んでください。)
正解:A,B,E
Explanation
According to the Palo Alto Networks documentation1, the firewall can use three external authentication services to authenticate admins into the Palo Alto Networks NGFW without creating administrator accounts on the firewall: RADIUS, TACACS+, and SAML. These services allow the firewall to verify the credentials of admins against an external server and grant them access based on their assigned roles and permissions.
Therefore, the correct answer is A, B, and E.
The other options are not external authentication services that the firewall can use to authenticate admins:
Kerberos: This option is not an external authentication service that the firewall can use to authenticate admins. Kerberos is a protocol that allows users to access network resources using a single sign-on mechanism. The firewall can use Kerberos to authenticate users for GlobalProtect VPN or Captive Portal, but not for admin access2.
LDAP: This option is not an external authentication service that the firewall can use to authenticate admins. LDAP is a protocol that allows querying and modifying directory services over a network. The firewall can use LDAP to retrieve user and group information from an external server, but not to authenticate admins3.
References: 1:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authentication-types/external-authent
2:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authentication-types/kerberos-authen
3:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/map-ip-addresses