Exam NGFW-Engineer Topic 2 Question 113 Discussion

Actual exam question for Palo Alto Networks's NGFW-Engineer exam
Question #: 113
Topic #: 2
An administrator is configuring a GlobalProtect pre-logon VPN. The administrator has already imported the necessary internal certificate authority (CA) certificates for issuing machine certificates onto the firewall.
Which configuration is required on the GlobalProtect Gateway to enable pre-logon using these machine certificates?

Suggested Answer: C Vote an answer

Pre-logon using machine certificates requires the GlobalProtect Gateway to authenticate endpoints based on certificate trust, which is achieved by creating a certificate profile that trusts the issuing CA and assigning it in the Gateway Agent → Client Authentication settings so the gateway can validate machine certificates during pre-logon authentication.

by Eileen at Sep 30, 2026, 09:18 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10