Palo Alto Networks NGFW Engineer — Question 42

A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency.
Which approach best addresses these requirements while maintaining consistent policy enforcement?

Answer options

Correct answer: B

Explanation

Option B is the best choice because it ensures consistent trust across all firewalls by distributing CA certificates via Panorama and supports efficient revocation checks with OCSP while allowing for separate profiles for users and devices. The other options either compromise on revocation checks, lack policy consistency, or introduce unnecessary complexity and overhead, making them less suitable for the enterprise's requirements.