Module 4 Managing Accounts Flashcards

1
Q

What type of user accounts does PAN-OS software support?

A

LDAP, AD, Kerberos, RADIUS, TACACS+ and SAML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What three types of authentication services are supported?

A

Local, external and multi-factor authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many local authentication services are there?

A

2: Local auth without a database and local authentication with a database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is local authentication w/o a database?

A

Username and password stored on the firewall in the XML configuration file of the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is local authentication w a database?

A

Username and password stored on the firewall in a local user database. The firewall can use this service to authenticate logins to the firewall, and user traffic flowing through the firewall, like to webmail, where authentication is required. (Users connecting to local sources)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Authentication Profile and Authentication Services - what is the difference?

A

You can configure each user individually on the firewall, with their own authentication profile…or you can configure all users to use the same authentication profile and authentication service (LDAP, RADIUS, TACACS+)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Configure Authentication “Through the Firewall”

A

You can also configure the firewall to authenticate user credentials when uses attempt to access network resources THROUGH the firewall - like webmail.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many types of admin role profiles are there?

A

Two - dynamic admin role profiles are built in and have a predefined set of permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many dynamic admin roles

A

6: Superuser, Superuser (read-only), Device administrator, device administrator (read-only), Virtual Systems administrator and Virtual Systems administrator (read-only)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between all three admin roles?

A

Device administrator cannot create new accounts, or virtual systems. Virtual admins can only manage those virtual systems assigned to them. (Also virtual admins do not have access to firewalls network-level functions such as network interfaces, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to create a Local (Non Database Admin Account

A

Device - admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How to create a local Database Authentication Profile

A

An authentication profile links in a username to the authentication service that the firewall must use to authenticate the users login credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly