Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Paloalto Networks Palo Alto Networks Next-Generation Firewall Engineer NGFW-Engineer Question # 18 Topic 2 Discussion

Paloalto Networks Palo Alto Networks Next-Generation Firewall Engineer NGFW-Engineer Question # 18 Topic 2 Discussion

NGFW-Engineer Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

A network engineer has configured a PAN-OS firewall for client certificate authentication. The firewall has the corporate root CA certificate loaded. Client certificates are issued by an intermediate certificate authority (CA), which is signed by the root CA. However, when users attempt to connect, the authentication fails, and system logs indicate an "invalid certificate" error.

What is the most likely cause of this authentication failure?


A.

Intermediate CA certificate has not been imported onto the firewall and added to the trust chain.


B.

Client certificates were generated with an insecure key length (e.g., 1024-bit RSA).


C.

Firewall clock is out of sync with the CA server by more than five minutes.


D.

Online Certificate Status Protocol (OCSP) responder is unreachable, and no certificate revocation list (CRL) fallback is configured.


Get Premium NGFW-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.