PCNSE GlobalProtect VPN and Remote Access 2 — Questions and Answers
Question 1: Which protocol does GlobalProtect primarily use to establish its VPN tunnel?
- GRE
- IPsec (Correct answer)
- L2TP
- PPTP
Correct answer: IPsec
GlobalProtect uses IPsec (with SSL as a fallback) to establish encrypted VPN tunnels between the agent and gateway.
Question 2: What is the role of the GlobalProtect Gateway?
- To distribute VPN configuration to agents
- To terminate VPN tunnels and enforce security policy for remote users (Correct answer)
- To issue client certificates
- To monitor endpoint health only
Correct answer: To terminate VPN tunnels and enforce security policy for remote users
The GlobalProtect Gateway terminates the IPsec/SSL VPN tunnel and applies security policy to inbound remote user traffic.
Question 3: Which feature allows GlobalProtect to dynamically select the best gateway based on response time?
- Policy-Based Forwarding
- Automatic Gateway Selection (Correct answer)
- BGP Route Reflector
- ECMP
Correct answer: Automatic Gateway Selection
Automatic Gateway Selection measures response times from multiple gateways and connects the agent to the fastest one.
Question 4: What type of certificate is required on the GlobalProtect Portal for secure client connections?
- Self-signed only
- A certificate trusted by the client machine or browser (Correct answer)
- An expired certificate for testing
- A wildcard certificate from the internal CA only
Correct answer: A certificate trusted by the client machine or browser
The portal certificate must be trusted by the connecting client to prevent certificate warnings and ensure secure connections.
Question 5: In a large enterprise GlobalProtect deployment, what is the recommended approach for scaling gateway capacity?
- Deploy a single high-memory gateway
- Deploy multiple gateways in different geographic locations (Correct answer)
- Use software-only virtual gateways on endpoints
- Disable HIP checks to reduce load
Correct answer: Deploy multiple gateways in different geographic locations
Deploying multiple geographically distributed gateways distributes load and reduces latency for remote users worldwide.
Question 6: Which GlobalProtect feature enables seamless user authentication using Windows credentials without prompting the user?
- On-Demand tunnel
- SSO (Single Sign-On) with Windows credentials (Correct answer)
- Certificate pinning
- OCSP stapling
Correct answer: SSO (Single Sign-On) with Windows credentials
SSO allows GlobalProtect to use Windows domain credentials so users authenticate to the VPN automatically at Windows login.
Which protocol does GlobalProtect primarily use to establish its VPN tunnel?