PCNSE GlobalProtect VPN and Remote Access 1 — Questions and Answers
Question 1: Which GlobalProtect component is responsible for authenticating remote users before they connect to the internal network?
- GlobalProtect Gateway
- GlobalProtect Portal (Correct answer)
- GlobalProtect Agent
- GlobalProtect HIP Check
Correct answer: GlobalProtect Portal
The GlobalProtect Portal authenticates remote users and distributes configuration and certificates to the GlobalProtect Agent.
Question 2: What is the purpose of Host Information Profile (HIP) in GlobalProtect?
- To encrypt VPN tunnel traffic
- To assign IP addresses to remote clients
- To collect and report endpoint security posture data (Correct answer)
- To manage firewall policy rules
Correct answer: To collect and report endpoint security posture data
HIP collects endpoint security posture data such as OS patch level and antivirus status, enabling policy enforcement based on device health.
Question 3: Which GlobalProtect connection method allows users to connect without initiating the connection themselves?
- On-Demand
- Pre-Logon (Correct answer)
- User-Logon
- Split Tunnel
Correct answer: Pre-Logon
Pre-Logon establishes a VPN tunnel before the user logs in, using machine certificates for authentication.
Question 4: In GlobalProtect, what is split tunneling used for?
- Encrypting all traffic through the VPN
- Routing only specific traffic through the VPN tunnel (Correct answer)
- Authenticating users with two factors
- Load balancing between multiple gateways
Correct answer: Routing only specific traffic through the VPN tunnel
Split tunneling directs only specified destination traffic through the VPN tunnel while other traffic goes directly to the internet.
Question 5: Which authentication method can GlobalProtect use to verify user identity alongside username and password?
- OSPF authentication
- MFA via RADIUS or SAML (Correct answer)
- BGP MD5 authentication
- LLDP authentication
Correct answer: MFA via RADIUS or SAML
GlobalProtect supports multi-factor authentication (MFA) by integrating with RADIUS or SAML identity providers.
Question 6: What happens when a HIP check fails in a GlobalProtect deployment with policy enforcement enabled?
- The VPN tunnel is encrypted with a weaker cipher
- The user is placed in a quarantine zone with restricted access (Correct answer)
- The gateway reboots the client machine
- The portal denies certificate issuance
Correct answer: The user is placed in a quarantine zone with restricted access
When a HIP check fails, the firewall can apply a separate security policy that quarantines or restricts the non-compliant endpoint.
Which GlobalProtect component is responsible for authenticating remote users before they connect to the internal network?