Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy
A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall can accurately identify users from a Microsoft Active Directory domain. Which User-ID agent type should be configured to integrate directly with Active Directory domain controllers to collect user-to-IP address mappings?
- ASyslog Listener
- BWindows-based User-ID Agent
- CTerminal Services Agent
- DGlobalProtect Agent
Show answer & explanationAnswer & explanation
Correct answer: B. Windows-based User-ID Agent
The Windows-based User-ID Agent is specifically designed to run on a Windows server and integrate directly with Active Directory domain controllers to collect user login information and map it to IP addresses.
Why the other options are wrong
- A. A Syslog Listener is a method to collect user-ID information from devices that send syslog messages, not a direct Active Directory integration agent.
- C. The Terminal Services Agent is used for environments where multiple users share a single IP address, such as Citrix or Microsoft Terminal Services.
- D. The GlobalProtect Agent is installed on end-user devices for VPN connectivity and host information profile (HIP) collection, not for Active Directory user mapping.
Windows-based User-ID Agent
A software agent installed on a Windows server that integrates with Active Directory to collect user login events and map IP addresses to usernames for User-ID functionality.
- Queries Active Directory domain controllers.
- Provides user-to-IP mappings.
- Essential for traditional Windows domain user identification.
Memory trick: User-ID Agents: 'W' for Windows, 'T' for Terminal, 'S' for Syslog, 'G' for Global.