Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall can accurately identify users from a Microsoft Active Directory domain. Which User-ID agent type should be configured to integrate directly with Active Directory domain controllers to collect user-to-IP address mappings?

  1. ASyslog Listener
  2. BWindows-based User-ID Agent
  3. CTerminal Services Agent
  4. DGlobalProtect Agent
Show answer & explanation

Correct answer: B. Windows-based User-ID Agent

The Windows-based User-ID Agent is specifically designed to run on a Windows server and integrate directly with Active Directory domain controllers to collect user login information and map it to IP addresses.

Why the other options are wrong

  • A. A Syslog Listener is a method to collect user-ID information from devices that send syslog messages, not a direct Active Directory integration agent.
  • C. The Terminal Services Agent is used for environments where multiple users share a single IP address, such as Citrix or Microsoft Terminal Services.
  • D. The GlobalProtect Agent is installed on end-user devices for VPN connectivity and host information profile (HIP) collection, not for Active Directory user mapping.

Windows-based User-ID Agent

A software agent installed on a Windows server that integrates with Active Directory to collect user login events and map IP addresses to usernames for User-ID functionality.

  • Queries Active Directory domain controllers.
  • Provides user-to-IP mappings.
  • Essential for traditional Windows domain user identification.

Memory trick: User-ID Agents: 'W' for Windows, 'T' for Terminal, 'S' for Syslog, 'G' for Global.

More Manage and Operate questions