Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium

A security engineer is designing a User-ID deployment for an Active Directory environment. The goal is to identify users on the network and apply security policies based on their group memberships. The network topology includes multiple domain controllers, and the firewalls are deployed in front of the user subnets. What is the most efficient and scalable method for the firewall to collect User-ID mappings?

  1. AManually creating static User-ID mappings for each user on the firewall.
  2. BEnabling passive monitoring on the firewall's interfaces to infer user logins.
  3. CDeploying a User-ID Agent on a dedicated server to monitor domain controller security event logs.
  4. DConfiguring each firewall to directly query all domain controllers via LDAP.
Show answer & explanation

Correct answer: C. Deploying a User-ID Agent on a dedicated server to monitor domain controller security event logs.

Deploying a User-ID Agent is the most efficient and scalable method for collecting User-ID mappings in an Active Directory environment. The agent monitors security event logs on domain controllers for login events, providing accurate and up-to-date user-to-IP mappings to the firewall.

Why the other options are wrong

  • A. Manual mappings are impractical and not scalable for dynamic user environments.
  • B. Passive monitoring is less reliable and accurate for Active Directory environments compared to explicit login event collection.
  • D. Direct querying of all DCs by each firewall can be inefficient and resource-intensive, especially with many firewalls or DCs.

User-ID Agent

A software component deployed on a Windows server that monitors Active Directory domain controller security event logs for user login/logout events, then sends user-to-IP mappings to Palo Alto Networks firewalls.

  • Collects user-to-IP mappings from AD
  • Reduces firewall load for User-ID
  • Supports multiple domain controllers

Memory trick: User-ID: Know your users, not just their IPs.

More Plan and Design questions