Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy
A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that all internal users accessing external websites are consistently identified by their usernames, even if their IP addresses change. Which User-ID feature is most appropriate for this requirement?
- AActive Directory integration with NTLM authentication
- BSyslog parsing for authentication events
- CGlobalProtect with HIP checks
- DUser-ID Agent with server monitoring
Show answer & explanationAnswer & explanation
Correct answer: D. User-ID Agent with server monitoring
The User-ID Agent with server monitoring is designed to collect user-to-IP address mappings from various sources, including Active Directory, ensuring consistent user identification even with dynamic IP assignments.
Why the other options are wrong
- A. NTLM can provide authentication but doesn't primarily focus on persistent user-to-IP mapping for dynamic environments.
- B. Syslog parsing can gather information but is generally less efficient and real-time for dynamic IP-to-user mapping compared to the User-ID Agent.
- C. GlobalProtect with HIP checks is primarily for remote access VPN and host integrity, not for core internal user identification.
User-ID Agent
A component of Palo Alto Networks User-ID that collects user-to-IP address mappings from various sources to enable user-based policy enforcement.
- Collects user-to-IP mappings
- Integrates with directory services (e.g., Active Directory)
- Enables user-based security policies
Memory trick: To know who's who, the Firewall needs a map from Person to Place.