Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that all internal users accessing external websites are consistently identified by their usernames, even if their IP addresses change. Which User-ID feature is most appropriate for this requirement?

  1. AActive Directory integration with NTLM authentication
  2. BSyslog parsing for authentication events
  3. CGlobalProtect with HIP checks
  4. DUser-ID Agent with server monitoring
Show answer & explanation

Correct answer: D. User-ID Agent with server monitoring

The User-ID Agent with server monitoring is designed to collect user-to-IP address mappings from various sources, including Active Directory, ensuring consistent user identification even with dynamic IP assignments.

Why the other options are wrong

  • A. NTLM can provide authentication but doesn't primarily focus on persistent user-to-IP mapping for dynamic environments.
  • B. Syslog parsing can gather information but is generally less efficient and real-time for dynamic IP-to-user mapping compared to the User-ID Agent.
  • C. GlobalProtect with HIP checks is primarily for remote access VPN and host integrity, not for core internal user identification.

User-ID Agent

A component of Palo Alto Networks User-ID that collects user-to-IP address mappings from various sources to enable user-based policy enforcement.

  • Collects user-to-IP mappings
  • Integrates with directory services (e.g., Active Directory)
  • Enables user-based security policies

Memory trick: To know who's who, the Firewall needs a map from Person to Place.

More Core Concepts questions