Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy
A company is implementing a new policy to restrict access to certain web applications based on the user's department. For instance, only the HR department should access HR-related SaaS applications, and the Finance department should access financial SaaS applications. Which Palo Alto Networks feature is primarily used in security policies to enforce this type of user-based access control?
- AContent-ID
- BApp-ID
- CUser-ID
- DURL Filtering
Show answer & explanationAnswer & explanation
Correct answer: C. User-ID
User-ID is the Palo Alto Networks feature that maps IP addresses to usernames and groups, allowing security policies to be enforced based on who is accessing the network, rather than just their IP address.
Why the other options are wrong
- A. Content-ID focuses on inspecting content for threats, sensitive data, or files, not user identity.
- B. App-ID identifies the application regardless of port, protocol, or encryption, but doesn't identify the user.
- D. URL Filtering controls access to web categories or specific URLs, not user identities directly.
User-ID
User-ID is a Palo Alto Networks feature that integrates with directory services (like Active Directory) to map IP addresses to usernames and groups, enabling user-based security policies.
- Maps IP addresses to users and groups.
- Enables user-based access control.
- Uses various methods: agents, syslog, authentication policy, XFF headers.
Memory trick: Who is it? User-ID will tell you.