Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A company is implementing a new policy to restrict access to certain web applications based on user groups. For example, only users in the 'Marketing' group should access 'Facebook' and 'Twitter', while 'Engineering' users should access 'GitHub' and 'Jira'. All other users should be blocked from these applications. Which feature on the Palo Alto Networks firewall is essential for enforcing such user-group-specific access controls in security policies?

  1. AUser-ID
  2. BContent-ID
  3. CURL Filtering
  4. DApp-ID
Show answer & explanation

Correct answer: A. User-ID

User-ID is the essential feature for enforcing security policies based on user groups or individual users. It maps IP addresses to usernames, allowing the firewall to apply rules specific to 'Marketing' or 'Engineering' groups, rather than just IP addresses.

Why the other options are wrong

  • B. Content-ID focuses on inspecting traffic for threats, sensitive data, or specific file types, not user-group-based access control.
  • C. URL Filtering controls access based on website categories, not user groups.
  • D. App-ID identifies applications regardless of user, but doesn't inherently link them to specific user groups for policy enforcement.

User-ID

User-ID is a Palo Alto Networks feature that maps IP addresses to usernames, enabling security policies to be enforced based on users and user groups rather than just IP addresses.

  • Integrates with directory services (e.g., Active Directory, LDAP).
  • Allows user- and group-based security policy rules.
  • Enhances visibility into user activity.
  • Can use agents, client probes, or syslog for mapping.

Memory trick: User-ID is like a security guard checking everyone's ID badge before they enter specific rooms (applications).

More Security Policy Configuration questions