Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Palo Alto Networks TechnologiesMedium

A network administrator is configuring a Palo Alto Networks NGFW to allow users to access specific internal web applications based on their Active Directory group membership, regardless of the physical port or IP address. Which two core NGFW features are essential to achieve this granular access control?

  1. AData Filtering and WildFire
  2. BGlobalProtect and Decryption
  3. CURL Filtering and Threat Prevention
  4. DApp-ID and User-ID
Show answer & explanation

Correct answer: D. App-ID and User-ID

App-ID identifies the specific web applications, and User-ID maps users to their Active Directory groups, allowing the NGFW to enforce policies based on both application and user identity.

Why the other options are wrong

  • A. Data Filtering prevents data exfiltration, and WildFire analyzes unknown threats; neither addresses user/group-based application access.
  • B. GlobalProtect provides remote access, and Decryption allows inspection of encrypted traffic; neither directly facilitates user group-based application access.
  • C. URL Filtering controls access to websites by category, and Threat Prevention blocks exploits/malware; neither directly handles user group-based application access.

App-ID & User-ID

Two foundational Palo Alto Networks NGFW technologies. App-ID identifies applications regardless of port, and User-ID maps IP addresses to user identities from directories like Active Directory.

  • App-ID enables application-level policy enforcement.
  • User-ID enables user and group-level policy enforcement.
  • Together, they provide granular, identity-based application control.

Memory trick: To know WHO is using WHAT app, you need User-ID and App-ID.

More Palo Alto Networks Technologies questions