Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A company is integrating its Active Directory with a Palo Alto Networks firewall to enforce user-based security policies. Which component is primarily responsible for mapping IP addresses to usernames?

  1. ASecurity Policy
  2. BUser-ID Agent
  3. CLDAP Server Profile
  4. DAuthentication Profile
Show answer & explanation

Correct answer: B. User-ID Agent

The User-ID Agent is the primary component that collects information from various sources, such as Active Directory, to map IP addresses to usernames, enabling user-based policy enforcement on the firewall.

Why the other options are wrong

  • A. A Security Policy defines what traffic is allowed or denied based on users, applications, etc., but doesn't perform the mapping itself.
  • C. An LDAP Server Profile specifies how the firewall connects to an LDAP directory (like Active Directory) but doesn't perform the IP-to-user mapping function.
  • D. An Authentication Profile defines how users authenticate to the firewall or services, but not IP-to-user mapping.

User-ID Agent

A component of the Palo Alto Networks User-ID feature that collects and maps IP addresses to usernames from various sources, enabling user-based security policies.

  • Integrates with directory services like Active Directory.
  • Maps IP addresses to active user sessions.
  • Essential for implementing user-based security rules.

Memory trick: The Agent is the detective, linking IPs to people.

More Core Concepts questions