Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy

A network security administrator needs to ensure that all internal users attempting to access external websites are authenticated against the corporate Active Directory before being allowed internet access. Which User-ID feature should be configured to achieve this?

  1. AGroup Mapping
  2. BServer Monitoring
  3. CRedistribution
  4. DAuthentication Policy
Show answer & explanation

Correct answer: D. Authentication Policy

Authentication Policy allows the firewall to challenge users for their credentials, typically against an external directory service like Active Directory, before permitting access to specific resources or zones.

Why the other options are wrong

  • A. Group Mapping is used to retrieve user group information from directory services, not to authenticate individual users for access.
  • B. Server Monitoring is used to check the availability and health of User-ID agents or directory servers, not to perform user authentication.
  • C. Redistribution refers to sharing user-to-IP mappings between firewalls, not directly authenticating users for access.

User-ID Authentication Policy

A feature that enforces user authentication against a directory service for network access, allowing granular control over who can access what.

  • Requires an Authentication Profile pointing to a directory service.
  • Can be applied to specific zones, source/destination IPs, or users/groups.
  • Challenges users with a login prompt (e.g., Captive Portal or transparent authentication).

Memory trick: Users need a key to the web gate.

More Manage and Operate questions