ExamGecko
Question list
Search
Search

Related questions











Question 242 - PCNSE discussion

Report
Export

Which source is the most reliable for collecting User-ID user mapping?

A.
GlobalProtect
Answers
A.
GlobalProtect
B.
Microsoft Active Directory
Answers
B.
Microsoft Active Directory
C.
Microsoft Exchange
Answers
C.
Microsoft Exchange
D.
Syslog Listener
Answers
D.
Syslog Listener
Suggested answer: B

Explanation:

For collecting User-ID user mapping information, the most reliable and commonly used source is directory services, with Microsoft Active Directory being the predominant choice in many organizational environments.

C) Microsoft Active Directory:

Microsoft Active Directory is a directory service used for user authentication and authorization. It provides a comprehensive database of user accounts, groups, and other objects within an organization's network. Palo Alto Networks firewalls can integrate with Active Directory to obtain real-time user mapping information, which is crucial for implementing security policies based on user identity.

The integration involves monitoring Active Directory domain controllers for security logs that contain user login events, IP address mappings, and other relevant information. This allows the firewall to accurately and dynamically map user identities to IP addresses, enhancing the granularity and effectiveness of security policies.

Compared to other sources like Syslog Listener, Microsoft Exchange, or GlobalProtect, Active Directory offers direct and comprehensive insights into user activities and is therefore considered the most reliable source for User-ID user mapping in Palo Alto Networks environments.


asked 23/09/2024
Jana Rutrich
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first