Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCNSA Topic 2 Question 67 Discussion

Actual exam question for Palo Alto Networks's PCNSA exam
Question #: 67
Topic #: 2
[All PCNSA Questions]

If using group mapping with Active Directory Universal Groups, what must you do when configuring the User-ID?

Show Suggested Answer Hide Answer
Suggested Answer: B, D

A dynamic address group populates its members dynamically using look ups for tags and tag-based filters. Tags are metadata elements or attribute-value pairs that are registered for each IP address. Tag-based filters use logical and and or operators to match the tags and determine the membership of the dynamic address group. For example, you can create a dynamic address group that includes all IP addresses that have the tags ''web-server'' and ''linux''. You can also use static tags as part of the filter criteria.Reference:Policy Object: Address Groups,Use Dynamic Address Groups in Policy,Statics vs. Dynamic Address Objects Groups


Contribute your Thoughts:

Benton
2 days ago
Option A seems logical, as we need to connect to the Global Catalog server to retrieve group information for User-ID mapping. I'd go with that.
upvoted 0 times
...
Royal
2 days ago
I'm not sure, but I think option B) Configure a frequency schedule to clear group mapping cache could also be important to ensure accurate user identification.
upvoted 0 times
...
Katheryn
4 days ago
I agree with Diane, because using group mapping with Active Directory Universal Groups requires connecting to the Global Catalog server for user identification.
upvoted 0 times
...
Diane
6 days ago
I think the answer is A) Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL.
upvoted 0 times
...
Mollie
8 days ago
I'm not sure, but I think option B) Configure a frequency schedule to clear group mapping cache could also be important to ensure accurate user identification.
upvoted 0 times
...
Janine
13 days ago
I agree with Javier, because using group mapping with Active Directory Universal Groups requires connecting to the Global Catalog server for user identification.
upvoted 0 times
...
Javier
14 days ago
I think the answer is A) Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL.
upvoted 0 times
...

Save Cancel