nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #206

If using group mapping with Active Directory Universal Groups, what must you do when configuring the User-ID?

The correct answer is A. Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port. If you have Universal Groups, create an LDAP server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL, then create another LDAP server profile to connect to the root domain controllers on port 389. This helps ensure that users and…

User-ID

Question

If using group mapping with Active Directory Universal Groups, what must you do when configuring the User-ID?

Options

  • ACreate an LDAP Server profile to connect to the root domain of the Global Catalog server on port
  • BConfigure a frequency schedule to clear group mapping cache
  • CConfigure a Primary Employee ID number for user-based Security policies
  • DCreate a RADIUS Server profile to connect to the domain controllers using LDAPS on port 636 or

How the community answered

(14 responses)
  • A
    79% (11)
  • B
    14% (2)
  • C
    7% (1)

Explanation

If you have Universal Groups, create an LDAP server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL, then create another LDAP server profile to connect to the root domain controllers on port 389. This helps ensure that users and group information is available for all domains and subdomains. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-users-to-groups

Topics

#User-ID#group mapping#Active Directory Universal Groups#LDAP Global Catalog

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice