nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #11

What must be configured before a firewall administrator can define policy rules based on users and groups?

The correct answer is C. Group mapping settings. To write Security policy rules that reference user groups (e.g., 'allow Finance-Group to access server X'), the firewall must first know which users belong to which groups. Group mapping settings (configured under Device > User Identification > Group Mapping Settings) connect…

User-ID Configuration and Integration

Question

What must be configured before a firewall administrator can define policy rules based on users and groups?

Options

  • AUser Mapping profile
  • BAuthentication profile
  • CGroup mapping settings
  • DLDAP Server profile

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    92% (24)
  • D
    4% (1)

Explanation

To write Security policy rules that reference user groups (e.g., 'allow Finance-Group to access server X'), the firewall must first know which users belong to which groups. Group mapping settings (configured under Device > User Identification > Group Mapping Settings) connect the firewall to an LDAP or Active Directory server to retrieve group membership data. The firewall periodically queries the directory and builds an internal mapping of groups to users. Without this, group names in policy rules cannot be resolved. While an LDAP Server profile (option D) is a prerequisite for group mapping (it defines the connection parameters to the directory server), it alone is not sufficient - the group mapping settings must be configured to actually pull and use group data. Authentication profiles (option B) govern how users authenticate but don't populate group membership. User Mapping profiles (option A) map IP addresses to usernames, which is a separate function from group membership.

Topics

#Palo Alto Networks#User-ID#Group Mapping#Security Policy

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice