nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #113

An organization uses Cloud Identity Engine (CIE) to gather user information from its on-premises Active Directory (AD) for employees and a separate Azure AD for external partners. Due to compliance…

The correct answer is B. Segments, which can be configured to create distinct, filter-based views of users and groups that. Segments in Cloud Identity Engine allow administrators to create filtered, logical partitions of identity data and redistribute only the relevant users and groups to specific firewalls, ensuring strict separation of employee and partner identities in compliance-driven…

User-ID and Identity Management

Question

An organization uses Cloud Identity Engine (CIE) to gather user information from its on-premises Active Directory (AD) for employees and a separate Azure AD for external partners. Due to compliance regulations, the firewalls protecting the internal network must not have any identity information about external partners. Conversely, firewalls in the partner-facing DMZ should only be aware of partner identities. Which CIE feature is designed to solve this data partitioning requirement?

Options

  • APanorama templates, which can be used to push different User-ID agent configurations to each
  • BSegments, which can be configured to create distinct, filter-based views of users and groups that
  • CMultiple tenants, where a separate CIE tenant is required for each user directory to maintain
  • DDirectory sync filtering, which is used at the source to prevent specific OUs from being imported

How the community answered

(16 responses)
  • A
    13% (2)
  • B
    81% (13)
  • D
    6% (1)

Explanation

Segments in Cloud Identity Engine allow administrators to create filtered, logical partitions of identity data and redistribute only the relevant users and groups to specific firewalls, ensuring strict separation of employee and partner identities in compliance-driven environments.

Topics

#Cloud Identity Engine#CIE Segments#User-ID#Identity-based Security

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice