nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #90

A network security engineer wants to create Security policy rules that allow or deny traffic based on a user's department, which corresponds to groups in the company's Active Directory. To achieve thi

The correct answer is A. LDAP server profile. An LDAP server profile must be created first because it defines the connection parameters to the Active Directory server, enabling the firewall to query directory services and retrieve user and group information required for group-based policy enforcement.

User-ID and Identity-Based Policy

Question

A network security engineer wants to create Security policy rules that allow or deny traffic based on a user's department, which corresponds to groups in the company's Active Directory. To achieve this, the firewall needs to retrieve group information from the directory server. Which configuration object must be created first to establish the connection with the Active Directory server?

Options

  • ALDAP server profile
  • BUser-ID agent service account
  • CAuthentication sequence
  • DKerberos server profile

How the community answered

(35 responses)
  • A
    94% (33)
  • C
    3% (1)
  • D
    3% (1)

Explanation

An LDAP server profile must be created first because it defines the connection parameters to the Active Directory server, enabling the firewall to query directory services and retrieve user and group information required for group-based policy enforcement.

Topics

#User-ID#Active Directory Integration#LDAP#Security Policy

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice