NGFW-ENGINEER · Question #92
A large organization has separate production and development environments, each with its own set of firewalls managed by Panorama. The organization uses Cloud Identity Engine (CIE) to consolidate…
The correct answer is A. Create two segments, one with only "DEV" and "QA" groups, and one with "Prod" groups. Cloud Identity Engine supports segmentation of identity data, allowing administrators to create separate segments containing only specific user groups and redistribute each segment selectively to the appropriate firewalls, which enforces strict identity visibility separation…
Question
A large organization has separate production and development environments, each with its own set of firewalls managed by Panorama. The organization uses Cloud Identity Engine (CIE) to consolidate user identities from Active Directory (AD) and Okta. A security mandate requires that development firewalls must only learn about "DEV" and "QA" user groups, while production firewalls should only see "Prod" user groups. How can an administrator enforce this separation using CIE with minimal complexity?
Options
- ACreate two segments, one with only "DEV" and "QA" groups, and one with "Prod" groups
- BRedistribute all user and group information to all firewalls and use Panorama Device Group
- CCreate filters using CLI commands to filter "Prod," "DEV," and "QA" groups.
- DConfigure two separate CIE instances, one for production and the other for development. Sync
How the community answered
(39 responses)- A79% (31)
- B5% (2)
- C3% (1)
- D13% (5)
Explanation
Cloud Identity Engine supports segmentation of identity data, allowing administrators to create separate segments containing only specific user groups and redistribute each segment selectively to the appropriate firewalls, which enforces strict identity visibility separation between development and production environments with minimal configuration complexity.
Topics
Community Discussion
No community discussion yet for this question.