nerdexam
Palo_Alto_Networks

PCNSA · Question #212

Which solution is a viable option to capture user identification when Active Directory is not in use?

The correct answer is D. Authentication Portal. When Active Directory is not available for user identification, an Authentication Portal is a suitable solution for capturing user identity directly from users.

Submitted by tom_us· Apr 18, 2026Configure

Question

Which solution is a viable option to capture user identification when Active Directory is not in use?

Options

  • ACloud Identity Engine
  • Bgroup mapping
  • CDirectory Sync Service
  • DAuthentication Portal

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    90% (47)

Why each option

When Active Directory is not available for user identification, an Authentication Portal is a suitable solution for capturing user identity directly from users.

ACloud Identity Engine

Cloud Identity Engine typically relies on integrating with existing identity sources rather than being a standalone method to capture user identification when none exist.

Bgroup mapping

Group mapping relies on existing user groups from an integrated directory service, which is not available if Active Directory is not in use.

CDirectory Sync Service

Directory Sync Service synchronizes user and group information from an existing directory service, and thus requires such a service to be present.

DAuthentication PortalCorrect

An Authentication Portal is a feature on Palo Alto Networks NGFWs that prompts users to authenticate via a web page, thereby capturing their identity for User-ID purposes even in the absence of traditional directory services.

Concept tested: User-ID without Active Directory

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/authentication-portal

Topics

#User-ID#Authentication#Captive Portal#Identity Management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice