nerdexam
Palo_Alto_Networks

PCNSA · Question #3

Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?

The correct answer is C. Captive Portal. For environments where clients do not authenticate to Active Directory, Captive Portal is the appropriate User-ID mapping method to identify users.

Submitted by kavita_s· Apr 18, 2026Configure

Question

Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?

Options

  • AWindows session monitoring via a domain controller
  • Bpassive server monitoring using the Windows-based agent
  • CCaptive Portal
  • Dpassive server monitoring using a PAN-OS integrated User-ID agent

How the community answered

(40 responses)
  • A
    5% (2)
  • C
    93% (37)
  • D
    3% (1)

Why each option

For environments where clients do not authenticate to Active Directory, Captive Portal is the appropriate User-ID mapping method to identify users.

AWindows session monitoring via a domain controller

Windows session monitoring relies on integration with Windows Active Directory domain controllers to retrieve user login events, which is not applicable if clients do not authenticate to AD.

Bpassive server monitoring using the Windows-based agent

Passive server monitoring using a Windows-based agent collects user login information from Windows servers, requiring clients to authenticate to those Windows servers, which is not the scenario described.

CCaptive PortalCorrect

Captive Portal is designed to identify users by requiring them to authenticate directly to the firewall through a web browser, making it suitable for environments where traditional AD-based authentication is not present or cannot be leveraged for User-ID.

Dpassive server monitoring using a PAN-OS integrated User-ID agent

Passive server monitoring using a PAN-OS integrated User-ID agent functions similarly to the Windows-based agent by monitoring servers for login events, which is ineffective if clients don't use Windows AD for authentication.

Concept tested: User-ID mapping methods for non-AD environments

Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-and-enable-captive-portal

Topics

#User-ID#Captive Portal#Authentication Methods

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice