PCNSA · Question #3
Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?
The correct answer is C. Captive Portal. For environments where clients do not authenticate to Active Directory, Captive Portal is the appropriate User-ID mapping method to identify users.
Question
Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?
Options
- AWindows session monitoring via a domain controller
- Bpassive server monitoring using the Windows-based agent
- CCaptive Portal
- Dpassive server monitoring using a PAN-OS integrated User-ID agent
How the community answered
(40 responses)- A5% (2)
- C93% (37)
- D3% (1)
Why each option
For environments where clients do not authenticate to Active Directory, Captive Portal is the appropriate User-ID mapping method to identify users.
Windows session monitoring relies on integration with Windows Active Directory domain controllers to retrieve user login events, which is not applicable if clients do not authenticate to AD.
Passive server monitoring using a Windows-based agent collects user login information from Windows servers, requiring clients to authenticate to those Windows servers, which is not the scenario described.
Captive Portal is designed to identify users by requiring them to authenticate directly to the firewall through a web browser, making it suitable for environments where traditional AD-based authentication is not present or cannot be leveraged for User-ID.
Passive server monitoring using a PAN-OS integrated User-ID agent functions similarly to the Windows-based agent by monitoring servers for login events, which is ineffective if clients don't use Windows AD for authentication.
Concept tested: User-ID mapping methods for non-AD environments
Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-and-enable-captive-portal
Topics
Community Discussion
No community discussion yet for this question.