nerdexam
Palo_Alto_Networks

PCNSA · Question #366

When configuring a security policy, what is a best practice for User-ID?

The correct answer is D. Deny WMI traffic from the User-ID agent to any external zone. A best practice for User-ID configuration is to restrict WMI traffic originating from the User-ID agent to external zones, enhancing network security by limiting exposure.

Submitted by kev92· Apr 18, 2026Securing Traffic

Question

When configuring a security policy, what is a best practice for User-ID?

Options

  • AUse only one method for mapping IP addresses to usernames.
  • BAllow the User-ID agent in zones where agents are not monitoring services.
  • CLimit User-ID to users registered in an Active Directory server.
  • DDeny WMI traffic from the User-ID agent to any external zone.

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    86% (32)

Why each option

A best practice for User-ID configuration is to restrict WMI traffic originating from the User-ID agent to external zones, enhancing network security by limiting exposure.

AUse only one method for mapping IP addresses to usernames.

Using multiple methods for User-ID mapping (e.g., WMI, Syslog, authentication policy) can provide redundancy and more comprehensive coverage, so limiting to only one method is not a best practice.

BAllow the User-ID agent in zones where agents are not monitoring services.

Allowing the User-ID agent in zones where it is not monitoring services is unnecessary and can potentially expose the agent to risks without providing any benefit.

CLimit User-ID to users registered in an Active Directory server.

User-ID can map users from various sources, not just Active Directory (e.g., LDAP, RADIUS, local databases), so limiting it solely to AD is not a best practice and may limit its utility.

DDeny WMI traffic from the User-ID agent to any external zone.Correct

User-ID agents often use WMI (Windows Management Instrumentation) to query Windows domain controllers for user login information. A best practice is to deny WMI traffic from the User-ID agent to any external zone, typically restricting it to only the internal zones where domain controllers reside to minimize the attack surface and prevent unauthorized WMI access from outside.

Concept tested: User-ID security best practices

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/user-id-best-practices.html

Topics

#User-ID#Security Best Practices#Network Security#WMI

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice