PCNSA · Question #385
What are three advantages of user-to-group mapping? (Choose three.)
The correct answer is C. It simplifies user administration. D. It automatically adds new users to the appropriate group. E. It allows an administrator to write more granular policies. User-to-group mapping streamlines user management by leveraging external directory services to simplify administration, automatically assign new users to groups, and enable the creation of more granular security policies on the firewall.
Question
What are three advantages of user-to-group mapping? (Choose three.)
Options
- AIt does not require additional objects to be configured.
- BIt does not require a Server profile.
- CIt simplifies user administration.
- DIt automatically adds new users to the appropriate group.
- EIt allows an administrator to write more granular policies.
How the community answered
(30 responses)- A3% (1)
- B10% (3)
- C87% (26)
Why each option
User-to-group mapping streamlines user management by leveraging external directory services to simplify administration, automatically assign new users to groups, and enable the creation of more granular security policies on the firewall.
User-to-group mapping typically requires configuring server profiles (e.g., LDAP), user identification agents, and potentially group mapping objects, which are additional configurations.
User-to-group mapping usually relies on server profiles (such as LDAP or RADIUS profiles) to authenticate and retrieve group information from external directory services.
By defining policies based on groups from an external directory, administrators can manage user access from a central directory, significantly simplifying firewall policy administration compared to individual user rules.
When new users are added to pre-configured groups in the external directory service, the firewall automatically applies the corresponding group-based policies to them, reducing manual configuration on the firewall.
User-to-group mapping allows security policies to be written for specific user groups, enabling fine-grained control over network access and application usage based on roles, departments, or privilege levels.
Concept tested: Advantages of user-to-group mapping for policy
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/user-id-overview/user-id-benefits
Topics
Community Discussion
No community discussion yet for this question.