nerdexam
Palo_Alto_Networks

PCNSA · Question #385

What are three advantages of user-to-group mapping? (Choose three.)

The correct answer is C. It simplifies user administration. D. It automatically adds new users to the appropriate group. E. It allows an administrator to write more granular policies. User-to-group mapping streamlines user management by leveraging external directory services to simplify administration, automatically assign new users to groups, and enable the creation of more granular security policies on the firewall.

Submitted by diego_uy· Apr 18, 2026Policy Evaluation and Management

Question

What are three advantages of user-to-group mapping? (Choose three.)

Options

  • AIt does not require additional objects to be configured.
  • BIt does not require a Server profile.
  • CIt simplifies user administration.
  • DIt automatically adds new users to the appropriate group.
  • EIt allows an administrator to write more granular policies.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    87% (26)

Why each option

User-to-group mapping streamlines user management by leveraging external directory services to simplify administration, automatically assign new users to groups, and enable the creation of more granular security policies on the firewall.

AIt does not require additional objects to be configured.

User-to-group mapping typically requires configuring server profiles (e.g., LDAP), user identification agents, and potentially group mapping objects, which are additional configurations.

BIt does not require a Server profile.

User-to-group mapping usually relies on server profiles (such as LDAP or RADIUS profiles) to authenticate and retrieve group information from external directory services.

CIt simplifies user administration.Correct

By defining policies based on groups from an external directory, administrators can manage user access from a central directory, significantly simplifying firewall policy administration compared to individual user rules.

DIt automatically adds new users to the appropriate group.Correct

When new users are added to pre-configured groups in the external directory service, the firewall automatically applies the corresponding group-based policies to them, reducing manual configuration on the firewall.

EIt allows an administrator to write more granular policies.Correct

User-to-group mapping allows security policies to be written for specific user groups, enabling fine-grained control over network access and application usage based on roles, departments, or privilege levels.

Concept tested: Advantages of user-to-group mapping for policy

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/user-id-overview/user-id-benefits

Topics

#User-to-Group Mapping#User-ID#Security Policy#Administration

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice