nerdexam
Palo_Alto_Networks

PCNSA · Question #83

Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilized. Which User-ID…

The correct answer is B. PAN-OS integrated agent deployed on the firewall. Which User-ID agent should I use? Use agentless (PAN-OS) If you have a small to medium deployment with 10 or fewer Domain controllers or Exchange If you wish to share PAN-OS sourced mappings from AD, Captive portal or Global Protect with other PA devices (max 255 devices) Use…

Submitted by mateo_ar· Apr 18, 2026Deploy

Question

Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilized. Which User-ID agent is sufficient in your network?

Options

  • AWindows-based agent deployed on each domain controller
  • BPAN-OS integrated agent deployed on the firewall
  • CCitrix terminal server agent deployed on the network
  • DWindows-based agent deployed on the internal network a domain member

How the community answered

(24 responses)
  • B
    96% (23)
  • C
    4% (1)

Explanation

Which User-ID agent should I use? Use agentless (PAN-OS) If you have a small to medium deployment with 10 or fewer Domain controllers or Exchange If you wish to share PAN-OS sourced mappings from AD, Captive portal or Global Protect with other PA devices (max 255 devices) Use User-ID Agent (Windows) If you have medium to large deployment with more than 10 domain controllers If you have multi-domain setup with large number of servers to monitor

Topics

#User-ID#Agent Types#Deployment Strategy#Active Directory Integration

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice