nerdexam
Palo_Alto_Networks

PCNSE · Question #124

Which two actions are required to make Microsoft Active Directory users appear in a firewall traffic log? (Choose two.)

The correct answer is A. Run the User-ID Agent using an Active Directory account that has "event log viewer" permissions C. Enable User-ID on the zone object for the source zone. To display Microsoft Active Directory users in firewall traffic logs, the User-ID Agent must be configured with appropriate permissions to read AD event logs, and User-ID must be enabled on the firewall's source zone.

Submitted by priya_blr· Apr 18, 2026Deploy and Configure

Question

Which two actions are required to make Microsoft Active Directory users appear in a firewall traffic log? (Choose two.)

Options

  • ARun the User-ID Agent using an Active Directory account that has "event log viewer" permissions
  • BConfigure a RADIUS server profile to point to a domain controller
  • CEnable User-ID on the zone object for the source zone
  • DEnable User-ID on the zone object for the destination zone
  • ERun the User-ID Agent using an Active Directory account that has "domain administrator"

How the community answered

(56 responses)
  • A
    89% (50)
  • B
    4% (2)
  • D
    2% (1)
  • E
    5% (3)

Why each option

To display Microsoft Active Directory users in firewall traffic logs, the User-ID Agent must be configured with appropriate permissions to read AD event logs, and User-ID must be enabled on the firewall's source zone.

ARun the User-ID Agent using an Active Directory account that has "event log viewer" permissionsCorrect

The Palo Alto Networks User-ID Agent needs to read security event logs from Active Directory domain controllers to map user IP addresses to usernames. The account used by the agent must have "event log viewer" permissions on the domain controllers to access these logs.

BConfigure a RADIUS server profile to point to a domain controller

RADIUS is primarily used for authentication and authorization, not for passive user-to-IP mapping for traffic logging purposes as User-ID does.

CEnable User-ID on the zone object for the source zoneCorrect

User-ID functionality, which maps IP addresses to usernames, must be explicitly enabled on the firewall security zone objects for the traffic that needs to be identified. Enabling it on the source zone ensures that incoming traffic from that zone has its users identified.

DEnable User-ID on the zone object for the destination zone

While User-ID is enabled on zones, it's typically enabled on the *source* zone where the users originate, not the destination zone, for user identification in traffic logs.

ERun the User-ID Agent using an Active Directory account that has "domain administrator"

Running the User-ID Agent with "domain administrator" privileges is an excessive and unnecessary permission level for merely reading event logs; "event log viewer" is sufficient and adheres to the principle of least privilege.

Concept tested: Palo Alto Networks User-ID for Active Directory integration

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/deploy-user-id/configure-user-id-for-user-mapping.html

Topics

#User-ID#Active Directory Integration#Zone Configuration#User-ID Agent

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice