PCNSE · Question #355
Users within an enterprise have been given laptops that are joined to the corporate domain. In some cases, IT has also deployed Linux-based OS systems with a graphical desktop. Information Security…
The correct answer is D. You can deploy the User-ID agent on the Linux desktop machines. To capture IP-to-user mapping for Linux desktop users, an organization can deploy a User-ID agent or integrate User-ID mechanisms to collect authentication information directly from the Linux machines.
Question
Users within an enterprise have been given laptops that are joined to the corporate domain. In some cases, IT has also deployed Linux-based OS systems with a graphical desktop. Information Security needs IP-to-user mapping, which it will use in group-based policies that will limit internet access for the Linux desktop users. Which method can capture IP-to-user mapping information for users on the Linux machines?
Options
- AYou can configure Captive Portal with an authentication policy.
- BIP-to-user mapping for Linux users can only be learned if the machine is joined to the domain.
- CYou can set up a group-based security policy to restrict internet access based on group
- DYou can deploy the User-ID agent on the Linux desktop machines
How the community answered
(41 responses)- B5% (2)
- C2% (1)
- D93% (38)
Why each option
To capture IP-to-user mapping for Linux desktop users, an organization can deploy a User-ID agent or integrate User-ID mechanisms to collect authentication information directly from the Linux machines.
While Captive Portal can obtain user identity, it requires active user interaction and is not the most efficient or passive method for continuous IP-to-user mapping on managed corporate systems like a User-ID agent.
This statement is incorrect because User-ID can acquire IP-to-user mapping from various sources, including syslog and API integrations, extending beyond domain-joined Windows machines to Linux environments.
Setting up a group-based security policy is the *application* of IP-to-user mapping for access control, not the method for *capturing* the mapping information itself.
Deploying the User-ID agent (or configuring a clientless User-ID method that integrates with Linux authentication sources like syslog) allows the firewall to directly acquire IP-to-user mapping from Linux desktop machines.
Concept tested: User-ID mapping for non-Windows endpoints
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/user-id-concepts.html
Topics
Community Discussion
No community discussion yet for this question.