nerdexam
Palo_Alto_Networks

PCNSE · Question #471

An administrator needs to build Security rules in a Device Group that allow traffic to specific users and groups defined in Active Directory. What must be configured in order to select users and group

The correct answer is B. A master device with Group Mapping configured must be set in the device group where the. When building Security rules in a Panorama Device Group that reference Active Directory users and groups, Panorama needs a source for group mapping data. A master device must be designated within the device group, and that master device must have Group Mapping configured and oper

Submitted by femi9· Apr 18, 2026Deploy and Configure

Question

An administrator needs to build Security rules in a Device Group that allow traffic to specific users and groups defined in Active Directory. What must be configured in order to select users and groups for those rules from Panorama?

Options

  • AThe Security rules must be targeted to a firewall in the device group and have Group Mapping
  • BA master device with Group Mapping configured must be set in the device group where the
  • CUser-ID Redistribution must be configured on Panorama to ensure that all firewalls have the
  • DA User-ID Certificate profile must be configured on Panorama

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    89% (25)
  • D
    7% (2)

Explanation

When building Security rules in a Panorama Device Group that reference Active Directory users and groups, Panorama needs a source for group mapping data. A master device must be designated within the device group, and that master device must have Group Mapping configured and operational. Panorama queries the master device to retrieve the list of AD users and groups, making them available for selection when authoring policy rules at the Device Group level. Without a master device that has Group Mapping enabled, Panorama has no mechanism to enumerate AD objects for use in shared policy rules. Options A, C, and D describe features that exist but do not fulfill the specific requirement of making AD user/group objects selectable in Panorama Device Group rules.

Topics

#User-ID#Group Mapping#Panorama#Active Directory

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice