nerdexam
Palo_Alto_Networks

PCNSE · Question #822

A firewall administrator has configured User-ID and deployed GlobalProtect, but there is no User- ID showing in the traffic logs. How can the administrator ensure that User-IDs are populated in the tr

The correct answer is D. Enable User-ID on the expected trusted zones.. For User-ID information to show up in the traffic logs, it needs to be properly configured and enabled in the trusted zones where users are authenticated. The firewall needs to gather User- ID information from the sources within these zones (such as the domain controllers, etc.).

Submitted by rania.sa· Apr 18, 2026Configuration Troubleshooting

Question

A firewall administrator has configured User-ID and deployed GlobalProtect, but there is no User- ID showing in the traffic logs. How can the administrator ensure that User-IDs are populated in the traffic logs?

Options

  • ACreate a Group Mapping for the GlobalProtect Group.
  • BEnable Captive Portal on the expected source interfaces.
  • CAdd the users to the proper Dynamic User Group.
  • DEnable User-ID on the expected trusted zones.

How the community answered

(16 responses)
  • A
    13% (2)
  • C
    6% (1)
  • D
    81% (13)

Explanation

For User-ID information to show up in the traffic logs, it needs to be properly configured and enabled in the trusted zones where users are authenticated. The firewall needs to gather User- ID information from the sources within these zones (such as the domain controllers, etc.). By enabling User-ID on the expected zones, the firewall can map users to their respective IP addresses and populate the User-ID in the traffic logs.

Topics

#User-ID#GlobalProtect#Traffic Logs#Zone Configuration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice