nerdexam
Palo_Alto_Networks

PCNSE · Question #874

An organization uses the User-ID agent to control access to sensitive internal resources. A firewall engineer adds Security policies to ensure only User A has access to a specific resource. User A was

The correct answer is D. ensures the agent monitors and maps those IPs, resolving connectivity by aligning User-ID. User-ID maps IP addresses to usernames so that security policies can be applied per-user. If the User-ID agent is not monitoring and mapping all IP addresses that User A's machine uses-for example, if the user's IP changes or a secondary IP is used-the firewall intermittently can

Submitted by anna_se· Apr 18, 2026Configuration Troubleshooting

Question

An organization uses the User-ID agent to control access to sensitive internal resources. A firewall engineer adds Security policies to ensure only User A has access to a specific resource. User A was able to access the resource without issue before the updated policies, but now is having intermittent connectivity issues. What is the most likely resolution to this issue?

Options

  • AAdd service accounts running on that machine to the "Ignore User List" in the User-ID agent
  • BRemove the identity redistribution rules synced from Cloud Identity Engine from the User-ID agent
  • CRemove the rate-limiting rule that is assigned to User A access from the User-ID agent
  • Densures the agent monitors and maps those IPs, resolving connectivity by aligning User-ID

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    85% (22)

Explanation

User-ID maps IP addresses to usernames so that security policies can be applied per-user. If the User-ID agent is not monitoring and mapping all IP addresses that User A's machine uses-for example, if the user's IP changes or a secondary IP is used-the firewall intermittently cannot match traffic to User A's identity, causing policy enforcement to fail unpredictably. The resolution is to ensure the User-ID agent correctly monitors and maps all relevant IP addresses to User A, aligning the IP-to-user mapping so that the security policy is consistently applied. Service accounts (choice A) cause spurious mappings, but adding them to the ignore list would only help if those accounts were overwriting User A's mapping-not the primary issue described here.

Topics

#User-ID#Troubleshooting#Identity Mapping#Security Policy Enforcement

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice