nerdexam
Palo_Alto_Networks

PSE-SASE · Question #93

A net new customer has a hard requirement for Active Directory Groups while looking for an SSE solution in order to create policies against a group of users, as opposed to individual users. Without…

The correct answer is D. Cloud Identity Engine. Cloud Identity Engine (CIE) is Palo Alto Networks' cloud-native service that connects directly to identity providers like Active Directory to sync user and group membership data into Prisma Access. Because it operates entirely in the cloud, it enables group-based policy…

Prisma Access Deployment and Configuration

Question

A net new customer has a hard requirement for Active Directory Groups while looking for an SSE solution in order to create policies against a group of users, as opposed to individual users. Without external hardware, what will enable group mappings to be accomplished with Prisma Access natively?

Options

  • AAuthentication profiles
  • BUser correlation profiles
  • CUser-ID
  • DCloud Identity Engine

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    78% (18)

Explanation

Cloud Identity Engine (CIE) is Palo Alto Networks' cloud-native service that connects directly to identity providers like Active Directory to sync user and group membership data into Prisma Access. Because it operates entirely in the cloud, it enables group-based policy creation without requiring an on-premises User-ID agent or any additional hardware - exactly what a net new customer needs for an SSE deployment.

Why the distractors fail:

  • A. Authentication profiles define how users authenticate (SAML, LDAP methods), not who belongs to which group for policy purposes.
  • B. User correlation profiles are used to correlate threat activity to users, not to map AD groups into policy objects.
  • C. User-ID is the underlying Palo Alto mechanism for IP-to-user mapping, but in its traditional form it requires an on-premises User-ID agent - hardware/software that the question explicitly rules out. CIE extends this capability to the cloud natively.

Memory tip: Think of CIE as "User-ID without the hardware." If the question mentions cloud, SSE, no on-prem agents, or group-based policy for new customers - Cloud Identity Engine is almost always the answer.

Topics

#Cloud Identity Engine#Active Directory#group mapping#identity integration

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice