PSE-STRATA-PRO-24 · Question #24
A company with a large Active Directory (AD) of over 20,000 groups has user roles based on group membership in the directory. Up to 1,000 groups may be used in Security policies. The company has…
The correct answer is C. Configure a group mapping profile with an include group list. Synchronizing a large Active Directory (AD) with over 20,000 groups can introduce significant overhead if all groups are synchronized, especially when only a subset of groups (e.g., 1,000 groups) are required for Security policies. The most efficient approach is to configure a…
Question
A company with a large Active Directory (AD) of over 20,000 groups has user roles based on group membership in the directory. Up to 1,000 groups may be used in Security policies. The company has limited operations personnel and wants to reduce the administrative overhead of managing the synchronization of the groups with their firewalls. What is the recommended architecture to synchronize the company's AD with Palo Alto Networks firewalls?
Options
- AConfigure a group mapping profile with custom filters for LDAP attributes that are mapped to the
- BConfigure a group mapping profile, without a filter, to synchronize all groups.
- CConfigure a group mapping profile with an include group list.
- DConfigure NGFWs to synchronize with the AD after deploying the Cloud Identity Engine (CIE) and
How the community answered
(65 responses)- A3% (2)
- B6% (4)
- C78% (51)
- D12% (8)
Explanation
Synchronizing a large Active Directory (AD) with over 20,000 groups can introduce significant overhead if all groups are synchronized, especially when only a subset of groups (e.g., 1,000 groups) are required for Security policies. The most efficient approach is to configure a group mapping profile with an include group list to minimize unnecessary synchronization and reduce administrative overhead. Using a group mapping profile with an include group list ensures that only the required 1,000 groups are synchronized with the firewall. This approach: Reduces the load on the firewall's User-ID process by limiting the number of synchronized goups. Simplifies management by focusing on the specific groups relevant to Security policies. Avoids synchronizing the entire directory (20,000 groups), which would be inefficient and resource- intensive.
Topics
Community Discussion
No community discussion yet for this question.