nerdexam
Palo_Alto_Networks

PSE-STRATA-PRO-24 · Question #40

A company plans to deploy identity for improved visibility and identity-based controls for least privilege access to applications and data. The company does not have an on-premises Active Directory…

The correct answer is C. GlobalProtect with an internal gateway deployment D. Cloud Identity Engine synchronized with Entra ID. In this scenario, the company does not use on-premises Active Directory and manages devices with Entra ID and Jamf, which implies a cloud-native and modern management setup. Option C: GlobalProtect is Palo Alto Networks' VPN solution, which allows for secure remote access. It…

Identity and Access Management

Question

A company plans to deploy identity for improved visibility and identity-based controls for least privilege access to applications and data. The company does not have an on-premises Active Directory (AD) deployment, and devices are connected and managed by using a combination of Entra ID and Jamf. Which two supported sources for identity are appropriate for this environment? (Choose two.)

Options

  • ACaptive portal
  • BUser-ID agents configured for WMI client probing
  • CGlobalProtect with an internal gateway deployment
  • DCloud Identity Engine synchronized with Entra ID

How the community answered

(62 responses)
  • A
    11% (7)
  • B
    6% (4)
  • C
    82% (51)

Explanation

In this scenario, the company does not use on-premises Active Directory and manages devices with Entra ID and Jamf, which implies a cloud-native and modern management setup. Option C: GlobalProtect is Palo Alto Networks' VPN solution, which allows for secure remote access. It also supports identity-based mapping when deployed with internal gateways. In this case, GlobalProtect with an internal gateway can serve as a mechanism to provide user and device visibility based on the managed devices connecting through the gateway. Option D: The Cloud Identity Engine provides a cloud-based approach to synchronize identity information from identity providers like Entra ID (formerly Azure AD). In a cloud-native environment with Entra ID and Jamf, the Cloud Identity Engine is a natural fit as it integrates seamlessly to provide identity visibility for applications and data.

Topics

#identity#GlobalProtect#Cloud Identity Engine#Entra ID

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA-PRO-24 Practice