exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 355 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 355
Topic #: 1
[All PCNSA Questions]

When configuring a security policy, what is a best practice for User-ID?

  • A. Use only one method for mapping IP addresses to usernames.
  • B. Allow the User-ID agent in zones where agents are not monitoring services.
  • C. Limit User-ID to users registered in an Active Directory server.
  • D. Deny WMI traffic from the User-ID agent to any external zone.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cjace
11 months, 2 weeks ago
D. Deny WMI traffic from the User-ID agent to any external zone1 WMI, or Windows Management Instrumentation, is a mechanism that can be used to actively probe managed Windows systems to learn IP-user mappings1. Because WMI probing trusts data reported back from the endpoint, it is not a recommended method of obtaining User-ID information in a high-security network1. On sensitive and high-security networks, WMI probing increases the overall attack surface, and administrators are recommended to disable WMI probing and instead rely upon User-ID mappings obtained from more isolated and trusted sources, such as domain controllers
upvoted 2 times
...
perceptivity
1 year, 9 months ago
Selected Answer: D
Only enable User-ID on trusted zones. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVPCA0
upvoted 4 times
hackeryorch
10 months, 3 weeks ago
If WMI probing is used, it should not be enabled on external untrusted interfaces
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago