Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 240 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 240
Topic #: 1
[All PCNSE Questions]

A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama.
Which configuration is necessary to retrieve groups from Panorama?

  • A. Configure an LDAP Server profile and enable the User-ID service on the management interface.
  • B. Configure a group mapping profile to retrieve the groups in the target template.
  • C. Configure a Data Redistribution Agent to receive IP User Mappings from User-ID agents.
  • D. Configure a master device within the device groups.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Gab99
Highly Voted 1 year, 2 months ago
Selected Answer: A
I am not sure what you are all relating to, but .. AD groups are always gathered from LDAP(AD servers), so an LDAP profile must be distributed via template from Panorama. Each FW gets his groups then directly from LDAP. The MASTER DEVICE is ONLY used for User-ID information gathering! Please take a look in Panorama Device groups, label says "master device is the firewall which Panorama gathers user ID info for use in policies". Nothing to do with groups here! So answer CANNOT be D if the questrion is related to AD groups! Only A or B are possible.
upvoted 6 times
Jared28
1 month, 2 weeks ago
Answer is C Direct from Panorama, when you select a User ID Master device the check option for it specifies to store groups too. "Store users and groups from Master Device if Reporting and Filtering on Groups is enabled in Panorama Settings"
upvoted 1 times
Jared28
1 month, 2 weeks ago
Whoops, meant D, the answer is D
upvoted 1 times
...
...
...
scanossa
Most Recent 2 months, 1 week ago
Selected Answer: D
On the device group settings, you would have to select the master device from which Panorama would pull the users' information from
upvoted 1 times
...
Whizdhum
4 months ago
Answer is D. To simplify the creation or modification of user- and group-based policies, you can use a Master Device to add the group names to drop-down lists in security policy rules. You need to designate a firewall as a Master Device for each device group. After you add a Master Device, the device group inherits all policies defined on the master device; for this reason, it should be a standalone, dedicated device to be used for that device group. Alternatively, you can enable username-to-user group mapping using an LDAP profile with a Group Include List.
upvoted 1 times
...
Metgatz
4 months, 1 week ago
D is correct Option
upvoted 1 times
...
davidpm
8 months ago
Selected Answer: D
D Correct https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG
upvoted 1 times
...
TAKUM1y
1 year, 6 months ago
Selected Answer: D
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG
upvoted 3 times
...
Alen
1 year, 8 months ago
as per everyones comments, the question needs to be re-worded. if groups are to be pulled from firewall, then D is correct
upvoted 1 times
...
JMIB
1 year, 8 months ago
D correct
upvoted 2 times
...
habeeb222
1 year, 8 months ago
pulling from Panaroma* B - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0
upvoted 1 times
...
UFanat
1 year, 9 months ago
Selected Answer: D
D correct
upvoted 2 times
...
mtopolovec
1 year, 10 months ago
This question is not formed right. It is asking about "retrieving groups from Panorama", but it should be about "Panorama retrieving groups from Firewall".
upvoted 1 times
...
DavidBackham2020
2 years, 3 months ago
D is correct but you still need to get the group information on the master device (firewall) which I already configured as decried in A. Please note: You cannot configure A on Panorama. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFQCA0 I guess what I am trying to say: I don't like the question. But D seems to be the most correct answer, ignoring how the Group information is provided to the FW.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...