exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 39 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 39
Topic #: 1
[All PCNSA Questions]

Which user mapping method could be used to discover user IDs in an environment with multiple Windows domain controllers?

  • A. Active Directory monitoring
  • B. Windows session monitoring
  • C. Windows client probing
  • D. domain controller monitoring
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LordScorpius
Highly Voted 2 years, 3 months ago
Selected Answer: D
"A" sounds so correct until you sit back and think, "Active Directory" isn't a thing on a LAN or WAN. It's an LDAP running on multiple domain controllers. "Monitor AD" isn't really a thing. Monitor Domain Controllers is.
upvoted 6 times
...
DC787
Highly Voted 3 years, 7 months ago
D To ensure the most comprehensive mapping of users, you must monitor all domain controllers that process authentication for users you want to map. You might need to install multiple User-ID agents to efficiently monitor all of your resources.
upvoted 5 times
...
Catza
Most Recent 6 days, 7 hours ago
Selected Answer: A
Server Monitoring -> Active Directory
upvoted 1 times
...
cjace
1 month, 3 weeks ago
A. Active Directory monitoring12 Active Directory monitoring allows the User-ID agent to monitor the security logs of Active Directory domain controllers for login events12. This information is used to map IP addresses to usernames12. The User-ID agent can monitor up to 100 servers, of which up to 50 can be syslog senders1. To collect all of the required mappings, the User-ID agent must connect to all servers that your users log in to in order to monitor the security log files on all servers that contain login events
upvoted 1 times
...
Totosos1
11 months ago
Selected Answer: D
I will go with D based on Palo's documentation: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/configure-the-windows-based-user-id-agent-for-user-mapping
upvoted 1 times
...
mr_flubber
1 year, 2 months ago
It's just a badly formulated question with questionable answers.
upvoted 2 times
...
BMRobertson
1 year, 5 months ago
I'm thinking D for two reasons: 1. You don't find the phrase "Active Directory Monitoring" anywhere in the documentation (I stand to be corrected); and 2. domain controller monitoring fits with EDU 110 (https://www.routeprotocol.com/palo-altro-edu-110-user-id/). But honestly...this is a stupid question that should have had "Server Monitoring" as the straight answer. I guess the implicit thought is that a domain controller is a server so in a weird way domain controller monitoring = server monitoring.
upvoted 1 times
...
seb_berlin
1 year, 6 months ago
Selected Answer: A
Path: Device/User Identification/Server Monitoring and then as type: Microsoft Active Directory So answer A seems correct to me.
upvoted 3 times
BMRobertson
1 year, 5 months ago
IDK, take a look at this link: https://www.routeprotocol.com/palo-altro-edu-110-user-id/....my question is, why don't we find Active Directory Monitoring at all in the studyguide? I do find this: In terms of Domain Controllers User-ID, When a user logs into their laptop, which is an Active Directory member, the AD domain controller logs a logon event with the username and IP address of the station." Again, not sure but you won't find "AD monitoring as a term/phrase anywhere (at least that I've found). For that reason I'd go with D.
upvoted 1 times
...
...
KirinKev
1 year, 6 months ago
Selected Answer: D
I think D is the most accuratte following, accordin to this, https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/user-id-concepts/user-mapping/server-monitoring#id89aad143-05b8-4805-8e7c-b123994edd30
upvoted 1 times
...
daytonadave2011
1 year, 6 months ago
None of these answers are correct. The answer you're looking for is "Server Monitoring".
upvoted 2 times
...
nuWat
1 year, 9 months ago
I think the correct answer should be "Server Monitoring"
upvoted 1 times
...
Hargert
2 years ago
Selected Answer: D
D is correct you monitor domain controllers
upvoted 1 times
...
Sandman77
2 years, 1 month ago
Selected Answer: D
D is correct
upvoted 2 times
...
ryel92
2 years, 6 months ago
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/user-id-concepts/user-mapping/server-monitoring.html#id89aad143-05b8-4805-8e7c-b123994edd30
upvoted 1 times
...
Cyril_the_Squirl
2 years, 8 months ago
A is correct. In an AD environment, you can configure the User-ID agent to monitor the security logs for Kerberos ticket grants or renewals, Exchange server access (if configured), and file and print service connections. For these events to be recorded in the security log, the AD domain must be configured to log successful account login events. In addition, because users can log in to any of the servers in the domain, you must set up server monitoring for all servers to capture all user login events. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/user-id-concepts/user-mapping/server-monitoring.html#id89aad143-05b8-4805-8e7c-b123994edd30
upvoted 3 times
...
vvss
2 years, 11 months ago
D: "...To ensure the most comprehensive mapping of users, you must monitor all domain controllers that process authentication for users you want to map. You might need to install multiple User-ID agents to efficiently monitor all of your resources.>"
upvoted 3 times
...
aoshy
3 years, 10 months ago
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago