exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 88 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 88
Topic #: 1
[All PCNSA Questions]

Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilized.
Which User-ID agent is sufficient in your network?

  • A. Windows-based agent deployed on each domain controller
  • B. PAN-OS integrated agent deployed on the firewall
  • C. Citrix terminal server agent deployed on the network
  • D. Windows-based agent deployed on the internal network a domain member
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
debabani
Highly Voted 2 years, 5 months ago
B should be the answer:
upvoted 8 times
...
o0ZACK0o
Most Recent 4 months, 1 week ago
Selected Answer: B
The PAN-OS Integrated Agent is more efficient in terms of network resources since it filters logs, whereas the Windows-Based Agent sends all security logs to the firewall.
upvoted 2 times
...
kuaiquchifan
6 months, 1 week ago
Selected Answer: B
It mentioned 'slightly" used
upvoted 2 times
...
DDisGR8
11 months ago
Selected Answer: B
Less than 10 DCs and minimal utilized management plane makes B the choice.
upvoted 3 times
...
z8d21oczd
1 year ago
Selected Answer: B
Only two DCs, same network, same location, slightly utilized management plane... obviously B.
upvoted 3 times
...
vexon
1 year ago
B Which User-ID agent should I use? Use agentless (PAN-OS) If you have a small to medium deployment with 10 or fewer Domain controllers or Exchange servers If you wish to share PAN-OS sourced mappings from AD, Captive portal or Global Protect with other PA devices (max 255 devices) Use User-ID Agent (Windows) If you have medium to large deployment with more than 10 domain controllers If you have multi-domain setup with large number of servers to monitor
upvoted 1 times
...
Letrange
1 year, 1 month ago
It can't be A because PAN doesn't recommend to install the windows agent in the domain controller. I think the correct answer is B.
upvoted 1 times
...
daan5000
1 year, 3 months ago
When they're talking about "sufficient bandwidth" and "sufficient resources" on the firewall, they are always hinting at the PAN-OS integrated agent. When they're talking about "limited network bandwidth" and/or the "management plane is heavily used", then they want you to use the Server agent.
upvoted 4 times
...
yurakoresh
1 year, 5 months ago
Selected Answer: A
PAN-OS Integrated User-ID Agent agent is used mostly for remote sites and it can't handle multiforest domains. Windows-based User-ID Agent at the local site. In this case its all on the same network so I think it should be "A"
upvoted 1 times
...
Rowdy_47
1 year, 10 months ago
Although, the Windows-based agent and the PAN-OS integrated agent perform the same basic tasks, they use different underlying communication protocols. This difference makes each agent more appropriate for different environments. The Windows-based agent uses MS-RPC, which requires the full Windows Security logs to be sent to the agent, where they are filtered for the relevant User-ID information. The PAN-OS integrated agent uses either the Windows Management Instrumentation, of WMI, or the Windows Remote Management Protocol, or WinRM which enables the agent to retrieve only the User-ID information from the Windows Security logs. The result is that, in an infrastructure with remote networks separated with WAN links, the integrated agent is more appropriate for reading remote logs and the Windows-based agent is more appropriate for reading local logs.However, uses of the integrated agent is not without cost: it consumes more of the firewall’s management plane resources. For this reason, deployment of the Windows agent at remote sites and having them forward the relevant User-ID information to firewall on a central network often is beneficial.
upvoted 2 times
...
Defvianti
2 years, 4 months ago
More then one domain? That is not supported with PA agent
upvoted 2 times
jonboy22
1 year, 3 months ago
The integrated agent can handle pup to 100 domains. https://www.routeprotocol.com/palo-altro-edu-110-user-id/
upvoted 1 times
...
jonboy22
1 year, 3 months ago
The integrated agent can only handle 1 AD domain, but can monitor up to 100 domain controllers. This question doesn't say more than one AD is active. Therefore, i believe B is correct.
upvoted 1 times
...
...
Lucerorudeboy
2 years, 5 months ago
network bandwidth isn't an issue in this case, I think A is correct
upvoted 1 times
...
atifikhan
2 years, 6 months ago
, if network bandwidth is an issue, you might want to use the PAN-OS integrated agent because it communicates directly with the servers, whereas the Windows agent communicates with the servers and then communicates the User-ID information to the firewall so that it can update the firewall database. For more information about the different agents and how they are used, see the following information: • “Block Threats by Identifying Users ” module in the EDU-110 and EDU-210 training, Firewall Essentials: Configuration and Management I think B is correct answer
upvoted 4 times
...
ElDTO91
2 years, 7 months ago
B should be the answer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago