Exam PCNSE All QuestionsBrowse all questions from this exam
Question 124

Which User-ID method maps IP addresses to usernames for users connecting through a web proxy that has already authenticated the user?

    Correct Answer: A

    Syslog listening is the correct method to map IP addresses to usernames for users connecting through a web proxy that has already authenticated the user. This involves the User-ID agent interpreting login and logout event messages sent to syslog servers from devices that have authenticated the users, such as proxy servers. This enables the mapping of IP addresses to corresponding usernames efficiently.

Discussion
aatechlerOption: A

Syslog: The Windows-based User-ID agent and the PAN-OS integrated User-ID agent use Syslog Parse Profiles to interpret login and logout event messages that are sent to syslog servers from devices that authenticate users. Such devices include wireless controllers, 802.1x devices, Apple Open Directory servers, proxy servers, and other network access control devices. Server monitoring: A Windows-based User-ID agent, or the built-in PAN-OS integrated User-ID agent inside the PAN-OS firewall, monitors Security Event logs for successful login and logout events on Microsoft domain controllers, Exchange servers, or Novell eDirectory servers.

TAKUM1yOption: A

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-id-to-monitor-syslog-senders-for-user-mapping/configure-the-pan-os-integrated-user-id-agent-as-a-syslog-listener#id91eb3abd-43c1-4969-8a5f-df032685e277

z8d21oczdOption: B

Yes listen to syslogs. But this is configured in Server Monitoring Section were you create a new Server Monitor with type Syslog Sender. So, logically it is a syslog listener but in palo alto terms it is a server monitor

z8d21oczd

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-id-to-monitor-syslog-senders-for-user-mapping/configure-the-pan-os-integrated-user-id-agent-as-a-syslog-listener#id91eb3abd-43c1-4969-8a5f-df032685e277

Gngogh

Server monitor can also be used to configure monitor for AD, Exchange and Novel-e. In this case Syslog listener is the most specific answer.

venkat_narsimuluOption: A

Ans should be A

nk12Option: A

Correct Answer: A To obtain user mappings from existing network services that authenticate users—such as wireless controllers, 802.1x devices, Apple Open Directory servers, proxy servers, or other Network Access Control (NAC) mechanisms—Configure User-ID to Monitor Syslog Senders for User Mapping.

Chris71Mach1

Best/proper explanation for this. Thanks!

nekkrokvlt

Correct answer should be https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/user-id-concepts/user-mapping/xff-headers

rammsdoctOption: A

A: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-ip-addresses-to-users

MarshpillowzOption: A

Answer is A

petros_K

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/user-id-overview.html