Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Next-Generation Firewall Engineer

Domain 2Objective 6

2.6 Configure On-Premises and Cloud Identity Engine User-ID NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 4)

Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.

20questions here
4free pages
6concepts
40%of the exam

Questions 16–20

  1. 16foundation · easy

    Which component can receive redistributed user-to-IP mappings?

    Select an answer first
  2. 17foundation · easy

    In a User-ID segment, what is typically defined to specify which users are included?

    Select an answer first
  3. 18foundation · easy

    Which directory type is directly supported for Group Mapping configuration on a Palo Alto Networks firewall?

    Select an answer first
  4. 19application · medium

    A global company has a PAN-OS firewall in its headquarters and a Cloud Identity Engine (CIE) tenant. The company wants to enforce consistent user-based policies across all locations, including remote offices that do not have a direct connection to the HQ firewall. The remote offices have local Active Directory domain controllers. What should be configured to ensure user and group information is available for policy enforcement at the remote offices?

    Select an answer first
  5. 20foundation · easy

    What is the purpose of directory synchronization in User-ID?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.