Courseiva
Zero Trust Architecture And DesignmediumMultiple SelectObjective-mapped

NetSec-Architect Zero Trust Architecture And Design Practice Question

An architect is designing a high-scale User-ID deployment using PAN-OS firewalls and Panorama. Which TWO methods can be utilized to gather user mapping information directly from Active Directory without relying solely on client-side software agents? (Choose two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring PAN-OS to listen for Syslog security log entries emitted from authentication servers or SIEMs

PAN-OS integrated User-ID mapping supports direct Windows User-ID agentless polling of security logs (WMI/RPC) and Syslog monitoring from authentication sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configuring XML API push notifications directly from the VMware NSX manager

    Why it's wrong here

    NSX manager integration maps hypervisor tags, not Active Directory user login identities.

  • Configuring PAN-OS to listen for Syslog security log entries emitted from authentication servers or SIEMs

    Why this is correct

    Syslog listening allows the firewall to parse authentication events sent from external logging systems or directory servers.

  • Installing the GlobalProtect app with embedded Host Information Profile (HIP) reporting on every user workstation

    Why it's wrong here

    GlobalProtect HIP reporting gathers workstation posture data, not raw Active Directory IP-to-username mappings.

  • Configuring PAN-OS Agentless User-ID to poll Active Directory domain controllers via WMI or Windows Security Event logs

    Why this is correct

    Agentless User-ID polls Windows domain controllers directly via WMI or RPC to read security event log logon IDs.

  • Enabling Terminal Server (TS) Agent on all client workstations

    Why it's wrong here

    TS Agent is specifically designed for multi-user terminal servers (Citrix/RDS), not individual standard client workstations.

About these practice questions

Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.