Courseiva
Securing Traffic →easyMultiple Choice

PCNSA Securing Traffic Practice Question

An administrator wants to block traffic from a specific user using User-ID. What is required to identify users in security policies?

⚠ Common exam trap

PCNSA often tests the misconception that SSL decryption or App-ID is needed to identify users, when in fact User-ID depends on directory integration or captive portal authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure User-ID by integrating with Active Directory or using captive portal.

User-ID requires a source of user-to-IP mapping. The two supported methods on Palo Alto Networks firewalls are integrating with a directory service such as Active Directory (via the User-ID Agent or Windows-based agent) or using captive portal to force users to authenticate. Once mappings exist, security policies can reference users or groups in the Source User field.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy SSL decryption to see user credentials.

    Why it's wrong here

    SSL decryption exposes encrypted payloads but does not itself create user-to-IP mappings for policy enforcement. It is tempting because credentials appear in decrypted traffic, and decryption would be the correct choice when the requirement is inspecting encrypted application content, not identifying users for policy.

  • ✓

    Configure User-ID by integrating with Active Directory or using captive portal.

    Why this is correct

    Integrating with Active Directory or deploying captive portal provides the user-to-IP mapping that User-ID requires, satisfying the stem's need to identify users in policy. Security policies match on usernames only after this mapping exists; without it, the firewall cannot attribute traffic to a specific user.

  • ✗

    Enable URL Filtering to track user visits.

    Why it's wrong here

    URL Filtering categorises web destinations; it does not perform user mapping, so the policy cannot match a username. It is tempting because URL logs show browsing activity, and URL Filtering would be the correct choice when the requirement is controlling access to specific website categories rather than identifying the user.

  • ✗

    Activate App-ID to detect user login events.

    Why it's wrong here

    App-ID classifies applications; it does not map IP addresses to usernames, so no user identity reaches the policy. It is tempting because App-ID and User-ID are configured together, and App-ID would be the correct choice when the requirement is identifying which application is traversing the firewall rather than which user.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.