Courseiva
Manage, Monitor and Operate →mediumMultiple Choice

PCNSE Manage, Monitor and Operate Practice Question

A company has configured User-ID with Active Directory polling. Some users cannot access resources even though their security policy rules appear correct. The administrator verifies that the User-ID agent is connected and polling. What additional step should the administrator take?

⚠ Common exam trap

Test-takers frequently assume a connected and polling User-ID agent guarantees correct policy enforcement, overlooking the critical step of verifying group mapping accuracy, which is a common misconfiguration in Active Directory environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the user group mapping is correct.

Even if the User-ID agent is connected and polling, the firewall may not have the correct group-to-user mappings. Without accurate group mapping, security policies that reference user groups will fail to match, causing access issues for users who are members of those groups. The administrator should verify the group mapping configuration in the User-ID agent or on the firewall to ensure users are properly associated with their groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restart the User-ID agent service.

    Why it's wrong here

    Restarting the service clears no stale mappings; the agent already polls successfully, so the fault lies in how the firewall maps IP to user, typically requiring a User-ID agent or terminal server agent on the specific source. Restarts suit crashed or hung agents, not mapping gaps.

  • ✗

    Check the firewall's management plane CPU usage.

    Why it's wrong here

    Management plane CPU load does not affect User-ID mapping accuracy; the firewall would still resolve users. The real gap is usually group mapping or the User-ID agent's include list. CPU checking is the right step when management responsiveness or commit times degrade, not when mappings are missing.

  • ✗

    Ensure the firewall has a license for User-ID.

    Why it's wrong here

    User-ID licensing is included with the base firewall licence, so a missing licence cannot explain selective failures while polling works. Licensing checks belong to subscription features such as WildFire or DNS Security, not to user mapping, which the stem already shows functioning.

  • ✓

    Verify that the user group mapping is correct.

    Why this is correct

    Group mapping determines which users inherit policy based on their directory groups. With Active Directory polling, the agent retrieves group membership alongside user-to-IP mappings, so stale or incorrect group data leaves users unmatched by rules. Verifying mapping confirms the identity data feeding policy evaluation is accurate, resolving access failures despite correct rules.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.