Courseiva

PCNSE Core Concepts and Architecture Practice Question

A security administrator is designing a zero trust architecture using Palo Alto Networks Next-Generation Firewalls. They need to ensure that all traffic between the internal network and the internet is inspected, and that users are identified regardless of location. Which two components are required to achieve user identification for both on-premises and remote users? (Choose two.)

⚠ Common exam trap

The trap here is thinking that a single component can handle all user identification, when in fact different methods are needed for on-premises and remote users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User-ID Agent to monitor directory servers and map IP addresses to usernames for on-premises users.

To identify users both on-premises and remotely, the administrator needs GlobalProtect for remote users and a User-ID Agent for on-premises users. GlobalProtect authenticates remote users and provides IP-to-username mapping, while the User-ID Agent monitors directory servers to map IP addresses to usernames for internal users. Together, they enable consistent user-based policy enforcement across locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Captive Portal to authenticate users who are not covered by other User-ID methods.

    Why it's wrong here

    Captive Portal is used to authenticate users who are not identified by other methods, but it is not typically used for remote users or as a primary method for on-premises users. It is a fallback authentication method and does not by itself provide the comprehensive user identification required for both on-premises and remote users.

  • ✓

    User-ID Agent to monitor directory servers and map IP addresses to usernames for on-premises users.

    Why this is correct

    The User-ID Agent connects to directory servers such as Active Directory to retrieve user-to-IP mappings for on-premises users. This is essential for identifying users on the internal network, as it provides the mapping that the firewall uses in security policies to enforce user-based rules.

  • ✗

    Syslog forwarding to send user mapping logs to an external server.

    Why it's wrong here

    Syslog forwarding is used to send logs to external systems for monitoring or analysis, but it does not provide user identification. It is an output mechanism, not a source of user mapping, so it would not help identify users on the internal network or remotely.

  • ✗

    XML API to query the firewall for user mapping information.

    Why it's wrong here

    The XML API is used for programmatic access to the firewall, including querying user mapping information, but it does not itself perform user identification. It is a management interface, not a User-ID source, so it would not help achieve user identification for on-premises or remote users.

  • ✓

    GlobalProtect to authenticate remote users and map their IP addresses to usernames.

    Why this is correct

    GlobalProtect provides authentication for remote users and can map their IP addresses to usernames, enabling User-ID for traffic from remote locations. This is a key component for extending user identification beyond the corporate network, as it ensures that policies can be enforced based on user identity even when users are off-site.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.