PCNSE Core Concepts and Architecture Practice Question
An organization uses User-ID with agent-based mapping on a Palo Alto Networks firewall. Users authenticate to a domain but some user-to-IP mappings are not showing up in the firewall's user cache. The firewall can reach the domain controllers. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume connectivity issues (like DNS or reachability) are the cause, but the question explicitly states the firewall can reach the domain controllers, narrowing the focus to authentication and configuration of the User-ID agent itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The User-ID agent is not configured with the correct domain credentials or domain name.
The User-ID agent requires valid domain credentials and the correct domain name to query Active Directory for user-to-IP mappings. If these are misconfigured, the agent cannot authenticate to the domain controllers, and no mappings will be populated in the firewall's user cache, even though network connectivity exists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Panorama must be used to distribute User-ID configurations.
Why it's wrong here
Panorama is not required for User-ID; a firewall can run the User-ID agent or direct LDAP integration locally. Panorama is tempting because it centrally manages policies and can push User-ID configs, but it would be correct only when the organisation already uses Panorama for centralised User-ID distribution.
- ✗
The firewall's DNS settings are incorrect, preventing user lookup.
Why it's wrong here
Agent-based User-ID receives mappings from the agent over its own channel, so firewall DNS resolution is not required for user-to-IP mapping. DNS settings are tempting because they matter for DNS-based User-ID, where the firewall resolves source IPs to hostnames before mapping users.
- ✗
The user-id mapping timeout is set too low.
Why it's wrong here
A low mapping timeout only ages out existing entries sooner; it cannot stop new mappings from being written, so it does not explain missing cache entries. It is tempting because timeouts do govern cache freshness, and tuning them is correct when stale mappings persist after users log off.
- ✓
The User-ID agent is not configured with the correct domain credentials or domain name.
Why this is correct
Agent-based User-ID requires valid domain credentials and the correct domain name to query Active Directory and build user-to-IP mappings. Without them, the agent cannot resolve users even though network connectivity to the domain controllers exists.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.