Courseiva
Network SecuritymediumMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Network Security Practice Question

An administrator deploys User-ID using Palo Alto Networks User-ID Agent on a Windows Server. Users report that after logging off their workstations, the firewall continues to attribute their web traffic to them for up to 45 minutes. How can the administrator reduce this timeout duration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Modify the User-ID idle timeout and mapping aging timers in Device > User-ID > Edit settings.

User-ID aging timers control how long IP-to-user mappings remain active after receiving a logout event or idle timeout. These are configured under Device > User-ID > User-ID Agent or Server settings / Group Mapping Settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change the Security policy session timeout value to 5 minutes.

    Why it's wrong here

    Session timeouts close firewall sessions, but do not delete User-ID IP-to-user cache mappings.

  • Enable Captive Portal as a primary authentication fallback mechanism.

    Why it's wrong here

    Captive portal acts as an authentication trigger, not a mapping aging timer adjustment.

  • Increase the GlobalProtect portal idle disconnect timer.

    Why it's wrong here

    GlobalProtect timers affect VPN client sessions, not general User-ID AD agent mappings.

  • Modify the User-ID idle timeout and mapping aging timers in Device > User-ID > Edit settings.

    Why this is correct

    Adjusting aging timers ensures stale IP-to-user mappings are purged more quickly after logoff.

About these practice questions

One of 206 original Cybersecurity-Practitioner practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.