Courseiva
Zero Trust Architecture And DesignmediumMultiple ChoiceObjective-mapped

NetSec-Architect Zero Trust Architecture And Design Practice Question

An architect is designing an identity management architecture at scale for a global enterprise utilizing Palo Alto Networks firewalls. The design must map users across multiple disjointed Active Directory forests. Which Palo Alto Networks feature enables seamless aggregation of user-to-IP mappings from multiple disparate forests into a unified policy enforcement framework?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring multiple User-ID agent connections or Panorama-managed User-ID sources mapped across all distinct AD forests with proper domain mapping

PAN-OS User-ID supports multiple User-ID agents, Panorama log forwarding, and multi-forest Active Directory polling configured via Panorama or local firewalls to aggregate mappings into a unified cache.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enforcing static local user accounts on every firewall CLI

    Why it's wrong here

    Incorrect. Local accounts do not scale for global enterprise AD environments.

  • Configuring multiple User-ID agent connections or Panorama-managed User-ID sources mapped across all distinct AD forests with proper domain mapping

    Why this is correct

    Correct. Multiple agent or server monitor connections allow aggregation of identities across disparate domains and forests.

  • Writing custom Python scripts on every firewall to scrape NetBIOS cache every 5 seconds

    Why it's wrong here

    Incorrect. NetBIOS scraping is legacy, unscalable, and insecure.

  • A single static User-ID agent pointing only to the primary domain controller of the root domain

    Why it's wrong here

    Incorrect. This fails to map users residing in secondary or trusting/trusted separate forests.

About these practice questions

This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.