Palo Alto Networks NGFW Engineer — Question 22

A multinational organization wants to use the Cloud Identity Engine (CIE) to aggregate identity data from multiple sources (on premises AD, Azure AD, Okta) while enforcing strict data isolation for different regional business units. Each region’s firewalls, managed via Panorama, must only receive the user and group information relevant to that region. The organization aims to minimize administrative overhead while meeting data sovereignty requirements.
Which approach achieves this segmentation of identity data?

Answer options

Correct answer: B

Explanation

The correct answer is B because establishing separate CIE tenants for each business unit allows for tailored integration with relevant identity sources, ensuring that only the necessary user and group data is available to each region's firewall. Options A and D fail to enforce strict data isolation, as they would either share all data across all firewalls or rely on filtering within a single tenant. Option C does not fulfill the requirement of data aggregation from multiple sources.