Palo Alto Networks NGFW Engineer — Question 34
What must be configured before a firewall administrator can define policy rules based on users and groups?
Answer options
- A. User Mapping profile
- B. Authentication profile
- C. Group mapping settings
- D. LDAP Server profile
Correct answer: D
Explanation
The correct answer is D, as the LDAP Server profile is essential for the firewall to authenticate users and retrieve group information. Without this configuration, the firewall cannot accurately apply policy rules based on user identities and their associated groups. The other options, while relevant, do not directly enable the necessary user and group identification for policy rules.