BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCNSE Topic 7 Question 86 Discussion

Actual exam question for Palo Alto Networks's PCNSE exam
Question #: 86
Topic #: 7
[All PCNSE Questions]

What would allow a network security administrator to authenticate and identify a user with a new BYOD-type device that is not joined to the corporate domain?

Show Suggested Answer Hide Answer
Suggested Answer: A

For a network security administrator to authenticate and identify a user with a new BYOD-type device that is not joined to the corporate domain, the most effective method is to use an Authentication policy targeting users not yet identified by the system.

A) an Authentication policy with 'unknown' selected in the Source User field:

An Authentication policy allows the firewall to challenge unidentified users for credentials. By selecting 'unknown' in the Source User field, the policy targets users who have not yet been identified by the firewall, which would include users on new BYOD devices not joined to the domain.

Once the user provides valid credentials, the firewall can authenticate the user and map their identity to subsequent sessions, enabling the application of user-based policy rules and monitoring.

This approach ensures that new and unknown devices can be properly authenticated and identified without compromising security or requiring the device to be part of the corporate domain.


Contribute your Thoughts:

Arlette
5 months ago
True, a new device wouldn't be a known user yet.
upvoted 0 times
...
Penney
5 months ago
But it says it's a new device, so 'unknown' seems logical.
upvoted 0 times
...
Sonia
5 months ago
Could be B too, right? Known-user for authentication?
upvoted 0 times
...
Lavonna
5 months ago
I think A makes sense for new BYOD devices.
upvoted 0 times
...
Arlette
5 months ago
Yeah, the options are a bit confusing.
upvoted 0 times
...
Penney
6 months ago
I found this question quite tricky.
upvoted 0 times
...

Save Cancel