View all questions & answers for the Palo Alto Next-Generation Firewall Engineer Exam Materials exam
Palo Alto Next-Generation Firewall Engineer Exam Materials-Question 122 Discussion
Comments
Selected Answers: B
The requirement says faculty firewalls must not process or store any student directory data. Palo Alto Networks describes a CIE tenant as a secure container used to isolate directory information between departments or business units.
Selected Answers: D
- B — A second tenant technically isolates the data but is the least efficient option. It duplicates licensing, onboarding, certificate trust, and administrative overhead, and fragments identity management across two consoles — exactly what segments exist to avoid.
Why D: Segments are the Cloud Identity Engine's native mechanism for partitioning directory data. You define a segment scoped to the on-prem AD (faculty) source, and firewalls associated with that segment receive only that segment's user and group context. The student Google Workspace data is never redistributed to the faculty firewalls at all — it's filtered at the source in CIE, not at the consumer. That satisfies both requirements: the faculty firewalls neither process nor store student identity data, and it's a single configuration change rather than new infrastructure.
A university uses Cloud Identity Engine (CIE) to integrate identity information from a Google Workspace directory for students and an on-premises Active Directory (AD) for faculty. The firewalls securing the faculty network should not process or store any student identity data. What is the most efficient method to ensure the faculty firewalls receive only faculty user and group information from CIE? (Choose one answer)
Brave-Dump Clients Votes