QuestionQ13
Integration and AutomationAn organization uses Cloud Identity Engine (CIE) to collect user information from its on-premises Active Directory (AD) for employees and from a separate Azure AD for external partners. Because of compliance regulations, the firewalls protecting the internal network must not contain any identity information about external partners. Conversely, firewalls in the partner-facing DMZ must be aware only of partner identities.
Which CIE feature is intended to meet this data-partitioning requirement?
- A Panorama templates, which can be used to push different User-ID agent configurations to each firewall group
- B Segments, which can be configured to create distinct, filter-based views of users and groups that are then redistributed only to the appropriate firewalls
- C Multiple tenants, where a separate CIE tenant is required for each user directory to maintain isolation
- D Directory sync filtering, which is used at the source to prevent specific OUs from being imported into CIE
Community Discussion