問題文
Why does PAN-OS let an organization define custom admin roles instead of only using the built-in dynamic roles?
選択肢
- So that each administrator sees only the parts of the configuration and the monitoring data that their job requires, rather than a fixed bundle of privileges.
- So that privileges can be granted from the directory group the administrator belongs to, which removes the need to define an authentication profile.
- So that the firewall can keep a separate configuration per administrator, and each of them can commit changes independently of the others.
- So that administrators can log in without any authentication profile, because the role itself carries the credentials that the firewall checks.