Free NETSEC-ARCHITECT Palo-Alto-Networks NETSEC-ARCHITECT Practice Test Question

Loading demo links...

Showing 1–3 of 3 questions

Question 1 (Topic 1)

A global organization has fully adopted Prisma Access to provide security for its mobile workforce and remote offices, and user identity is managed in Okta. The security team wants to create consistent Security policies that grant access to specific SaaS applications based on a users' departments, regardless of whether they work from home or a from branch office connected via an SD-WAN device Which architecture ensures that consistent user-to-group mapping is available to Prisma Access for policy enforcement in this use case?

Select an option, then click Submit answer.

  • Install the Palo Alto Networks User-ID agent and configure it to sync user information from Okta to Prisma Access
  • Deploy Panorama to manage Prisma Access and configure it to pull user and group information from Okta via the Cloud Identity Engine
  • Configure SAML federation between Prisma Access and Okta to provide user identity for every web request
  • Configure each remote office SD-WAN device and each user’s GlobalProtect client to query Okta directly for user information
Question 2 (Topic 1)

An organization plans to deploy a full SASE architecture consisting of Prisma SD-WAN IONs at branches and data centers alongside Prisma Access remote networks, service connections, and mobile users. The business office team requires that traffic from global remote offices to public cloud is of highest criticality, and this traffic should have the greatest service-level agreement (SLA) and QoS priority while still maintaining a balance of threat inspection. Which recommendation should the architect make to provide the lowest latency, highest throughput, and greatest resilience for the applications?

Select an option, then click Submit answer.

  • Prisma Access Agent or а РАС file explicit proxy configuration connecting the end user devices directly to Prisma Access with a service connection to the public cloud provider
  • Prisma Access remote networks with service connections directly to the cloud environment using IPSec and either static or dynamic routing
  • Prisma SD-WAN IONs deployed within the cloud environment using BGP-to-peer to the internal route tables of the application
  • Prisma SD-WAN ION deployed at both branch and private data center with a direct private link between the private data center and the public cloud provider
Question 3 (Topic 1)

Which custom component can mitigate the risk associated with an organization’s sales staff filling out a customer intake PDF form that contains corporate confidential information?

Select an option, then click Submit answer.

  • App-ID matching distinct components of the PDF applied using a security rule
  • Document type using trainable classifiers applied using a profile
  • Threat signature blocking the file based on a hash of the PDF
  • File blocking rule unique matching header or byte-code of the PDF