
Palo Alto NetworksCertified Network Security Architect
Domain 9Objective 2
9.2 Design for Maintenance and Security Across CSP Environments NETWORK-SECURITY-ARCHITECT Practice Questions (Page 1)
Part of the Public Cloud domain, which accounts for 11% of the NETWORK-SECURITY-ARCHITECT exam.
19questions here
4free pages
4concepts
11%of the exam
Questions 1–5
- 1
A company is deploying a decentralized firewall architecture in GCP, with firewalls in front of each application VPC. They need to implement SSL decryption to inspect outbound traffic from applications. What is the primary design consideration for SSL decryption in this architecture?
Select an answer first - 2
In a cloud deployment, where is a VPN gateway typically placed to terminate VPN tunnels?
Select an answer first - 3
What is a recommended best practice for executing an OS upgrade on a firewall in a cloud environment?
Select an answer first - 4
A company has a centralized firewall architecture in AWS with a pair of firewalls in an active/standby configuration. They need to upgrade the OS. The standby firewall is currently out of sync with the active firewall due to a previous configuration change. What is the most appropriate action before starting the upgrade?
Select an answer first - 5
A company is designing a multi-VPC architecture in AWS. They need to inspect traffic between VPCs and also terminate VPN connections from branch offices. They have a small security team and want to minimize management overhead. Which architecture is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.