
Palo Alto NetworksCertified Network Security Architect
Domain 9Objective 2
9.2 Design for Maintenance and Security Across CSP Environments NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)
Part of the Public Cloud domain, which accounts for 11% of the NETWORK-SECURITY-ARCHITECT exam.
19questions here
4free pages
4concepts
11%of the exam
Questions 6–10
- 6
Which implementation approach is commonly used for SSL decryption in a cloud environment?
Select an answer first - 7
What is a primary advantage of a centralized firewall architecture in a cloud environment?
Select an answer first - 8
A company is deploying a centralized firewall in AWS to inspect traffic from multiple VPCs. They want to enable SSL decryption for outbound traffic. They are concerned about the performance impact of decryption on the firewall. What is the most effective way to mitigate this performance concern?
Select an answer first - 9
A company is deploying a centralized firewall architecture in Azure to inspect traffic for multiple spoke VNets. They need to terminate site-to-site VPN connections from branch offices. Where should the VPN gateway be placed to ensure all branch traffic is inspected by the firewall?
Select an answer first - 10
A company is deploying a decentralized firewall architecture in GCP. Each application team manages its own firewall. What is a significant security challenge with this approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.