Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Architect

Domain 1Objective 1

1.1 Design User-ID and Device Health, Host Information Profile (HIP) and Security Posture, and Device-IDbased Least Privilege Access Security Policy Controls NETWORK-SECURITY-ARCHITECT Practice Questions (Page 1)

Part of the Zero Trust Enterprise domain, which accounts for 8% of the NETWORK-SECURITY-ARCHITECT exam.

16questions here
4free pages
5concepts
8%of the exam

Questions 1–5

  1. 1foundation · easy

    Which policy type uses HIP profiles to enforce device compliance?

    Select an answer first
  2. 2foundation · easy

    A network security architect is designing a user-based security policy. Which User-ID integration method enables the firewall to map IP addresses to usernames by monitoring authentication traffic?

    Select an answer first
  3. 3foundation · easy

    Which method can be used to identify a device for Device-ID?

    Select an answer first
  4. 4application · medium

    An organization requires that all managed Windows laptops have disk encryption (BitLocker) enabled and the latest antivirus definitions installed before they can access the internal file server. They use GlobalProtect for remote access. Which configuration will enforce this requirement?

    Select an answer first
  5. 5foundation · easy

    Which combination of features enables a security policy to enforce least privilege by requiring both user identity and device compliance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.