Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Architect

Domain 1Objective 1

1.1 Design User-ID and Device Health, Host Information Profile (HIP) and Security Posture, and Device-IDbased Least Privilege Access Security Policy Controls NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)

Part of the Zero Trust Enterprise domain, which accounts for 8% of the NETWORK-SECURITY-ARCHITECT exam.

16questions here
4free pages
5concepts
8%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the primary purpose of a Host Information Profile (HIP) check in a Palo Alto Networks security architecture?

    Select an answer first
  2. 7foundation · easy

    In a HIP-based security policy, what action can be taken when a device fails a HIP check?

    Select an answer first
  3. 8application · medium

    A company has a remote workforce that connects via GlobalProtect. They want to enforce a policy that only allows access to the corporate network if the user's device has the latest OS patches. They have configured HIP checks. What is the most effective way to enforce this policy?

    Select an answer first
  4. 9foundation · easy

    Which component is required on an endpoint for the Palo Alto Networks firewall to receive Host Information Profile (HIP) data?

    Select an answer first
  5. 10expert · hard

    A financial services firm requires that access to its customer database (CRM) be granted only to users in the 'Finance' AD group, from a corporate-managed device, and only if the device has the latest patch level and disk encryption enabled. They are using GlobalProtect and have User-ID, Device-ID, and HIP configured. How should the security policy rule be structured to enforce this least-privilege requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.