
Palo Alto NetworksCertified Network Security Architect
Domain 1Objective 3
1.3 Differentiate Access to Specific Applications NETWORK-SECURITY-ARCHITECT Practice Questions (Page 1)
Part of the Zero Trust Enterprise domain, which accounts for 8% of the NETWORK-SECURITY-ARCHITECT exam.
15questions here
3free pages
5concepts
8%of the exam
Questions 1–5
- 1
An organization is replacing a legacy firewall that uses IP-based rules with a Palo Alto Networks firewall. The security team wants to ensure that access to a legacy mainframe application is controlled by the application itself, not by the IP address of the mainframe. The application is not currently identified by App-ID. What is the first step the team should take?
Select an answer first - 2
A security architect is designing access control for a new cloud-based project management tool. The Zero Trust principle of least privilege must be applied. Users in the 'Project Managers' group need full access, while 'Team Members' should only have read-only access. The firewall can identify the application and integrate with the identity provider. What is the most appropriate policy design?
Select an answer first - 3
What is the primary purpose of using user and group-based access control for applications?
Select an answer first - 4
What is a key benefit of tailoring access policies to specific applications rather than to broad network segments?
Select an answer first - 5
In a Zero Trust architecture, how does application-specific access control differ from traditional network-segment-based access control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.