
Palo Alto NetworksCertified Network Security Architect
Domain 3Objective 6
3.6 Evaluate Cloud Identity Engine Use Cases NETWORK-SECURITY-ARCHITECT Practice Questions (Page 1)
Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.
12questions here
3free pages
3concepts
13%of the exam
Questions 1–5
- 1
A company has 4,000 remote users who connect via Prisma Access. They use Okta as their identity provider. The security team wants to enforce user-based policies for remote users. They also want to see which user is associated with each connection in the firewall logs. Which of the following are benefits of using Cloud Identity Engine in this scenario? (Select all that apply.)
Select an answer first - 2
What capability does Cloud Identity Engine add to Prisma SD-WAN?
Select an answer first - 3
What is a key benefit of using Cloud Identity Engine with Prisma Access?
Select an answer first - 4
How does Cloud Identity Engine enhance user identification for an NGFW beyond traditional methods?
Select an answer first - 5
A retail company has 50 branch offices connected via Prisma SD-WAN. Each branch has a local NGFW. The company uses Google Workspace as its identity provider. They want to segment branch network access based on user groups (e.g., finance, HR, guest) and enforce the same policies across all branches. They want to avoid configuring user mapping on each individual branch firewall. What is the most efficient way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.