Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Architect

Domain 3Objective 6

3.6 Evaluate Cloud Identity Engine Use Cases NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)

Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.

12questions here
3free pages
3concepts
13%of the exam

Questions 6–10

  1. 6application · medium

    A global company is rolling out a new zero-trust initiative. They have 2,000 remote employees who connect through Prisma Access, and they also have 500 on-premises users behind NGFWs. The company uses Okta as its identity provider and wants to enforce the same user-based application access policies for both remote and on-premises users. The security team wants to avoid maintaining separate user-to-IP mapping tables. Which approach should the architect take to meet these requirements?

    Select an answer first
  2. 7application · medium

    A company has 5,000 remote users who connect via Prisma Access. They use Microsoft Entra ID (Azure AD) as their identity provider. The security team wants to enforce different access policies for contractors versus full-time employees, and they need to see which user is associated with each connection in the firewall logs. They also want to avoid deploying any additional on-premises infrastructure. What should the architect configure?

    Select an answer first
  3. 8application · medium · select all that apply

    A company has NGFWs in their data center and branch offices connected via Prisma SD-WAN. They use Microsoft Entra ID as their identity provider. The security team wants to enforce user-based policies for both data center traffic and branch traffic. They also want to ensure that user group changes in Entra ID are reflected in policy enforcement quickly. Which of the following are benefits of using Cloud Identity Engine in this scenario? (Select all that apply.)

    Select an answer first
  4. 9application · medium

    An organization uses NGFWs in a data center and Prisma Access for remote users. They have recently migrated from Active Directory on-premises to Microsoft Entra ID (cloud-only). The security team wants to enforce user-based policies for both data center traffic and remote user traffic. They also want to reduce the administrative overhead of managing user mappings. What should the architect implement?

    Select an answer first
  5. 10foundation · easy

    How does Cloud Identity Engine support policy enforcement in a Prisma SD-WAN branch network?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.