
Palo Alto NetworksCertified Network Security Architect
Domain 3Objective 3
3.3 Recommend Cloud Identity Engine Directory Sync Options NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)
Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.
31questions here
7free pages
8concepts
13%of the exam
Questions 6–10
- 6
Which type of credential is commonly used to authenticate Cloud Identity Engine to Okta for directory sync?
Select an answer first - 7
A company has both Microsoft Entra ID and Okta tenants. They want to use Cloud Identity Engine to provide user identity to their firewalls. The architect needs to decide which directory to sync. What is the primary consideration when choosing between Entra ID and Okta as the sync source?
Select an answer first - 8
A security administrator notices that user and group changes made in on-premises Active Directory are not appearing in Cloud Identity Engine within the expected time frame. The on-premises agent is running and shows a healthy status. What is the most likely cause of the delay?
Select an answer first - 9
Where is the on-premises agent for Cloud Identity Engine typically deployed?
Select an answer first - 10
What is required to sync a directory from Microsoft Entra ID (Azure AD) to Cloud Identity Engine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.