
Palo Alto NetworksCertified Network Security Architect
Domain 3Objective 3
3.3 Recommend Cloud Identity Engine Directory Sync Options NETWORK-SECURITY-ARCHITECT Practice Questions (Page 3)
Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.
31questions here
7free pages
8concepts
13%of the exam
Questions 11–15
- 11
A company has two identity sources: an on-premises Active Directory for all employees and a Microsoft Entra ID tenant that contains only guest users from partner organizations. The firewall policy must enforce different access rules for employees and guests. The architect wants to use Cloud Identity Engine to provide both user sets to the firewalls. What is the most appropriate sync strategy?
Select an answer first - 12
A company uses a SAML 2.0 identity provider that is not natively supported by Cloud Identity Engine. They want to use user-ID-based policies on their firewalls. The architect is evaluating whether to use SAML 2.0 or to deploy the on-premises agent with an LDAP proxy. What is the key advantage of using SAML 2.0 in this scenario?
Select an answer first - 13
An administrator is deploying the on-premises agent for Cloud Identity Engine in an environment where the Active Directory schema has been extended with custom attributes. The security team wants these custom attributes to be available for user mapping in firewall policies. What must the administrator do to make these attributes available?
Select an answer first - 14
What is required to sync a directory from Okta to Cloud Identity Engine?
Select an answer first - 15
A multinational company is deploying Cloud Identity Engine to enable user-ID-based policies across firewalls in three regions. Their user identities are authoritative in an on-premises Active Directory forest that has no internet connectivity from domain controllers. They also have a separate Microsoft Entra ID tenant used only for Microsoft 365, which contains a subset of the same users. The security team wants identity data for all users, including those not in Microsoft 365, available in Cloud Identity Engine with minimal administrative overhead. Which approach should the architect recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.