
Palo Alto NetworksCertified Network Security Architect
Domain 3Objective 5
3.5 Recommend User Identification and Authentication Methods (e.g., Cloud Identity Engine, CAS for SAML) NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)
Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.
25questions here
5free pages
5concepts
13%of the exam
Questions 6–10
- 6
Which authentication method would be most appropriate for a small organization with no existing directory service that needs a simple solution for firewall administrative access?
Select an answer first - 7
A company is deploying Cloud Identity Engine (CIE) for user identification. They have a large number of users and are concerned about the accuracy of user-to-IP mapping, especially for users who roam across subnets. The architect needs to ensure the most accurate mapping possible. What should be recommended?
Select an answer first - 8
Which benefit does the Cloud Identity Engine (CIE) provide over traditional on-premises User-ID agents?
Select an answer first - 9
A company wants to authenticate firewall administrators using their corporate Microsoft Entra ID (Azure AD) with SAML single sign-on. They have a mix of firewall models, including some older models that do not support direct SAML integration. What should the architect recommend to provide consistent SSO across all firewalls?
Select an answer first - 10
Which user identification method in a Palo Alto Networks environment typically uses the User-ID agent to collect username-to-IP mappings from Active Directory?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.