
Palo Alto NetworksCertified Network Security Architect
Domain 3Objective 5
3.5 Recommend User Identification and Authentication Methods (e.g., Cloud Identity Engine, CAS for SAML) NETWORK-SECURITY-ARCHITECT Practice Questions (Page 4)
Part of the Centralized Management and IAM domain, which accounts for 13% of the NETWORK-SECURITY-ARCHITECT exam.
25questions here
5free pages
5concepts
13%of the exam
Questions 16–20
- 16
An enterprise has 50 firewalls deployed across multiple sites. They currently use User-ID agents at each site, but the security team finds it difficult to maintain consistent user mapping and policy enforcement. They want to centralize user identification management. What should the architect recommend to simplify operations?
Select an answer first - 17
Which authentication method is best suited for browser-based single sign-on to a Palo Alto Networks product using an external identity provider?
Select an answer first - 18
A company has a complex Active Directory environment with multiple domains and trusts. They are deploying Cloud Identity Engine for user identification. The architect notices that some users are not being mapped correctly because of duplicate usernames across domains. What should the architect configure in CIE to resolve this?
Select an answer first - 19
Which user identification method in a Palo Alto Networks environment relies on a client certificate presented during the TLS handshake to map a user to an identity?
Select an answer first - 20
Which authentication method is most appropriate when an organization needs to authenticate users against an existing RADIUS infrastructure for firewall administrative access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.