
Palo Alto NetworksCertified Network Security Professional
Domain 1Objective 4
1.4 Explain the Application of Network Hardening Methods for Enhanced Security on Strata and SASE Products (e.g., Content-ID, Zero Trust, User-ID, Device-ID, Zones) NETWORK-SECURITY-PROFESSIONAL Practice Questions (Page 4)
Part of the Network Security Fundamentals domain, which accounts for 17% of the NETWORK-SECURITY-PROFESSIONAL exam.
27questions here
6free pages
7concepts
17%of the exam
Questions 16–20
- 16
A company is hardening its network for a Zero Trust architecture. They want to enforce access based on user identity, device posture, and content inspection. Which three features should be combined? (Select all that apply.)
Select an answer first - 17
How does the Zero Trust model enforce least-privilege access in Strata and SASE products?
Select an answer first - 18
A company has a Strata firewall with zones: untrust, dmz, and trust. They want to allow remote workers to access the DMZ via VPN, but also want to prevent the DMZ from being used as a pivot to the internal network. They also want to log all access to the DMZ. Which combination of features should be used?
Select an answer first - 19
A financial services firm uses Prisma Access for remote workers. They need to prevent data exfiltration by blocking uploads of sensitive documents to cloud storage, but only for users in the HR department. They also need to ensure that HR users can still access the cloud storage for legitimate business needs. Which combination of features should be used?
Select an answer first - 20
What is a security zone in the context of Strata and SASE products?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.