
Palo Alto NetworksCertified Network Security Professional
Domain 1Objective 4
1.4 Explain the Application of Network Hardening Methods for Enhanced Security on Strata and SASE Products (e.g., Content-ID, Zero Trust, User-ID, Device-ID, Zones) NETWORK-SECURITY-PROFESSIONAL Practice Questions (Page 5)
Part of the Network Security Fundamentals domain, which accounts for 17% of the NETWORK-SECURITY-PROFESSIONAL exam.
27questions here
6free pages
7concepts
17%of the exam
Questions 21–25
- 21
A healthcare provider is implementing a Zero Trust architecture for remote access to patient records. They need to enforce least-privilege access based on user role, device compliance, and network location. Which two features are essential to enforce these requirements? (Select all that apply.)
Select an answer first - 22
A company wants to isolate its guest Wi-Fi network from the internal corporate network to prevent lateral movement. They are using a Strata firewall. What is the most effective way to achieve this?
Select an answer first - 23
A company uses Prisma Access to secure remote workers. They want to prevent sensitive files from being uploaded to a public file-sharing site, but only for users in the Finance group. Which two features must be combined to achieve this?
Select an answer first - 24
Which of the following is an example of a device attribute that Device-ID can use to identify a device?
Select an answer first - 25
A company is moving to a Zero Trust model. They currently have a flat network with no segmentation. They want to implement micro-segmentation to limit lateral movement. Which approach is most aligned with Zero Trust principles?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.