Palo Alto Networks NetSec-Pro Content-ID Zero Trust User-ID Device-ID And Zones Practice Test

 

This Palo Alto Networks Network Security Professional practice test focuses on content-id zero trust user-id device-id and zones through original scenario-based questions aligned to the June 2026 NetSec-Pro blueprint. Use the full ExamSnap NetSec-Pro collection for broader practice across all current blueprint domains. For broader exam preparation, review the Palo Alto Networks NetSec-Pro Exam Dumps page.

Question 1

Which option best supports the goal to reduce lateral movement between network segments in Tailspin Energy’s Palo Alto Networks environment?

  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Use User-ID to map network activity to users and groups and reference those identities in policy

Correct answer: D

Explanation

  1. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  2. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  3. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  4. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This directly satisfies one of the stated requirement(s).
  5. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.

Learning point: NETSEC-T04-Q001: Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries.

 

Question 2

A security review at Woodgrove Bank identifies a gap. The team wants to write policy based on authenticated user identity instead of only source IP addresses. Which action should it take?

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions

Correct answer: B

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  2. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This directly satisfies one of the stated requirement(s).
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  4. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  5. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.

Learning point: NETSEC-T04-Q002: Use User-ID to map network activity to users and groups and reference those identities in policy.

 

Question 3

While validating a deployment for Alpine Ski House, an architect must ensure the design can differentiate managed and unmanaged endpoints in access decisions. What should be done?

  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources

Correct answer: C

Explanation

  1. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  2. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  3. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This directly satisfies one of the stated requirement(s).
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  5. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.

Learning point: NETSEC-T04-Q003: Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions.

 

Question 4

At Litware Manufacturing, the network security team needs to inspect allowed traffic for threats and sensitive content. Which approach best meets the requirement?

  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions

Correct answer: E

Explanation

  1. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  2. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  3. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  4. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  5. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T04-Q004: Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions.

 

Question 5

Adventure Works is reviewing its Palo Alto Networks deployment. What should the administrator do to apply a Zero Trust approach to an internal application?

  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Use User-ID to map network activity to users and groups and reference those identities in policy

Correct answer: C

Explanation

  1. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This directly satisfies one of the stated requirement(s).
  4. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  5. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.

Learning point: NETSEC-T04-Q005: Verify identity and device context, grant only the minimum application access required, and continuously inspect the session.

 

Question 6

During a design review for Proseware Services, the requirement is to keep administrative interfaces from being exposed to broad user networks. Which choice is most appropriate?

  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Combine User-ID with Device-ID or device context rather than relying on username alone

Correct answer: C

Explanation

  1. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  3. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This directly satisfies one of the stated requirement(s).
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  5. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.

Learning point: NETSEC-T04-Q006: Restrict management access to dedicated trusted networks and tightly scoped administrator sources.

 

Question 7

A change request at Wingtip Logistics states that the team must harden a rule that currently permits any application and any service between sensitive zones. What is the best response?

  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries

Correct answer: D

Explanation

  1. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  2. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  3. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This directly satisfies one of the stated requirement(s).
  5. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.

Learning point: NETSEC-T04-Q007: Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles.

 

Question 8

An engineer at Blue Yonder Airlines is troubleshooting a configuration decision. Which action directly addresses the need to enforce different access for the same user when connecting from a risky device?

  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions

Correct answer: D

Explanation

  1. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  2. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  3. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  4. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This directly satisfies one of the stated requirement(s).
  5. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.

Learning point: NETSEC-T04-Q008: Combine User-ID with Device-ID or device context rather than relying on username alone.

 

Question 9

Tailspin Energy has two related requirements: it must prevent an IoT device subnet from becoming a general-purpose trusted network, and it must also write policy based on authenticated user identity instead of only source IP addresses. Which TWO actions best satisfy these requirements? Select two.

  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries

Correct answers: B, C

Explanation

  1. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network; write policy based on authenticated user identity instead of only source IP addresses.
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This directly satisfies one of the stated requirement(s).
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This directly satisfies one of the stated requirement(s).
  4. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network; write policy based on authenticated user identity instead of only source IP addresses.
  5. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network; write policy based on authenticated user identity instead of only source IP addresses.

Learning point: NETSEC-T04-Q009: Place the devices in a dedicated zone and permit only required application flows to approved destinations; Use User-ID to map network activity to users and groups and reference those identities in policy.

 

Question 10

A security review at City Power & Light identifies a gap. The team wants to validate that security controls still match intended trust boundaries after changes. Which action should it take?

  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Combine User-ID with Device-ID or device context rather than relying on username alone

Correct answer: A

Explanation

  1. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This directly satisfies one of the stated requirement(s).
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  4. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  5. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.

Learning point: NETSEC-T04-Q010: Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation.

 

Question 11

While validating a deployment for Lucerne Publishing, an architect must ensure the design can reduce lateral movement between network segments. What should be done?

  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session

Correct answer: C

Explanation

  1. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  3. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This directly satisfies one of the stated requirement(s).
  4. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  5. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.

Learning point: NETSEC-T04-Q011: Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries.

 

Question 12

At A. Datum Research, the network security team needs to write policy based on authenticated user identity instead of only source IP addresses. Which approach best meets the requirement?

  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Combine User-ID with Device-ID or device context rather than relying on username alone

Correct answer: C

Explanation

  1. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This directly satisfies one of the stated requirement(s).
  4. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  5. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.

Learning point: NETSEC-T04-Q012: Use User-ID to map network activity to users and groups and reference those identities in policy.

 

Question 13

Coho Winery is reviewing its Palo Alto Networks deployment. What should the administrator do to differentiate managed and unmanaged endpoints in access decisions?

  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations

Correct answer: C

Explanation

  1. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  2. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  3. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This directly satisfies one of the stated requirement(s).
  4. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  5. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.

Learning point: NETSEC-T04-Q013: Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions.

 

Question 14

During a design review for Trey Research, the requirement is to inspect allowed traffic for threats and sensitive content. Which choice is most appropriate?

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Use User-ID to map network activity to users and groups and reference those identities in policy

Correct answer: B

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This directly satisfies one of the stated requirement(s).
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  4. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  5. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.

Learning point: NETSEC-T04-Q014: Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions.

 

Question 15

A change request at Wide World Importers states that the team must apply a Zero Trust approach to an internal application. What is the best response?

  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations

Correct answer: C

Explanation

  1. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  2. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This directly satisfies one of the stated requirement(s).
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  5. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.

Learning point: NETSEC-T04-Q015: Verify identity and device context, grant only the minimum application access required, and continuously inspect the session.

 

Question 16

An engineer at Contoso Retail is troubleshooting a configuration decision. Which action directly addresses the need to keep administrative interfaces from being exposed to broad user networks?

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries

Correct answer: A

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This directly satisfies one of the stated requirement(s).
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  3. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  4. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  5. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.

Learning point: NETSEC-T04-Q016: Restrict management access to dedicated trusted networks and tightly scoped administrator sources.

 

Question 17

Which option best supports the goal to harden a rule that currently permits any application and any service between sensitive zones in Fabrikam Health’s Palo Alto Networks environment?

  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions

Correct answer: A

Explanation

  1. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This directly satisfies one of the stated requirement(s).
  2. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  3. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  4. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.
  5. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones.

Learning point: NETSEC-T04-Q017: Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles.

 

Question 18

City Power & Light has two related requirements: it must enforce different access for the same user when connecting from a risky device, and it must also differentiate managed and unmanaged endpoints in access decisions. Which TWO actions best satisfy these requirements? Select two.

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session

Correct answers: C, D

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device; differentiate managed and unmanaged endpoints in access decisions.
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device; differentiate managed and unmanaged endpoints in access decisions.
  3. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This directly satisfies one of the stated requirement(s).
  4. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This directly satisfies one of the stated requirement(s).
  5. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device; differentiate managed and unmanaged endpoints in access decisions.

Learning point: NETSEC-T04-Q018: Combine User-ID with Device-ID or device context rather than relying on username alone; Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions.

 

Question 19

While validating a deployment for Tailspin Energy, an architect must ensure the design can prevent an IoT device subnet from becoming a general-purpose trusted network. What should be done?

  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries

Correct answer: B

Explanation

  1. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  2. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This directly satisfies one of the stated requirement(s).
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  4. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  5. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.

Learning point: NETSEC-T04-Q019: Place the devices in a dedicated zone and permit only required application flows to approved destinations.

 

Question 20

At Woodgrove Bank, the network security team needs to validate that security controls still match intended trust boundaries after changes. Which approach best meets the requirement?

  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use User-ID to map network activity to users and groups and reference those identities in policy

Correct answer: A

Explanation

  1. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This directly satisfies one of the stated requirement(s).
  2. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  4. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  5. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.

Learning point: NETSEC-T04-Q020: Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation.

 

Question 21

Alpine Ski House is reviewing its Palo Alto Networks deployment. What should the administrator do to reduce lateral movement between network segments?

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations

Correct answer: D

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  2. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  3. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.
  4. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This directly satisfies one of the stated requirement(s).
  5. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce lateral movement between network segments.

Learning point: NETSEC-T04-Q021: Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries.

 

Question 22

During a design review for Litware Manufacturing, the requirement is to write policy based on authenticated user identity instead of only source IP addresses. Which choice is most appropriate?

  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation

Correct answer: D

Explanation

  1. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  2. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  3. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.
  4. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This directly satisfies one of the stated requirement(s).
  5. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): write policy based on authenticated user identity instead of only source IP addresses.

Learning point: NETSEC-T04-Q022: Use User-ID to map network activity to users and groups and reference those identities in policy.

 

Question 23

A change request at Adventure Works states that the team must differentiate managed and unmanaged endpoints in access decisions. What is the best response?

  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session

Correct answer: A

Explanation

  1. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This directly satisfies one of the stated requirement(s).
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  4. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.
  5. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): differentiate managed and unmanaged endpoints in access decisions.

Learning point: NETSEC-T04-Q023: Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions.

 

Question 24

An engineer at Proseware Services is troubleshooting a configuration decision. Which action directly addresses the need to inspect allowed traffic for threats and sensitive content?

  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources

Correct answer: C

Explanation

  1. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  2. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  3. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This directly satisfies one of the stated requirement(s).
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.
  5. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): inspect allowed traffic for threats and sensitive content.

Learning point: NETSEC-T04-Q024: Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions.

 

Question 25

Which option best supports the goal to apply a Zero Trust approach to an internal application in Wingtip Logistics’s Palo Alto Networks environment?

  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation

Correct answer: B

Explanation

  1. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  2. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This directly satisfies one of the stated requirement(s).
  3. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  4. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.
  5. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply a Zero Trust approach to an internal application.

Learning point: NETSEC-T04-Q025: Verify identity and device context, grant only the minimum application access required, and continuously inspect the session.

 

Question 26

A security review at Blue Yonder Airlines identifies a gap. The team wants to keep administrative interfaces from being exposed to broad user networks. Which action should it take?

  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Use User-ID to map network activity to users and groups and reference those identities in policy

Correct answer: A

Explanation

  1. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This directly satisfies one of the stated requirement(s).
  2. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  3. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  4. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.
  5. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): keep administrative interfaces from being exposed to broad user networks.

Learning point: NETSEC-T04-Q026: Restrict management access to dedicated trusted networks and tightly scoped administrator sources.

 

Question 27

Tailspin Energy has two related requirements: it must harden a rule that currently permits any application and any service between sensitive zones, and it must also inspect allowed traffic for threats and sensitive content. Which TWO actions best satisfy these requirements? Select two.

  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations
  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation

Correct answers: B, D

Explanation

  1. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones; inspect allowed traffic for threats and sensitive content.
  2. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This directly satisfies one of the stated requirement(s).
  3. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones; inspect allowed traffic for threats and sensitive content.
  4. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This directly satisfies one of the stated requirement(s).
  5. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): harden a rule that currently permits any application and any service between sensitive zones; inspect allowed traffic for threats and sensitive content.

Learning point: NETSEC-T04-Q027: Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles; Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions.

 

Question 28

At City Power & Light, the network security team needs to enforce different access for the same user when connecting from a risky device. Which approach best meets the requirement?

  • Use security zones and least-privilege interzone policy so only explicitly required traffic can cross trust boundaries
  • Combine User-ID with Device-ID or device context rather than relying on username alone
  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations

Correct answer: B

Explanation

  1. Zone segmentation creates enforceable boundaries and limits the reach of a compromised host. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  2. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This directly satisfies one of the stated requirement(s).
  3. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  4. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.
  5. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce different access for the same user when connecting from a risky device.

Learning point: NETSEC-T04-Q028: Combine User-ID with Device-ID or device context rather than relying on username alone.

 

Question 29

Lucerne Publishing is reviewing its Palo Alto Networks deployment. What should the administrator do to prevent an IoT device subnet from becoming a general-purpose trusted network?

  • Use User-ID to map network activity to users and groups and reference those identities in policy
  • Use Device-ID or device context to identify endpoint characteristics and include them in policy decisions
  • Attach appropriate Security Profiles or profile groups so Content-ID technologies examine permitted sessions
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Place the devices in a dedicated zone and permit only required application flows to approved destinations

Correct answer: E

Explanation

  1. User-ID lets policy follow people and groups rather than relying solely on IP addresses that can change or be shared. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  2. Device identity adds endpoint context so access can reflect device type or management posture as well as user and network location. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  3. Allowing a session should not end security inspection; Content-ID based services analyze permitted traffic for malicious or risky content. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  4. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prevent an IoT device subnet from becoming a general-purpose trusted network.
  5. Dedicated segmentation plus explicit application policy limits the effect of device compromise. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T04-Q029: Place the devices in a dedicated zone and permit only required application flows to approved destinations.

 

Question 30

During a design review for A. Datum Research, the requirement is to validate that security controls still match intended trust boundaries after changes. Which choice is most appropriate?

  • Replace the broad rule with application-specific, least-privilege access and attach relevant threat-prevention profiles
  • Restrict management access to dedicated trusted networks and tightly scoped administrator sources
  • Verify identity and device context, grant only the minimum application access required, and continuously inspect the session
  • Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation
  • Combine User-ID with Device-ID or device context rather than relying on username alone

Correct answer: D

Explanation

  1. Narrowing applications and services while retaining content inspection substantially reduces unnecessary attack surface. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  2. Separating and restricting management access reduces opportunities to attack privileged control interfaces. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  3. Zero Trust treats access as explicit, contextual, and least-privilege rather than automatically trusting users or devices because they are internal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.
  4. Hardening depends on the combined policy context; configuration drift in any of these controls can weaken the intended boundary. This directly satisfies one of the stated requirement(s).
  5. User identity and device identity answer different trust questions and can be combined for more adaptive policy decisions. This can be valid in another context, but it does not directly satisfy the stated requirement(s): validate that security controls still match intended trust boundaries after changes.

Learning point: NETSEC-T04-Q030: Review zone assignments, identity mappings, device context, and attached security profiles as part of change validation.

Popular posts

img