Palo Alto Networks NetSec-Pro Prisma Access Remote Users Networks And Private Apps Practice Test

 

This Palo Alto Networks Network Security Professional practice test focuses on prisma access remote users networks and private apps through original scenario-based questions aligned to the June 2026 NetSec-Pro blueprint. Use the full ExamSnap NetSec-Pro collection for broader practice across all current blueprint domains. For broader exam preparation, review the Palo Alto Networks NetSec-Pro Exam Dumps page.

Question 1

At Contoso Retail, the network security team needs to secure roaming users who need protected access from outside corporate sites. Which approach best meets the requirement?

  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy

Correct answer: E

Explanation

  1. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  2. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  3. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  4. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  5. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q001: Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy.

 

Question 2

Fabrikam Health is reviewing its Palo Alto Networks deployment. What should the administrator do to connect a branch or remote network to cloud-delivered security?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Use centralized management and shared policy constructs where the same security intent applies
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: D

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  2. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  3. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  4. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This directly satisfies one of the stated requirement(s).
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.

Learning point: NETSEC-T07-Q002: Configure the remote network connection to Prisma Access and apply the required routing and security policy.

 

Question 3

During a design review for Northwind Traders, the requirement is to allow users to reach a private application without exposing it directly to the public internet. Which choice is most appropriate?

  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy

Correct answer: D

Explanation

  1. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  2. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  4. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This directly satisfies one of the stated requirement(s).
  5. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.

Learning point: NETSEC-T07-Q003: Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy.

 

Question 4

A change request at Tailspin Energy states that the team must control internet-bound remote-user traffic by application. What is the best response?

  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: D

Explanation

  1. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  2. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  3. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  4. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This directly satisfies one of the stated requirement(s).
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.

Learning point: NETSEC-T07-Q004: Use centralized Prisma Access security policy with App-ID and relevant security profiles.

 

Question 5

An engineer at Woodgrove Bank is troubleshooting a configuration decision. Which action directly addresses the need to understand whether a remote-user issue is connectivity or policy related?

  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized management and shared policy constructs where the same security intent applies
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: B

Explanation

  1. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  2. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This directly satisfies one of the stated requirement(s).
  3. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  4. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.

Learning point: NETSEC-T07-Q005: Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes.

 

Question 6

Which option best supports the goal to translate traffic where a Prisma Access design requires NAT in Alpine Ski House’s Palo Alto Networks environment?

  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: E

Explanation

  1. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  2. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  4. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q006: Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation.

 

Question 7

A security review at Litware Manufacturing identifies a gap. The team wants to apply consistent policy to remote users and remote networks. Which action should it take?

  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use centralized management and shared policy constructs where the same security intent applies
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy

Correct answer: C

Explanation

  1. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  2. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  3. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This directly satisfies one of the stated requirement(s).
  4. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  5. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.

Learning point: NETSEC-T07-Q007: Use centralized management and shared policy constructs where the same security intent applies.

 

Question 8

While validating a deployment for Adventure Works, an architect must ensure the design can reduce exposure when granting access to sensitive internal applications. What should be done?

  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized management and shared policy constructs where the same security intent applies
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: C

Explanation

  1. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  2. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  3. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This directly satisfies one of the stated requirement(s).
  4. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.

Learning point: NETSEC-T07-Q008: Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation.

 

Question 9

City Power & Light has two related requirements: it must verify that a new Prisma Access deployment is auditable, and it must also connect a branch or remote network to cloud-delivered security. Which TWO actions best satisfy these requirements? Select two.

  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service

Correct answers: B, E

Explanation

  1. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable; connect a branch or remote network to cloud-delivered security.
  2. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This directly satisfies one of the stated requirement(s).
  3. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable; connect a branch or remote network to cloud-delivered security.
  4. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable; connect a branch or remote network to cloud-delivered security.
  5. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q009: Validate traffic and threat logging and confirm required logs reach the chosen logging/management service; Configure the remote network connection to Prisma Access and apply the required routing and security policy.

 

Question 10

Wingtip Logistics is reviewing its Palo Alto Networks deployment. What should the administrator do to choose Prisma Access rather than backhauling all remote traffic to a single data center?

  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations

Correct answer: E

Explanation

  1. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  2. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  3. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  4. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  5. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q010: Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations.

 

Question 11

During a design review for Blue Yonder Airlines, the requirement is to secure roaming users who need protected access from outside corporate sites. Which choice is most appropriate?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use centralized management and shared policy constructs where the same security intent applies
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  2. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  3. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This directly satisfies one of the stated requirement(s).
  4. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  5. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.

Learning point: NETSEC-T07-Q011: Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy.

 

Question 12

A change request at Fourth Coffee states that the team must connect a branch or remote network to cloud-delivered security. What is the best response?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  2. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  3. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This directly satisfies one of the stated requirement(s).
  4. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  5. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.

Learning point: NETSEC-T07-Q012: Configure the remote network connection to Prisma Access and apply the required routing and security policy.

 

Question 13

An engineer at City Power & Light is troubleshooting a configuration decision. Which action directly addresses the need to allow users to reach a private application without exposing it directly to the public internet?

  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy

Correct answer: E

Explanation

  1. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  2. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  3. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  4. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  5. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q013: Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy.

 

Question 14

Which option best supports the goal to control internet-bound remote-user traffic by application in Lucerne Publishing’s Palo Alto Networks environment?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use centralized management and shared policy constructs where the same security intent applies
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  2. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  3. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This directly satisfies one of the stated requirement(s).
  4. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  5. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.

Learning point: NETSEC-T07-Q014: Use centralized Prisma Access security policy with App-ID and relevant security profiles.

 

Question 15

A security review at A. Datum Research identifies a gap. The team wants to understand whether a remote-user issue is connectivity or policy related. Which action should it take?

  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes

Correct answer: E

Explanation

  1. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  2. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  4. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  5. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q015: Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes.

 

Question 16

While validating a deployment for Coho Winery, an architect must ensure the design can translate traffic where a Prisma Access design requires NAT. What should be done?

  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: E

Explanation

  1. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  2. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  3. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  4. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q016: Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation.

 

Question 17

At Trey Research, the network security team needs to apply consistent policy to remote users and remote networks. Which approach best meets the requirement?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized management and shared policy constructs where the same security intent applies
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  2. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  3. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This directly satisfies one of the stated requirement(s).
  4. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks.

Learning point: NETSEC-T07-Q017: Use centralized management and shared policy constructs where the same security intent applies.

 

Question 18

Tailspin Energy has two related requirements: it must reduce exposure when granting access to sensitive internal applications, and it must also allow users to reach a private application without exposing it directly to the public internet. Which TWO actions best satisfy these requirements? Select two.

  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Use centralized management and shared policy constructs where the same security intent applies
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation

Correct answers: A, E

Explanation

  1. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This directly satisfies one of the stated requirement(s).
  2. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications; allow users to reach a private application without exposing it directly to the public internet.
  3. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications; allow users to reach a private application without exposing it directly to the public internet.
  4. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications; allow users to reach a private application without exposing it directly to the public internet.
  5. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T07-Q018: Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation; Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy.

 

Question 19

During a design review for Contoso Retail, the requirement is to verify that a new Prisma Access deployment is auditable. Which choice is most appropriate?

  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy

Correct answer: B

Explanation

  1. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  2. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This directly satisfies one of the stated requirement(s).
  3. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  4. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  5. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.

Learning point: NETSEC-T07-Q019: Validate traffic and threat logging and confirm required logs reach the chosen logging/management service.

 

Question 20

A change request at Fabrikam Health states that the team must choose Prisma Access rather than backhauling all remote traffic to a single data center. What is the best response?

  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized management and shared policy constructs where the same security intent applies
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: D

Explanation

  1. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  2. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  3. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  4. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This directly satisfies one of the stated requirement(s).
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.

Learning point: NETSEC-T07-Q020: Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations.

 

Question 21

An engineer at Northwind Traders is troubleshooting a configuration decision. Which action directly addresses the need to secure roaming users who need protected access from outside corporate sites?

  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy

Correct answer: A

Explanation

  1. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This directly satisfies one of the stated requirement(s).
  2. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  4. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.
  5. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): secure roaming users who need protected access from outside corporate sites.

Learning point: NETSEC-T07-Q021: Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy.

 

Question 22

Which option best supports the goal to connect a branch or remote network to cloud-delivered security in Tailspin Energy’s Palo Alto Networks environment?

  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes

Correct answer: B

Explanation

  1. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  2. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This directly satisfies one of the stated requirement(s).
  3. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  4. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.
  5. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): connect a branch or remote network to cloud-delivered security.

Learning point: NETSEC-T07-Q022: Configure the remote network connection to Prisma Access and apply the required routing and security policy.

 

Question 23

A security review at Woodgrove Bank identifies a gap. The team wants to allow users to reach a private application without exposing it directly to the public internet. Which action should it take?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Use centralized management and shared policy constructs where the same security intent applies

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  2. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  3. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This directly satisfies one of the stated requirement(s).
  4. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.
  5. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): allow users to reach a private application without exposing it directly to the public internet.

Learning point: NETSEC-T07-Q023: Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy.

 

Question 24

While validating a deployment for Alpine Ski House, an architect must ensure the design can control internet-bound remote-user traffic by application. What should be done?

  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations

Correct answer: A

Explanation

  1. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This directly satisfies one of the stated requirement(s).
  2. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  4. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.
  5. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control internet-bound remote-user traffic by application.

Learning point: NETSEC-T07-Q024: Use centralized Prisma Access security policy with App-ID and relevant security profiles.

 

Question 25

At Litware Manufacturing, the network security team needs to understand whether a remote-user issue is connectivity or policy related. Which approach best meets the requirement?

  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation

Correct answer: B

Explanation

  1. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  2. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This directly satisfies one of the stated requirement(s).
  3. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  4. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.
  5. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): understand whether a remote-user issue is connectivity or policy related.

Learning point: NETSEC-T07-Q025: Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes.

 

Question 26

Adventure Works is reviewing its Palo Alto Networks deployment. What should the administrator do to translate traffic where a Prisma Access design requires NAT?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Use centralized management and shared policy constructs where the same security intent applies
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes

Correct answer: C

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  2. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  3. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This directly satisfies one of the stated requirement(s).
  4. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.
  5. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): translate traffic where a Prisma Access design requires NAT.

Learning point: NETSEC-T07-Q026: Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation.

 

Question 27

City Power & Light has two related requirements: it must apply consistent policy to remote users and remote networks, and it must also control internet-bound remote-user traffic by application. Which TWO actions best satisfy these requirements? Select two.

  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles
  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Use centralized management and shared policy constructs where the same security intent applies
  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy

Correct answers: B, D

Explanation

  1. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks; control internet-bound remote-user traffic by application.
  2. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This directly satisfies one of the stated requirement(s).
  3. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks; control internet-bound remote-user traffic by application.
  4. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This directly satisfies one of the stated requirement(s).
  5. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): apply consistent policy to remote users and remote networks; control internet-bound remote-user traffic by application.

Learning point: NETSEC-T07-Q027: Use centralized management and shared policy constructs where the same security intent applies; Use centralized Prisma Access security policy with App-ID and relevant security profiles.

 

Question 28

A change request at Wingtip Logistics states that the team must reduce exposure when granting access to sensitive internal applications. What is the best response?

  • Use the supported Prisma Access private-application connectivity design and restrict access by identity and policy
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Use centralized Prisma Access security policy with App-ID and relevant security profiles

Correct answer: B

Explanation

  1. Private application access should preserve private reachability while enforcing authenticated, least-privilege access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  2. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This directly satisfies one of the stated requirement(s).
  3. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  4. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.
  5. Prisma Access applies Palo Alto Networks application-aware security controls to remote-user traffic. This can be valid in another context, but it does not directly satisfy the stated requirement(s): reduce exposure when granting access to sensitive internal applications.

Learning point: NETSEC-T07-Q028: Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation.

 

Question 29

An engineer at Blue Yonder Airlines is troubleshooting a configuration decision. Which action directly addresses the need to verify that a new Prisma Access deployment is auditable?

  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure NAT policy in the supported Prisma Access management workflow instead of assuming security policy performs translation
  • Use Prisma Access monitoring and logs to check user connectivity, policy match, application, and session outcomes
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation
  • Use centralized management and shared policy constructs where the same security intent applies

Correct answer: A

Explanation

  1. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This directly satisfies one of the stated requirement(s).
  2. NAT and security policy are separate functions in Prisma Access just as they are on NGFWs. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  3. Operational telemetry distinguishes tunnel or connection problems from sessions that connect successfully but are denied or inspected by policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  4. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.
  5. A cloud-delivered security service is most effective when common controls are managed consistently across user and branch access. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify that a new Prisma Access deployment is auditable.

Learning point: NETSEC-T07-Q029: Validate traffic and threat logging and confirm required logs reach the chosen logging/management service.

 

Question 30

Which option best supports the goal to choose Prisma Access rather than backhauling all remote traffic to a single data center in Fourth Coffee’s Palo Alto Networks environment?

  • Use Prisma Access remote-user connectivity with the supported endpoint or access method and apply centralized security policy
  • Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations
  • Validate traffic and threat logging and confirm required logs reach the chosen logging/management service
  • Configure the remote network connection to Prisma Access and apply the required routing and security policy
  • Combine authenticated identity, least-privilege application policy, security inspection, and appropriate network segmentation

Correct answer: B

Explanation

  1. Prisma Access extends security policy and inspection to mobile and remote users without requiring traffic to terminate on an on-premises firewall. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  2. Prisma Access is designed to deliver security services from the cloud and can reduce dependence on centralized backhaul architectures. This directly satisfies one of the stated requirement(s).
  3. Monitoring and logging are core Prisma Access functions and must be available for operations and investigation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  4. Prisma Access remote networks bring branch traffic to the cloud security service for policy enforcement. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.
  5. Private connectivity alone does not provide least privilege; identity and security policy still determine what users may do. This can be valid in another context, but it does not directly satisfy the stated requirement(s): choose Prisma Access rather than backhauling all remote traffic to a single data center.

Learning point: NETSEC-T07-Q030: Use cloud-delivered enforcement when distributed users and branches need scalable security closer to their access locations.

Popular posts

img