Palo Alto Networks NetSec-Architect - Palo Alto Networks Network Security Architect Exam

Question #11 (Topic: Exam A)
The network security architect leading a Zero Trust migration has successfully completed identifying and classifying all mission-critical Data, Applications, Assets, and Services (DAAS). The architect must now gather the necessary data to inform the technical design of the micro-perimeters and the placement of the VM-Series virtual firewalls in Azure.
According to the Palo Alto Networks Zero Trust implementation methodology, what is the mandatory next step to gather the necessary data for designing the segmentation and the placement of security controls?
A. Identify the five essential components to be validated B. Create the Zero Trust policy using the Kipling Method C. Map the transaction flows to and from the protect surface D. Monitor and maintain the network by inspecting and logging all traffic flows
Answer: C
Question #12 (Topic: Exam A)
Which custom component can mitigate the risk associated with an organization’s sales staff filling out a customer intake PDF form that contains corporate confidential information?
A. App-ID matching distinct components of the PDF applied using a security rule B. Document type using trainable classifiers applied using a profile C. Threat signature blocking the file based on a hash of the PDF D. File blocking rule unique matching header or byte-code of the PDF
Answer: B
Question #13 (Topic: Exam A)
A large organization is building a hybrid AI environment. The plan is to develop proprietary machine learning (ML) models on-premises in a VMware NSX environment and create separate, cloud-native AI applications in a Google Kubernetes Engine (GKE) cluster environment. The CISO has requested a single solution that can offer runtime protection and visibility for the two environments.
Which Prisma AIRS component or form factor should a security architect recommend to this customer?
A. AI Agent Security installed on each individual virtual machine (VM) and container across both environments to provide host-level protection B. Prisma AIRS Network Intercept deployed as security virtual appliances in both environments C. Prisma AIRS SaaS platform to ingest telemetry from both environments without requiring local enforcement points D. AI Security Posture Management (AI-SPM) scanner to connect to both on-premises and cloud environments to scan for misconfigurations
Answer: B
Question #14 (Topic: Exam A)
An organization is designing the Prisma Access service connections for its data centers. Each data center has 10 Gb redundant links to the internet. Each data center will need to support a minimum of 1.5 Gbps of throughput from Prisma Access connected users and branches.
Which diagram depicts a solution that meets the requirements of this use case?
A. B. C. D.
Answer: B
Question #15 (Topic: Exam A)
An organization with offices throughout the world has an SD-WAN solution in which all traffic is backhauled to a central set of data centers. Many of the offices have IoT / OT devices.
Which IoT Security requirement must be taken into consideration by the security architect when determining which Zero Trust network solution will help this organization evolve its security architecture?
A. Either a Prisma SD-WAN ION or an NGFW device must be present for accurate IoT / ОТ detection. B. A local sensor must be deployed as either an agent on the DHCP server or as a container on the virtual infrastructure. C. All DHCP requests must traverse the Prisma SD-WAN fabric for IoT / ОТ detection. D. The organization must have local NGFW for enforcement.
Answer: A
Download Exam
Page: 3 / 9
Total 45 questions