10 free sample questions from a bank of 45, with the correct answers and explanations. No signup required — start practising right now.
1A technology company is deploying its own AI applications on a Google Kubernetes Engine (GKE) cluster. The development team is concerned about protecting the complex, microservices-based AI stack from both internal and external threats: such as data poisoning and lateral movement between containerized components. Which solution should be proposed to address these concerns?
AI Access Security with Advanced URL Filtering
AI Access Security with App-ID Cloud Engine
Prisma AIRS Network Intercept
Prisma AIRS API Intercept
Answer: C
The short version
C — GKE microservices threats need Network Intercept. Inline network enforcement stops poisoning and lateral movement between containers.
Key concepts in this question
Network Intercept: inline inspection of AI-stack traffic.
Threat pair: data poisoning plus lateral movement are network-visible.
Access-layer contrast: URL filtering and App-ID serve user-to-app, not stack-internal.
Why C is correct
Prisma AIRS Network Intercept protects the containerized AI stack from internal and external network threats.
Why the others are wrong
A. URL Filtering governs web destinations, not microservice laterals.
B. App-ID Cloud Engine identifies apps; it interdicts no laterals.
D. API Intercept guards API surfaces, not container-network movement.
NetSec Architect exam tip
Stack-internal movement means Network Intercept. API surface means API Intercept.
2An architect is reviewing a use case with the following requirements: Visibility on the health of an end user's path for the five most critical applications Metrics on the impact of endpoint health for application Centralized call quality analytics from Zoom video conferencing solution Insights into the supporting protocols, such as DNS Support 600 users on Windows desktops in a single sales office Which solution should be recommended to meet these requirements?
Remote networks with ADEM enabled and an ION device
GlobalProtect with a Prisma Access portal configured and ADEM enabled
Prisma SD-WAN using the native application dashboard and link quality monitoring
Prisma Browser or the Prisma Browser extension with RUM metrics
Answer: A
The short version
A — Zoom analytics plus endpoint path health means ADEM on remote networks. ION-backed remote access with experience monitoring covers every requirement.
Key concepts in this question
ADEM: digital experience monitoring including collaboration quality.
Remote networks plus ION: single-office Windows fleet fit.
Close vote: 4-to-3 with the banked key; GlobalProtect lacks the Zoom analytics.
Why A is correct
Remote networks with ADEM and an ION deliver path health, endpoint impact, Zoom call analytics, DNS insight, and office scale.
Why the others are wrong
B. GlobalProtect portal plus ADEM misses the centralized Zoom analytics and office-network fit.
C. SD-WAN dashboards show links, not Zoom call quality or endpoint impact.
D. Browser RUM covers web apps, not Zoom or endpoint health.
NetSec Architect exam tip
Collaboration-quality analytics always answer ADEM. Link dashboards never do.
3A large organization uses Palo Alto Networks VM-Series firewalls deployed across multiple availability zones in Microsoft Azure. These are managed by an Azure Virtual Machine Scale Set (VMSS) and integrated with an Azure Load Balancer for high availability (HA) traffic inspection within a Transit VNet. The security team needs to perform a critical PAN-OS software upgrade across the entire fleet of firewalls with the requirement of minimal application downtime. Following Palo Alto Networks best practices for highly available cloud deployments, what is the recommended approach for safely performing this software upgrade with the least downtime?
Update the image in an Azure VMSS and then initiate an upgrade of the instances
Configure Azure Load Balancer probes to handle the health check failover during upgrades
Provision a new, parallel VMSS with the new PAN-OS version, validate it, and redirect traffic from the old VMSS to the new one
Use Azure Update Manager to push the PAN-OS upgrade package directly to all firewall instances simultaneously during a scheduled maintenance window
Answer: C
The short version
C — blue-green VMSS swap upgrades Azure fleets safely. Validate the parallel scale set, then swing traffic with minimal downtime.
Key concepts in this question
Parallel validation: new PAN-OS proven before cutover.
Traffic swing: load balancer moves flows cleanly.
In-place contrast: image swaps and simultaneous pushes risk the fleet.
Why C is correct
A parallel VMSS on the new version, validated then cut over, is the best-practice safe upgrade.
Why the others are wrong
A. In-place image upgrades bounce instances with downtime.
B. Probes steer failover; they upgrade nothing.
D. Simultaneous pushes maximize blast radius during the window.
NetSec Architect exam tip
Fleet upgrades go blue-green: build parallel, validate, swing.
4A global organization has fully adopted Prisma Access to provide security for its mobile workforce and remote offices, and user identity is managed in Okta. The security team wants to create consistent Security policies that grant access to specific SaaS applications based on a users' departments, regardless of whether they work from home or a from branch office connected via an SD-WAN device Which architecture ensures that consistent user-to-group mapping is available to Prisma Access for policy enforcement in this use case?
Install the Palo Alto Networks User-ID agent and configure it to sync user information from Okta to Prisma Access
Deploy Panorama to manage Prisma Access and configure it to pull user and group information from Okta via the Cloud Identity Engine
Configure SAML federation between Prisma Access and Okta to provide user identity for every web request
Configure each remote office SD-WAN device and each user’s GlobalProtect client to query Okta directly for user information
Answer: B
The short version
B — Panorama plus Cloud Identity Engine bridges Okta to Prisma Access. Group mapping flows IdP to engine to enforcement consistently.
Key concepts in this question
CIE sync: Okta users and groups into the identity fabric.
Panorama management: consistent policy referencing those groups.
Per-device contrast: distributed queries never stay consistent.
Why B is correct
Panorama-managed Prisma Access pulling Okta groups via Cloud Identity Engine gives every location one mapping.
Why the others are wrong
A. User-ID agents do not sync cloud IdP groups to Prisma Access.
C. Per-request SAML authenticates; it does not distribute group maps.
D. Per-device IdP queries fragment policy and scale nowhere.
NetSec Architect exam tip
Consistent cloud groups mean CIE in the middle. Agents and per-device queries never do.
5An organization wants to migrate to an SSE model using Prisma Access for hybrid workforce connectivity. Following bandwidth analysis, network engineers have identified high-bandwidth requirements (>2 Gbps) sustained throughput to the data center for privately hosted applications (e.g., three tier applications active FTP and SMB file servers, EDR toolsets). Business continuity for the organization requires the ability to use multiple cloud providers for private-application connectivity, ensuring no single cloud provider outage can disrupt operations. The network operations team has expressed concerns about migrating to SSE with legacy routing technical debt noting multiple redistribution protocols in place across the environment. Which two network connectivity methods will meet the business requirements to access private applications from Prisma Access? (Choose two.)
ZTNA Connectors
Colo-Connect
Cloud gateways
Service connections
Answer: B, D
The short version
B and D — fat private flows ride Colo-Connect plus service connections. Dedicated multi-cloud private paths carry the sustained gigabits.
Service connections: Prisma Access private-app on-ramps.
ZTNA contrast: per-app brokers, not multi-gigabit DC pipes.
Why B and D are correct
B. Colo-Connect supplies multi-cloud private connectivity immune to single-provider outages.
D. Service connections land private applications into Prisma Access.
Why the others are wrong
A. ZTNA Connectors broker apps, not sustained 2 Gbps-plus DC flows.
C. Cloud gateways do not meet the stated private-throughput design.
NetSec Architect exam tip
Gigabits-private-multicloud means Colo plus service connections. App brokers answer other asks.
6A global organization plans to implement a full Zero Trust network solution to evolve its security architecture and is deciding between SASE and traditional firewall edge solutions. The organization currently has a WAN solution with all traffic backhauled to a central set of data centers and requires that branch-to-branch traffic be permitted for all 721 branch locations. What is a crucial consideration as the solutions architect plans the end architecture for this organization?
PAN-OS SD-WAN should be used for full mesh deployments of 100 or more sites that require full security capabilities
Prisma Access does not support direct branch-to-branch traffic, but requires traffic to be routed by a service connection
Prisma SD-WAN supports partial mesh architectures with App-ID, Threat, and DNS Security for direct branch-to-branch traffic
Explicit proxy may be used in conjunction with Prisma Browser or а РАС file to access applications on a remote network
Answer: C
The short version
C — 721-site mesh with security means Prisma SD-WAN partial mesh. App-ID, Threat, and DNS Security ride direct branch-to-branch paths.
Key concepts in this question
Partial mesh: scalable any-to-any without full-mesh state.
Embedded security: App-ID, Threat, DNS on the WAN fabric.
Scale ceiling: PAN-OS full mesh stops far below 721 sites.
Why C is correct
Prisma SD-WAN partial mesh with embedded security serves all branches directly with full inspection.
Why the others are wrong
A. PAN-OS full mesh does not scale to hundreds of secured sites.
B. Branch-to-branch works on the SD-WAN fabric; the impossibility claim is false.
D. Proxy/PAC answers remote-app access, not branch mesh design.
7An organization plans to deploy a full SASE architecture consisting of Prisma SD-WAN IONs at branches and data centers alongside Prisma Access remote networks, service connections, and mobile users. The business office team requires that traffic from global remote offices to public cloud is of highest criticality, and this traffic should have the greatest service-level agreement (SLA) and QoS priority while still maintaining a balance of threat inspection. Which recommendation should the architect make to provide the lowest latency, highest throughput, and greatest resilience for the applications?
Prisma Access Agent or а РАС file explicit proxy configuration connecting the end user devices directly to Prisma Access with a service connection to the public cloud provider
Prisma Access remote networks with service connections directly to the cloud environment using IPSec and either static or dynamic routing
Prisma SD-WAN IONs deployed within the cloud environment using BGP-to-peer to the internal route tables of the application
Prisma SD-WAN ION deployed at both branch and private data center with a direct private link between the private data center and the public cloud provider
Answer: C
The short version
C — cloud-resident IONs with BGP win the SLA race. In-cloud fabric nodes peer directly to app route tables for lowest latency and best resilience.
Key concepts in this question
Proximity: inspection adjacent to the workload.
BGP peering: direct route exchange with app tables.
Balance: threat inspection retained without hairpin cost.
Why C is correct
Prisma SD-WAN IONs inside the cloud peering BGP to internal tables give the lowest latency, top throughput, and resilient inspected paths.
Why the others are wrong
A. Agent/PAC paths serve users, not cloud-ward SLA design.
B. Remote-network IPsec hairpins add latency versus in-cloud IONs.
D. Private-line backhaul bypasses the inspected cloud fabric.
NetSec Architect exam tip
Cloud-ward SLA means IONs in the cloud peering BGP. Hairpins and agents lose.
8A cloud engineer has implemented a security solution with a VM-Series firewall in a GCP centralized VPC to secure traffic between two spoke VPCs, but there is no communication between the spokes. Which missed implementation step may cause this behavior?
Security policy rule allowing inter-spoke traffic
Peering connection between the two spoke VPCs
Source NAT policy for traffic initiated from one spoke to the other
Specific no-NAT policy rule for traffic between the spoke CIDR ranges
Answer: A
The short version
A — silent spokes mean a missing allow rule. Central inspection drops what no policy permits.
Key concepts in this question
Centralized model: spokes route via the security VPC.
Default deny: unpermitted inter-spoke flows die quietly.
Peering myth: spoke-to-spoke peering would bypass the firewall.
Why A is correct
Without a security rule allowing inter-spoke traffic, the central VM-Series drops it.
Why the others are wrong
B. Direct spoke peering contradicts centralized inspection.
C. Source NAT fixes addressing, not missing permits.
D. GCP peering plus centralized inspection needs no-NAT tricks for basic flow.
NetSec Architect exam tip
Central inspection silence means check the allow rule first, topology second.
9An organization uses Microsoft Entra ID and wants to strictly enforce a requirement that remote users accessing highly sensitive SaaS applications can only do so when originating from Prisma Browser. Which unique identifier must be configured within the Entra ID Conditional Access policy to effectively confirm and enforce that the access request is specifically originating from Prisma Browser and preventing standard web browsers from circumventing the Zero Trust Network Access (ZTNA) control?
List of known egress IP addresses associated with Prisma Browser’s cloud proxy infrastructure
Unique device token or Device-ID issued by Prisma Browser and validated by Entra ID
Certificate thumbprint of Prisma Browser’s secure workspace key used for session encryption
GlobalProtect mobile application installed on the user's endpoint
Answer: B
The short version
B — Entra enforcement of Browser-only access needs the Browser device token. Device-ID proves the requester is Prisma Browser, not any browser.