NetSec-Architect Sample Questions & Answers
From centralized management through Panorama and Strata Cloud Manager, the top weight, to securing IoT and private clouds, you'll also cover private application access, SaaS data security, branch SASE, mobile users, Zero Trust controls, and AI security via Prisma AIRS.
Launch the full NetSec-Architect simulator →Showing 10 of 20 free samples.
- Question 1Advanced
AI Security · AI Security Architectures
An architect is deploying Prisma AIRS to secure a Kubernetes-based AI inference cluster. The requirement is to enforce microsegmentation between the 'Ingest', 'Inference', and 'Output' pods. Which component enables this visibility and control within the Kubernetes environment?
Show answer & explanation
Correct answer: C
In a Kubernetes environment, Prisma AIRS (leveraging Prisma Cloud technology) deploys as a DaemonSet (Defender) on each node to provide deep visibility and enforce microsegmentation policies at the pod/container level.
- Question 2Intermediate
AI Security · AI Application Security Controls
When designing access controls for employees using public Generative AI tools (like ChatGPT or Gemini), which feature of 'AI Access' allows the organization to distinguish between enterprise and consumer versions of the same application to enforce data controls?
Show answer & explanation
Correct answer: B
The App-ID Cloud Engine (ACE) provides advanced application identification capabilities that can distinguish between different functional aspects and versions of SaaS applications, such as distinguishing 'ChatGPT Enterprise' from 'ChatGPT Consumer'.
- Question 3IntermediateSelect 2
AI Security · Prisma AIRS and AI Access
Select TWO key functions of Prisma AIRS 'AI Red Teaming' capabilities. (Select TWO)
Show answer & explanation
Correct answers: A, D
Red Teaming also includes assessing the security posture of the model's components and supply chain risks.
AI Red Teaming involves simulating attacks to find vulnerabilities like jailbreaks or prompt injections before deployment.
- Question 4Intermediate
AI Security · AI Compliance and Controls
Which architectural component is primarily responsible for ensuring that AI applications comply with GDPR data residency requirements by preventing sensitive PII from being sent to AI models hosted in non-compliant regions?
Show answer & explanation
Correct answer: C
Enterprise DLP can identify sensitive data (PII) and enforce policies based on destination, ensuring data does not cross borders into non-compliant regions/applications.
- Question 5Advanced
AI Security · AI Application Security Controls
You are advising a customer on securing their new internal AI chatbot. They need to prevent employees from pasting proprietary source code into the chat interface. Which specific DLP classifier method would be most effective and accurate for this use case?
Show answer & explanation
Correct answer: A
ML classifiers are best suited for detecting source code and unstructured proprietary data patterns that are difficult to capture with simple regex or keywords.
- Question 6Advanced
Centralized Management and IAM · Panorama and Logging
A large enterprise uses Panorama to manage 500 firewalls. They require a log collection architecture that can sustain the failure of an entire data center without losing logs or stopping collection. Which architectural design meets this requirement?
Show answer & explanation
Correct answer: C
Spanning a Log Collector Group across locations ensures that if one site fails, the firewalls can send logs to the surviving collectors in the same group. Enabling log redistribution ensures logs are replicated/accessible.
- Question 7Intermediate
Centralized Management and IAM · Cloud Management
Which statement correctly identifies a key advantage of Strata Cloud Manager (SCM) over on-premises Panorama for a distributed SASE and NGFW environment?
Show answer & explanation
Correct answer: B
SCM is the unified management plane for the entire Strata portfolio (Hardware, Software, SASE). Being SaaS, it removes the need for managing Panorama versions/upgrades and unifies policy across form factors.
- Question 8Intermediate
Centralized Management and IAM · Identity Integration
A customer wants to simplify user authentication across their hybrid environment (Prisma Access and On-Premises Firewalls). They use Okta as their IdP. Which component should be recommended to synchronize user group information once and distribute it to all enforcement points?
Show answer & explanation
Correct answer: D
Cloud Identity Engine (CIE) connects to directory sources (like Okta, Active Directory, Entra ID) and aggregates group mapping information, providing a single source of truth that all firewalls and Prisma Access nodes can query.
- Question 9Intermediate
Centralized Management and IAM · Log Forwarding
To securely forward logs from Strata Logging Service to a third-party SIEM that only supports Syslog, which method should be recommended?
Show answer & explanation
Correct answer: B
Strata Logging Service can forward logs to external destinations. For security, Syslog over TLS (TCP/6514) is the standard recommended method to ensure logs are encrypted in transit to the SIEM.
- Question 10IntermediateSelect 2
Centralized Management and IAM · Cloud Identity Engine Use Cases
Select TWO valid use cases for integrating Cloud Identity Engine (CIE) with Prisma Access. (Select TWO)
Show answer & explanation
Correct answers: C, D
CIE can sync directory information using a lightweight cloud connector, removing the need for complex User-ID agent deployments for group mapping.
CIE acts as a broker for SAML authentication, simplifying the integration between Prisma Access and IdPs like Entra ID.
Ready for the real thing?
The full NetSec-Architect simulator has every exam-style question, timed mode, and instant scoring.