<< Prev Question Next Question >>

Question 26/32

An organization has a directive to adopt a Zero Trust framework focused on using identity and role-based access groups, device security and content inspection across all Security policies. To achieve this goal, an Enterprise License Agreement (ELA) was purchased, including Advanced Threat Prevention, IoT Security, and GlobalProtect.
The current security architecture uses Panorama to manage 60 NGFWs - a mix of PA-3240, PA-1410, and PA-440. Sites with PA-3240s host private application resources in the trust data center zone All sites have an untrust zone for internet access and a users zone for managed and unmanaged endpoint devices. A transit mesh zone exists to establish site-to-site connectivity through PAN-OS SD-WAN.
Privately hosted applications include web servers, SMB and NFS file servers and hosted Active Directory. The organization is in the process of adopting group mapping restrictions to these private applications, with daily additions of groups. It is also planning to build AI applications to assist the data teams with complex queries that will be hosted in the large offices containing data centers and is exploring hosting in the public cloud.
The organization uses on-premises Exchange, Dropbox, Zoom, and ChatGPT. There are a number of shadow SaaS applications that require further investigation. Users have been using Google Drive to upload confidential files within the organization by using their personal logins.
IoT devices on the network are associated on their own VLAN on the users zone. Using Device Security, all IoT devices have been categorized by asset profiles with medium or high confidence, policy sets imported into Panorama, and a default deny applied to the IoT networks.
The organization has rolled out SSL decryption and is using URL categorization for the majority of content filtering. Malicious categories, unknown and high-risk websites are blocked, with the remainder of sites set to alert.
Which deployment method should the architect suggest for enabling User-ID based rules, restricting or allowing access as close to the source as possible, while minimizing operational overhead?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (32q)
Question 1: A multinational organization has a large worldwide remote us...
Question 2: A multinational organization has a large worldwide remote us...
Question 3: An organization wants to detect and prevent unknown malware....
Question 4: A global manufacturing organization has a strategic plan for...
Question 5: A network experiences encrypted threats bypassing inspection...
Question 6: A company wants to reduce false positives in threat detectio...
Question 7: A global manufacturing organization has a strategic plan for...
Question 8: An organization uses Microsoft Entra ID and wants to strictl...
Question 9: An organization is in the process of building a network infr...
Question 10: A global manufacturing organization has a strategic plan for...
Question 11: A global manufacturing organization with 50,000 employees sp...
Question 12: A global organization is in the process of securing critical...
Question 13: A global organization is in the process of securing critical...
Question 14: An architect is reviewing a use case with the following requ...
Question 15: An organization wants to modernize its legacy branch archite...
Question 16: An enterprise needs to identify users accessing applications...
Question 17: An organization with offices throughout the world has an SD-...
Question 18: You need to ensure compliance reporting and audit visibility...
Question 19: An architect must design secure remote access for users. Whi...
Question 20: Which custom component can mitigate the risk associated with...
Question 21: A global organization is in the process of securing critical...
Question 22: A global organization is modernizing its data center and pri...
Question 23: A multinational organization has a large worldwide remote us...
Question 24: An organization is designing the Prisma Access service conne...
Question 25: An organization is in the process of building a network infr...
Question 26: An organization has a directive to adopt a Zero Trust framew...
Question 27: A multinational organization has a large worldwide remote us...
Question 28: You must ensure high availability for critical firewall depl...
Question 29: An organization has a directive to adopt a Zero Trust framew...
Question 30: A global manufacturing organization with 50,000 employees sp...
Question 31: A company needs DNS-based threat protection to block malicio...
Question 32: A retail organization wants to sanction the use of a particu...