検証済みNetSec-Architect問題集と解答で2026年最新のNetSec-Architectをダウンロード
更新された100%カバー率リアルNetSec-Architect試験問題で100%合格保証付いてます
質問 # 21
An IoT sensor should be deployed in the path between the IoT device and which infrastructure component for comprehensive profiling coverage?
- A. DHCP server
- B. IoT Gateway
- C. DNS server
- D. SNMP Collector
正解:A
解説:
DHCP traffic provides critical device-identifying attributes such as MAC address, hostname, vendor class identifier, and IP address assignment, which are essential for accurate IoT device profiling. Placing the IoT sensor in the path between the device and the DHCP server ensures comprehensive visibility during initial network onboarding, enabling reliable identification and classification.
質問 # 22
A company experiences lateral movement attacks within the internal network. Which feature helps mitigate this risk?
- A. QoS policies
- B. Static routes
- C. Internal segmentation with NGFW
- D. NAT rules
正解:C
解説:
Internal segmentation using NGFWs enforces security policies between internal zones, limiting lateral movement. This approach applies inspection and access control within the network, unlike NAT or routing, which do not provide security enforcement.
質問 # 23
A global manufacturing organization has a strategic plan for rapid growth through mergers and acquisitions Several components the organization has purchased are deemed large deployments with existing IP address schemas and allocations that conflict with the parent organization. The manufacturing organization needs access to the resources before a re-IP initiative can be completed.
All of the deployments include a variety of IoT devices Leadership requires protection of vulnerable assets and identification of any known CVEs associated with the IoT devices. The governance, risk and compliance (GRC) team requires comprehensive non-repudiable logs to identify all IoT devices reporting "Critical (9 0+) CVE scores" for mandatory remediation.
Throughput needs to exceed the current 1 Gbps trending rate, and with expected growth will soon scale to 5 Gbps.
Segmentation is a mandatory requirement with enclaves based on region, device type, and function.
Which off-ramp should an architect recommend to meet the requirements of the organization?
- A. Colo-Connect
- B. ZTNA Connector
- C. GCP Network Cloud Connector
- D. Service Connection
正解:A
解説:
Colo-Connect provides high-throughput, private connectivity between Prisma Access and on- premises or data center environments, supporting multi-gigabit requirements (scaling beyond 1 Gbps toward 5 Gbps). It is designed for large-scale, high-performance environments and supports segmentation and secure access without requiring immediate re-IP, making it the best fit for this scenario.
質問 # 24
An architect must design secure remote access for users. Which solution is MOST appropriate?
- A. Static routing
- B. NAT only
- C. GlobalProtect
- D. VLAN segmentation
正解:C
解説:
GlobalProtect provides secure remote access with user authentication, device posture checks, and policy enforcement. It ensures secure connectivity compared to basic network configurations.
質問 # 25
You must ensure high availability for critical firewall deployments. What configuration should you implement?
- A. Static routing only
- B. Manual failover
- C. Active/Passive HA
- D. Single firewall
正解:C
解説:
Active/Passive HA ensures redundancy by maintaining a standby firewall ready to take over in case of failure. This minimizes downtime and ensures continuous protection, unlike manual failover or single-device deployments.
質問 # 26
A global manufacturing organization has a strategic plan for rapid growth through mergers and acquisitions Several components the organization has purchased are deemed large deployments with existing IP address schemas and allocations that conflict with the parent organization. The manufacturing organization needs access to the resources before a re-IP initiative can be completed.
All of the deployments include a variety of IoT devices Leadership requires protection of vulnerable assets and identification of any known CVEs associated with the IoT devices. The governance, risk and compliance (GRC) team requires comprehensive non-repudiable logs to identify all IoT devices reporting "Critical (9 0+) CVE scores" for mandatory remediation.
Throughput needs to exceed the current 1 Gbps trending rate, and with expected growth will soon scale to 5 Gbps.
Segmentation is a mandatory requirement with enclaves based on region, device type, and function.
A firewall has been configured in tap mode for visibility into the traffic for profiling Inconsistencies in the profiling have been observed with a mix of behaviors.
What are two possible root causes for the behavior? (Choose two.)
- A. Asymmetric routing is providing visibility into TX but not RX traffic
- B. Hard coded MAC addresses cannot be properly profiled
- C. The devices are deployed behind a NAT device
- D. MAC spoofing is occurring on the network
正解:A、C
解説:
When devices are behind a NAT device, multiple endpoints can appear as a single source, which reduces profiling accuracy and can cause mixed or inconsistent behavior to be attributed incorrectly. Asymmetric routing can also cause incomplete visibility because the firewall may see only one side of the conversation, preventing the profiling engine from observing the full traffic pattern needed for accurate identification.
質問 # 27
An organization is in the process of building a network infrastructure that is cloud first. Part of the revised architecture includes Prisma Access as demonstrated in the diagram below. The organization has selected Strata Cloud Manager (SCM) as the management method for Prisma Access and NGFWs deployed at the data center and in public cloud environments. There are 150 NGFWs in place that are used to terminate service connections and segment networks as well as to secure the data center and public cloud resources.
One of the resilience requirements is to provide highly available directory services and authentication for the NGFW and Prisma Access deployment.
Which traffic flow is valid for administrators connecting network equipment over SSH hosted in the data center?
- A. Prisma Browser → Service Connection → Data Center → Target Application
- B. Prisma Browser → Explicit Proxy → Service Connection → Data Center → Target Application
- C. Prisma Browser → Explicit Proxy → Mobile User SPN → Service Connection → Data Center → Target Application
- D. Prisma Browser → Mobile User SPN → Service Connection → Data Center → Target Application
正解:D
解説:
SSH is not an HTTP/HTTPS application, so it does not use the explicit proxy path. For administrators connecting from Prisma Browser to network equipment hosted in the data center, the valid flow is through the mobile user path into Prisma Access, then across the service connection to the data center, and finally to the target device. This matches the IPSec/SSL connectivity shown for Prisma Browser-based user access to private applications.
質問 # 28
A company wants automated response to detected threats. What should they implement?
- A. Disable alerts
- B. Static rules only
- C. SOAR integration
- D. Manual response
正解:C
解説:
SOAR enables automated incident response by integrating detection and remediation workflows.
This reduces response time and improves consistency compared to manual processes.
質問 # 29
A global manufacturing organization with 50,000 employees spanning 35 countries designs advanced industrial equipment and owns significant intellectual property. The organization operates in a highly competitive market where protecting trade secrets is critical to maintaining market advantage.
Over the past 18 months, the CISO discovered that employees across the organization have adopted hundreds of GenAI applications to improve productivity. Engineers use AI coding assistants to accelerate product development sales teams use AI tools to generate proposals, and customer service representatives use chatbots to draft responses. While this adoption has driven innovation, it has also created significant security risks.
A security audit reveals sensitive CAD files uploaded to image-generation services, proprietary source code shared with public coding assistants, and confidential customer information used in prompts. The audit identifies over 300 different GenAI applications in use, most of which had not been formally reviewed or approved.
The customer service department has also been developing internal AI applications, including a customer service copilot built on a cloud large language model (LLM) platform, an internal knowledge management assistant, and a code review tool. These internal applications access sensitive databases, customer records and internal APIs - creating additional security concerns about exploitation or misuse.
The organization has a distributed workforce in which 60% of employees work remotely or in hybrid arrangements, accessing corporate resources and AI applications from various locations using managed and unmanaged devices. Existing network security infrastructure lacks AI-specific security capabilities.
Organization leadership wants to enable AI-driven innovation while implementing comprehensive security controls. The CISO has been tasked with developing an organization-wide GenAI governance program that protects sensitive assets without hindering productivity. The program must address both external AI applications employees are using and internal AI applications being developed by IT.
In which two ways would Prisma AIRS secure AI agents deployed across multiple cloud platforms in this scenario? (Choose two.)
- A. By supporting API Intercept for Multicloud deployments since Network Intercept cannot be deployed in the network architectures of different cloud providers.
- B. By providing Network Intercept inline in multicloud network architectures to monitor AI agent traffic, and API Intercept as Security as Code (SaC) to scan prompts and responses before they reach models.
- C. By offering Network Intercept for infrastructure-level protection across any cloud platform and API Intercept for application-level security embedded directly in agent code.
- D. By requiring separate product installations for each cloud platform with AWS-specific agents for Bedrock and GCP-specific agents for Vertex AI that cannot share policies.
正解:B、C
解説:
Network Intercept provides inline visibility and control of AI traffic across multicloud environments, enabling consistent infrastructure-level protection regardless of where agents are deployed. API Intercept complements this by acting at the application layer, scanning prompts and responses and embedding security controls directly into AI workflows, ensuring protection before interactions reach the model.
質問 # 30
A multinational organization has a large worldwide remote user base. This user base consists of several persona types with distinct requirements and concerns regarding the adoption of a Zero Trust Network Access (ZTNA) solution.
- Developers have a requirement to temporarily bypass security controls for business purposes, but the security team sees this as a potential risk. The developers commonly access development servers onsite in private data centers and public cloud. These development applications use web (HTTP/HTTPS), API, RPC, and SMB-based applications.
- Sales staff travel regularly and connect to the network via many different types of connections, but they are generally limited to SaaS-based web applications. They often complain about performance when any agent is installed and want the ability to temporarily disable these agents.
Data exfiltration and insider risk have been identified as the primary threats for this class of user.
- Executives have concerns about being high-value targets. Security must be consistent across the multiple endpoint types, including mobile and desktop devices. The executive team members have indicated that their primary objective is to ensure that the solution is responsive and easy to troubleshoot.
Which solution should be suggested to mitigate the security risk and meet the concerns of the sales team?
- A. Provide end users scoped access to Strata Cloud Manager (SCM) and require them to configure split tunneling for applications they need to bypass
- B. Migrate end users to Prisma Browser for all work applications and apply data protection rules to all enterprise applications
- C. Use the standalone WildFire Agent on the endpoint to maintain security for large and unknown file downloads
- D. Automate uploads of files to the Enterprise DLP submissions portal so all files undergo data inspection regardless of connectivity method
正解:B
解説:
Prisma Browser provides agentless access with built-in data protection controls, allowing the organization to enforce DLP and prevent data exfiltration without requiring a traditional endpoint agent. This directly addresses the sales team's concern about performance and the ability to disable agents while still maintaining strong security controls for SaaS-based applications.
質問 # 31
A network experiences encrypted threats bypassing inspection. What is the BEST mitigation?
- A. Enable SSL decryption
- B. Block all HTTPS
- C. Disable logging
- D. Use static routes
正解:A
解説:
SSL decryption allows inspection of encrypted traffic, revealing hidden threats. Blocking HTTPS is impractical, and disabling logging or adjusting routing does not address encrypted threat visibility.
質問 # 32
A company wants visibility into all traffic, including unknown applications. What feature enables this?
- A. Routing
- B. QoS
- C. App-ID
- D. NAT
正解:C
解説:
App-ID identifies applications regardless of port, protocol, or encryption. It provides deep visibility into network traffic, including unknown or evasive applications.
質問 # 33
A security architect needs to design a log collection architecture for a large organization with hundreds of firewalls distributed across multiple geographic regions. The primary requirement is to ensure that if a single Log Collector in any region fails, logs from the firewalls in that region will automatically be sent to another available Log Collector without manual intervention. What is the recommended Panorama feature to achieve this level of log collection resilience?
- A. Storage capacity increase on each individual Log Collector
- B. Load balancer to distribute logs across all Log Collectors
- C. Log Collector Group for each geographic region
- D. Log Collectors deployed in a high availability (HA) pair
正解:C
解説:
A Log Collector Group allows multiple collectors to operate together so firewalls can automatically forward logs to any available collector in the group. If one collector fails, logging seamlessly continues to other members without manual reconfiguration, providing the required resilience across regions.
質問 # 34
A security architect must design a Zero Trust architecture using Palo Alto solutions. Which principle is MOST critical?
- A. Disable encryption
- B. Allow all outbound traffic
- C. Trust internal network by default
- D. Verify and inspect all traffic
正解:D
解説:
Zero Trust requires continuous verification of all users and traffic, regardless of location. Palo Alto NGFW supports this with App-ID, User-ID, and content inspection. Trusting internal networks or allowing unrestricted outbound traffic contradicts Zero Trust principles.
質問 # 35
An enterprise deploys Palo Alto NGFWs across multiple regions. They require consistent security policy enforcement and centralized management while minimizing configuration drift. Which solution should be implemented?
- A. Local firewall configuration only
- B. Manual policy synchronization
- C. Separate management per region
- D. Panorama with device groups and templates
正解:D
解説:
Panorama provides centralized management of policies and configurations across multiple firewalls. Device groups allow consistent policy enforcement, while templates manage network and system settings. This reduces configuration drift and operational overhead compared to manual or decentralized approaches.
質問 # 36
An organization has selected Prisma SD-WAN ION devices for use at branch offices and is working to build a low-level design for its sites. A typical branch site has a 10 Mbps MPLS with fiber LC-SR, and an RJ-45 Ethernet 50 Mbps DIA internet circuit.
There are 75 workstations and a stacked core switch that supports LACP, M-LAG, BGP, and OSPF will be used. The core switch is the default gateway for all local VLANs. The final design will determine the selection of the appropriate model and accessories for the site.
Which statement applies to the Prisma SD-WAN architecture in this use case?
- A. High availability (HA) for the LAN side connectivity can at most support two interfaces using LAG / LACP
- B. Connectivity over the MPLS will be lost when the device that terminates it loses power
- C. MPLS underlay paths cannot be used as an active path alongside internet overlay path
- D. Only a default route can be advertised on a LAN-side BGP peering from the ION
正解:B
解説:
In this design, the MPLS circuit is being terminated by the ION. If that device loses power, the MPLS path also goes down because the branch loses the device that is physically terminating and forwarding that private WAN connection. Prisma SD-WAN does support using private WAN and internet paths actively, so the issue is not coexistence of MPLS and DIA. It also supports LAN-side BGP beyond just advertising a default route, and LAG/LACP can bundle multiple LAN interfaces rather than being limited to only two.
質問 # 37
An organization is designing the Prisma Access service connections for its data centers. Each data center has 10 Gb redundant links to the internet. Each data center will need to support a minimum of 1.5 Gbps of throughput from Prisma Access connected users and branches. Which diagram depicts a solution that meets the requirements of this use case?
- A.

- B.

- C.

- D.

正解:A
解説:
This design uses ECMP across redundant ISP links with multiple active IPsec tunnels, allowing traffic to be load-balanced and aggregated. This ensures the required throughput (>1.5 Gbps) can be achieved while also providing high availability and resilience, aligning with best practices for Prisma Access service connections.
質問 # 38
A global organization is in the process of securing critical applications during a cloud-based migration while migrating to a cloud-first design, and it is currently performing a brownfield migration of its most critical applications - such as CRM and product intellectual property / design systems - into Azure Cloud. The organization already has an active/passive high availability (HA) NGFW deployed at its data center with multiple zones and has replicated that design into its existing Azure HA deployment.
The organization recognizes the need to modernize its security posture as critical workloads move out of the data center and users connect from anywhere. Its security model is defined by a traditional "hard shell, soft center" approach:
Zero Trust Gaps
- Current network segmentation is perimeter-based. The organization wants to expand Zero Trust principles across cloud and on-premises environments.
- The network relies heavily on VLANs and IP address-based Access Control Lists (ACLs) segmented primarily by office location and broad departmental groups.
- Once employees are on the corporate network (i.e., inside the "perimeter"), they have relatively wide access.
- If attackers compromise a single endpoint (e.g., via a phishing email), they can easily move laterally and scan for high-value targets.
Cloud Blind Spots
- The organization uses Azure for its production environments and hosts applications that contain sensitive customer data.
- Security controls in the cloud are often managed independently of the on-premises network.
Access is frequently granted with overly permissive identity and access management (IAM) roles and keys based on the resource rather than the user's real-time context or application health.
Remote User Access
- Many remote users are still hairpinning into the corporate data center just to reach internet or SaaS resources, creating latency and inefficiency.
- Traditional VPN is used for remote employees.
- The VPN grants access to the entire internal network segment making the remote endpoint the new, weaker perimeter. There is no continuous check on the user's device health after the initial connection.
Visibility and Logging
- Logs are primarily stored on-premises, then forwarded to a local Security Information and Event Management (SIEM) solution. As applications move to Azure, visibility into cloud traffic and user behavior becomes fragmented.
Data Security Concern
- Sensitive data, including product design files, will now live in SaaS and cloud environments. The organization needs data security to prevent leakage and enforce compliance.
Ingress Security
- Third-party partners and suppliers require access into the data center and cloud applications, introducing risk at ingress points.
The current Microsoft Azure NGFW architecture will not support the increased traffic with the new applications being migrated.
Which architectural solution will provide scalable inspection?
- A. Decommission the firewall pair and use a multi-region deployment of Azure VPN gateways to manage VNet-to-VNet connections.
- B. Keep the active/passive firewall only for north-south traffic and rely entirely on Azure Network Security Groups (NSGs) for east-west traffic inspection.
- C. Maintain the Azure active/passive design and use Azure scale sets to vertically scale the firewall size to handle all current and anticipated future east-west traffic.
- D. Migrate to a load balancer-based autoscaling firewall cluster that uses User-Defined Routes (UDRs) to traffic to multiple concurrent firewall instances for inspection.
正解:D
解説:
A scalable Azure design for VM-Series uses load balancers with multiple active firewall instances rather than a fixed active/passive pair. Palo Alto Networks documents high-resiliency Azure deployments that use load balancers to distribute traffic across concurrent firewall instances, and Azure routing to the VM-Series relies on User-Defined Routes to steer traffic through the inspection path. That makes a load balancer-based autoscaling firewall cluster the correct architecture for increased cloud migration traffic and scalable inspection.
質問 # 39
A global organization is modernizing its data center and private cloud infrastructure. The environment consists of:
- A Nutanix AHV cluster hosting critical east-west application workloads
- A VMware ESXi cluster with multi-socket hosts, supporting high-throughput workloads (>10 Gbps)
- A new pair of PA-5450 firewalls to secure the perimeter and handle encrypted traffic inspection at scale
- Strict performance service-level agreements (SLAs) for both north-south and east-west flows, with heavy reliance on TLS 1.3 and IPSec
- A Network Functions Virtualization (NFV) environment on KVM to provide high-performance security services to maximize packet throughput and minimize latency The chief architect is tasked with ensuring that the firewall design avoids hypervisor contention optimizes non-uniform memory access (NUMA) and uses hardware features for encrypted traffic.
VM-Series on Nutanix AHV - Resource Allocation
- Because the Nutanix cluster is already heavily used, the architect's main concern is preventing performance degradation of the virtual firewall. Thin provisioning or ballooning could introduce latency and unpredictability which is unacceptable for a security-sensitive workload.
VM-Series on VMware ESXi - NUMA and vCPU Placement
- In the VMware ESXi environment, the architect is deploying VM-Series for workloads pushing >10 Gbps. Assigning vCPUs across NUMA nodes or oversubscribing cores would create latency due to cross-socket memory access and scheduling delays. Similarly, dedicating logical hypethreads does not provide the deterministic data plane performance required.
Operational Integration and High Availability
- With performance guaranteed by correct hypervisor and hardware provisioning, the architect also considers high availability (HA). VM-Series pairs are deployed in active/passive HA across Nutanix and VMware clusters, while PA-5450s form the data center's north-south secure perimeter deployment. This ensures resilience without introducing unnecessary east-west inspection bottlenecks.
- The recommendation must be a scalable, high-performance firewall deployment aligned with enterprise SLAs and the CISO's encrypted traffic concerns.
Which PAN-OS feature will meet the CISO's need for north-south traffic inspection?
- A. Dedicated hardware crypto engines for offloading SSL/TLS decryption and IPSec processing
- B. Dual redundant, hot-swappable power supplies for HA
- C. Dedicated out-of-band management port for separating management and data traffic
- D. High-density DAC/QSFP ports for flexible network connectivity
正解:A
解説:
Dedicated hardware crypto engines on the PA-5450 offload SSL/TLS decryption and IPSec processing from the main CPU, enabling high-performance inspection of encrypted north-south traffic. This ensures the firewall can meet strict SLAs while handling heavy TLS 1.3 and IPSec workloads efficiently.
質問 # 40
A global manufacturing organization with 50,000 employees spanning 35 countries designs advanced industrial equipment and owns significant intellectual property. The organization operates in a highly competitive market where protecting trade secrets is critical to maintaining market advantage.
Over the past 18 months, the CISO discovered that employees across the organization have adopted hundreds of GenAI applications to improve productivity. Engineers use AI coding assistants to accelerate product development sales teams use AI tools to generate proposals, and customer service representatives use chatbots to draft responses. While this adoption has driven innovation, it has also created significant security risks.
A security audit reveals sensitive CAD files uploaded to image-generation services, proprietary source code shared with public coding assistants, and confidential customer information used in prompts. The audit identifies over 300 different GenAI applications in use, most of which had not been formally reviewed or approved.
The customer service department has also been developing internal AI applications, including a customer service copilot built on a cloud large language model (LLM) platform, an internal knowledge management assistant, and a code review tool. These internal applications access sensitive databases, customer records and internal APIs - creating additional security concerns about exploitation or misuse.
The organization has a distributed workforce in which 60% of employees work remotely or in hybrid arrangements, accessing corporate resources and AI applications from various locations using managed and unmanaged devices. Existing network security infrastructure lacks AI-specific security capabilities.
Organization leadership wants to enable AI-driven innovation while implementing comprehensive security controls. The CISO has been tasked with developing an organization-wide GenAI governance program that protects sensitive assets without hindering productivity. The program must address both external AI applications employees are using and internal AI applications being developed by IT.
Which architectural approach best aligns with the organization's strategic objectives to enable AI innovation and protect sensitive assets?
- A. Segment network zones within each data center to isolate AI workloads from critical IP address repositories and monitor east-west traffic
- B. Deploy a cloud-delivered security platform with AI-aware controls integrated with identity and device posture
- C. Rely on existing perimeter firewalls and VPN concentrators applying standard URL filtering and data loss prevention (DLP) policies for AI traffic
- D. Block external GenAI applications at the firewall and empower employees to use internally developed AI applications.
正解:B
解説:
A cloud-delivered security platform with AI-aware controls provides centralized visibility and policy enforcement across both sanctioned and unsanctioned AI applications, regardless of user location or device. By integrating identity and device posture, it enables granular Zero Trust access, protects sensitive data from exfiltration, and secures both external and internally developed AI applications without restricting innovation.
質問 # 41
An organization wants to migrate to an SSE model using Prisma Access for hybrid workforce connectivity. Following bandwidth analysis, network engineers have identified high-bandwidth requirements (>2 Gbps) sustained throughput to the data center for privately hosted applications (e.g., three tier applications active FTP and SMB file servers, EDR toolsets).
Business continuity for the organization requires the ability to use multiple cloud providers for private-application connectivity, ensuring no single cloud provider outage can disrupt operations.
The network operations team has expressed concerns about migrating to SSE with legacy routing technical debt noting multiple redistribution protocols in place across the environment.
Which two network connectivity methods will meet the business requirements to access private applications from Prisma Access? (Choose two.)
- A. Cloud gateways
- B. Service connections
- C. ZTNA Connectors
- D. Colo-Connect
正解:B、D
解説:
Colo-Connect provides high-throughput, private connectivity from Prisma Access to on-premises data centers, supporting multi-gigabit bandwidth requirements and enabling connections across multiple cloud providers for resiliency. Service connections allow direct, private routing between Prisma Access and internal resources while maintaining control over routing without requiring complex redistribution changes, making them suitable for environments with existing routing technical debt.
質問 # 42
A cloud engineer has implemented a security solution with a VM-Series firewall in a GCP centralized VPC to secure traffic between two spoke VPCs, but there is no communication between the spokes. Which missed implementation step may cause this behavior?
- A. Peering connection between the two spoke VPCs
- B. Security policy rule allowing inter-spoke traffic
- C. Specific no-NAT policy rule for traffic between the spoke CIDR ranges
- D. Source NAT policy for traffic initiated from one spoke to the other
正解:B
解説:
In the GCP centralized hub-and-spoke design, traffic between spoke VPCs is steered to the internal load balancer in the hub VPC, then inspected and forwarded by the VM-Series firewall through its trust interface to the destination spoke. That means spoke-to-spoke communication depends on the firewall being configured to permit that inter-spoke traffic after inspection. Direct peering between the spokes is not required in this architecture.
質問 # 43
An organization plans to deploy a full SASE architecture consisting of Prisma SD-WAN IONs at branches and data centers alongside Prisma Access remote networks, service connections, and mobile users. The business office team requires that traffic from global remote offices to public cloud is of highest criticality, and this traffic should have the greatest service-level agreement (SLA) and QoS priority while still maintaining a balance of threat inspection. Which recommendation should the architect make to provide the lowest latency, highest throughput, and greatest resilience for the applications?
- A. Prisma Access remote networks with service connections directly to the cloud environment using IPSec and either static or dynamic routing
- B. Prisma Access Agent or a PAC file explicit proxy configuration connecting the end user devices directly to Prisma Access with a service connection to the public cloud provider
- C. Prisma SD-WAN IONs deployed within the cloud environment using BGP-to-peer to the internal route tables of the application
- D. Prisma SD-WAN ION deployed at both branch and private data center with a direct private link between the private data center and the public cloud provider
正解:C
解説:
Deploying Prisma SD-WAN IONs in the public cloud gives remote offices the most direct path to cloud-hosted applications, which is the best fit for lowest latency and highest throughput. Prisma SD-WAN is built around application-aware path selection, QoS, and performance policy so traffic can be prioritized by business criticality and moved to a better path when SLA metrics such as latency, loss, or jitter are violated. Palo Alto Networks also supports BGP on branch and data center ION devices, including public-cloud deployments through its cloud integrations, which provides resilient routing to cloud application environments.
質問 # 44
......
リアル問題集で100%無料NetSec-Architect試験問題集を試そう:https://www.goshiken.com/Palo-Alto-Networks/NetSec-Architect-mondaishu.html