Courseiva
Specialized Security DomainsmediumMultiple ChoiceObjective-mapped

NetSec-Architect Specialized Security Domains Practice Question

A security architect is configuring Prisma Access for mobile users to ensure that traffic destined for internal corporate applications is routed securely via a specific Remote Networks connection without exposing it to the public internet. Which configuration object must be used to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Traffic Steering rule in Panorama under Cloud Services to steer private subnet traffic via Service Connections.

Explicit Proxy and Service Connections or Remote Networks routing tables via Prisma Access Panorama plugin handle routing of internal corporate traffic. Specifically, defining Traffic Steering rules ensures internal app traffic goes through Service Connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply an external dynamic list (EDL) of internal subnets to the decryption policy to bypass inspection.

    Why it's wrong here

    EDLs are for IP/URL blacklists or whitelists, not routing internal app traffic.

  • Configure a Traffic Steering rule in Panorama under Cloud Services to steer private subnet traffic via Service Connections.

    Why this is correct

    Traffic Steering rules define how traffic from mobile users reaches corporate internal networks via Service Connections.

  • Create an explicit proxy profile and push it to GlobalProtect clients via client setup settings.

    Why it's wrong here

    Explicit proxy is for web browsing inspection, not general routing of internal app traffic.

  • Implement a Zone Protection profile on the mobile user security zone to encapsulate internal routing tags.

    Why it's wrong here

    Zone Protection defends against network-level floods and spoofing, not routing.

About these practice questions

Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.