Courseiva

Certified Network Security Architect (NetSec-Architect) (NetSec-Architect) — Questions 226228

228 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
MCQeasy

What is the primary function of the VM-Series plugin for Panorama?

A.To compile WildFire malware signatures locally on the firewall data plane
B.To accelerate IPsec VPN tunnel throughput using hardware encryption crypto chips
C.To provide zero-touch provisioning and cloud API integration for VM-Series firewalls across multi-cloud environments
D.To replace the need for Panorama Log Collectors in distributed deployments
AnswerC

The VM-Series plugin allows Panorama to interact with cloud APIs, handle bootstrapping, and manage cloud-specific features.

Why this answer

The VM-Series plugin for Panorama enables Panorama to manage VM-Series firewalls across various public and private cloud environments and interact with cloud APIs.

227
MCQeasy

An architect is designing user-based security policies for a campus network where users authenticate via captive portal. Some users connect via shared workstations. Which User-ID mapping method is best suited to accurately track individual user sessions in this environment?

A.Captive Portal authentication prompting users for credentials when accessing controlled network resources.
B.Configuring static IP-to-User bindings for every workstation in the building.
C.Relying entirely on Windows Security Log polling via the User-ID Agent.
D.Using DHCP server lease logs exclusively without secondary authentication.
AnswerA

Captive portal correctly attributes traffic to the authenticated user on shared workstations rather than mapping to the machine account.

Why this answer

Captive Portal prompts users for authentication credentials when they attempt to access network resources, making it ideal for shared workstations where IP-to-user mappings from Active Directory security logs would be inaccurate or ambiguous.

228
Multi-Selectmedium

An architect is designing a Panorama role-based access control (RBAC) model for a large enterprise. Which TWO of the following capabilities can be restricted using Admin Role Profiles in Panorama? (Choose two)

Select 2 answers
A.The physical CPU core allocation assigned to individual management plane worker threads.
B.The underlying Linux root password of the Panorama appliance CLI.
C.The hardware license serial number registered to the Panorama virtual appliance.
D.Access to specific Device Groups or Templates, limiting administrators to only manage designated regions.
E.Permissions to execute specific operational tasks, such as running packet captures or clearing sessions.
AnswersD, E

Device Group and Template permissions can be restricted per admin role to enforce geographical or functional boundaries.

Why this answer

Admin Role Profiles can restrict access to specific configuration tabs, WebUI/CLI features, and specific Device Groups.

Page 3

Page 4 of 4

All pages