NetSec-Architect Zero Trust Architecture And Design Practice Question
An architect is designing a Zero Trust network segmentation strategy for a multi-tenant enterprise data center using Palo Alto Networks PA-5250 firewalls. Which architectural design principle aligns best with a Zero Trust Network Architecture (ZTNA) when applied to east-west traffic between different applications within the same trust zone?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish granular Layer 7 App-ID based policies and inspect all east-west traffic between internal application segments
Zero Trust mandates that all traffic, regardless of its origin zone, must be inspected and authorized. Trusting internal zones violates the fundamental principle of 'never trust, always verify'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable User-ID and App-ID mapping for internal traffic to reduce CPU overhead on the firewall while maintaining layer 3/4 filtering
Why it's wrong here
Incorrect. Layer 7 visibility (App-ID and User-ID) is vital in Zero Trust architectures to ensure least-privilege access control.
- ✓
Establish granular Layer 7 App-ID based policies and inspect all east-west traffic between internal application segments
Why this is correct
Correct. Zero Trust requires inspection and strict access control for all traffic, including intra-zone and east-west flows.
- ✗
Create a wide-open intra-zone rule to allow all east-west traffic for performance optimization and apply inspection only on the perimeter
Why it's wrong here
Incorrect. Relying on perimeter security and trusting internal traffic is the traditional perimeter-based model, which Zero Trust seeks to eliminate.
- ✗
Route all east-west traffic directly through core enterprise switches without firewall inspection to minimize latency
Why it's wrong here
Incorrect. Bypassing the firewall means zero visibility and control over east-west traffic, failing ZT requirements.
About these practice questions
This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.