Courseiva
Zero Trust Architecture And DesigneasyMultiple ChoiceObjective-mapped

NetSec-Architect Zero Trust Architecture And Design Practice Question

An architect is designing a Zero Trust network segmentation strategy for a multi-tenant enterprise data center using Palo Alto Networks PA-5250 firewalls. Which architectural design principle aligns best with a Zero Trust Network Architecture (ZTNA) when applied to east-west traffic between different applications within the same trust zone?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Establish granular Layer 7 App-ID based policies and inspect all east-west traffic between internal application segments

Zero Trust mandates that all traffic, regardless of its origin zone, must be inspected and authorized. Trusting internal zones violates the fundamental principle of 'never trust, always verify'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable User-ID and App-ID mapping for internal traffic to reduce CPU overhead on the firewall while maintaining layer 3/4 filtering

    Why it's wrong here

    Incorrect. Layer 7 visibility (App-ID and User-ID) is vital in Zero Trust architectures to ensure least-privilege access control.

  • Establish granular Layer 7 App-ID based policies and inspect all east-west traffic between internal application segments

    Why this is correct

    Correct. Zero Trust requires inspection and strict access control for all traffic, including intra-zone and east-west flows.

  • Create a wide-open intra-zone rule to allow all east-west traffic for performance optimization and apply inspection only on the perimeter

    Why it's wrong here

    Incorrect. Relying on perimeter security and trusting internal traffic is the traditional perimeter-based model, which Zero Trust seeks to eliminate.

  • Route all east-west traffic directly through core enterprise switches without firewall inspection to minimize latency

    Why it's wrong here

    Incorrect. Bypassing the firewall means zero visibility and control over east-west traffic, failing ZT requirements.

About these practice questions

This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.