NetSec-Architect Zero Trust Architecture And Design Practice Question
An architect is designing high-scale identity mapping for a multi-cloud environment using Palo Alto Networks firewalls. The architecture includes AWS, Azure, and on-premises datacenters. Some users authenticate via SAML 2.0 to cloud applications, while others authenticate via Kerberos/NTLM on-premises. How should the architect design User-ID collection to ensure consistent identity enforcement across all environments?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate multiple User-ID sources (Active Directory agent monitoring, Syslog listening from identity providers, and User-ID XML API updates from SAML gateways) into Panorama and the firewalls
PAN-OS supports multiple concurrent User-ID sources, including syslog mapping, PAN-OS XML API (fed by SAML identity providers), and Windows-based agents, consolidating them into a unified identity store.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Route all cloud traffic back through a single on-premises domain controller via GRE tunnels
Why it's wrong here
Incorrect. Backhauling cloud traffic introduces massive latency and is architecturally inefficient.
- ✗
Disable User-ID entirely and rely solely on source IP address logging in security rules
Why it's wrong here
Incorrect. Source IPs change frequently with DHCP and NAT, making them unreliable for identity.
- ✗
Configure each firewall to use a single authentication method (e.g., only NTLM), breaking SAML cloud users
Why it's wrong here
Incorrect. This fails for cloud-native SAML users.
- ✓
Integrate multiple User-ID sources (Active Directory agent monitoring, Syslog listening from identity providers, and User-ID XML API updates from SAML gateways) into Panorama and the firewalls
Why this is correct
Correct. Combining multiple User-ID information sources ensures coverage across hybrid and multi-cloud authentication mechanisms.
About these practice questions
Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.