NetSec-Architect Specialized Security Domains Practice Question
An architect is designing mobile user security using Prisma Access. The design requires all remote users to connect via a single persistent client interface that automatically establishes secure tunnels regardless of user location. Which client software must be deployed to the endpoints?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GlobalProtect app
GlobalProtect is the client software used by Prisma Access to establish secure IPsec/SSL connections from mobile user endpoints to the Prisma Access cloud infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prisma SD-WAN ION client
Why it's wrong here
Prisma SD-WAN ION devices are hardware or virtual branch appliances, not software clients for individual mobile laptops.
- ✓
GlobalProtect app
Why this is correct
The GlobalProtect app is the standard agent deployed to endpoints for mobile user secure connectivity in Prisma Access.
- ✗
Prisma Cloud Defender agent
Why it's wrong here
Prisma Cloud Defender secures cloud host workloads and containers, not remote user workstations.
- ✗
WildFire agent for endpoints
Why it's wrong here
Endpoint security monitoring is handled by Cortex XDR, not WildFire.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.