NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture
An architect is implementing SaaS Security inline to discover and control unauthorized (shadow IT) cloud applications used by employees. The requirement is to generate logs and alert administrators when high-risk file-sharing applications are accessed, without immediately blocking business operations. How should this be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Security Rule allowing the specific App-ID applications, attach a SaaS Security policy profile, and set log-setting to log at session end.
SaaS Security inline policies and App-ID security rules can be configured with logging enabled and the action set to 'allow' while applying a custom SaaS Security profile to tag and monitor risk levels without dropping traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the security rule action to 'Deny' and configure a custom response page directing users to submit a business justification ticket.
Why it's wrong here
Setting the action to 'Deny' blocks the application, which violates the requirement not to block operations immediately.
- ✗
Disable App-ID inspection and configure Layer-4 port-based blocking rules for ports 80 and 443.
Why it's wrong here
Port-based blocking blocks all web traffic indiscriminately.
- ✗
Configure a GlobalProtect client certificate authentication requirement for all web traffic.
Why it's wrong here
Client certificates do not provide SaaS application discovery or shadow IT risk profiling.
- ✓
Create a Security Rule allowing the specific App-ID applications, attach a SaaS Security policy profile, and set log-setting to log at session end.
Why this is correct
Allowing the applications while logging and profiling via SaaS Security provides visibility and risk scoring without breaking business processes.
About these practice questions
One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.