Courseiva

NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture

An architect is implementing SaaS Security inline to discover and control unauthorized (shadow IT) cloud applications used by employees. The requirement is to generate logs and alert administrators when high-risk file-sharing applications are accessed, without immediately blocking business operations. How should this be configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Security Rule allowing the specific App-ID applications, attach a SaaS Security policy profile, and set log-setting to log at session end.

SaaS Security inline policies and App-ID security rules can be configured with logging enabled and the action set to 'allow' while applying a custom SaaS Security profile to tag and monitor risk levels without dropping traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set the security rule action to 'Deny' and configure a custom response page directing users to submit a business justification ticket.

    Why it's wrong here

    Setting the action to 'Deny' blocks the application, which violates the requirement not to block operations immediately.

  • Disable App-ID inspection and configure Layer-4 port-based blocking rules for ports 80 and 443.

    Why it's wrong here

    Port-based blocking blocks all web traffic indiscriminately.

  • Configure a GlobalProtect client certificate authentication requirement for all web traffic.

    Why it's wrong here

    Client certificates do not provide SaaS application discovery or shadow IT risk profiling.

  • Create a Security Rule allowing the specific App-ID applications, attach a SaaS Security policy profile, and set log-setting to log at session end.

    Why this is correct

    Allowing the applications while logging and profiling via SaaS Security provides visibility and risk scoring without breaking business processes.

About these practice questions

One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.