NetSec-Architect Zero Trust Architecture And Design Practice Question
An enterprise architect is deploying GlobalProtect for Zero Trust Network Access (ZTNA) across 20,000 remote endpoints. The design requires that device posture checks (checking for corporate certificate, disk encryption, and active endpoint protection) be evaluated before granting network access. Which feature combination should the architect configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GlobalProtect HIP (Host Information Profile) checks combined with HIP-based Security Policy rules on the firewall
GlobalProtect Host Information Profile (HIP) checks the security posture of the endpoint and sends the data to the firewall, where HIP-based objects can be enforced within security policy rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static IPsec pre-shared keys configured on standard native OS VPN clients
Why it's wrong here
Incorrect. Pre-shared keys provide no posture assessment or user context.
- ✗
Standard HTTP basic authentication prompts combined with local administrator username/password files
Why it's wrong here
Incorrect. Basic auth does not perform device health or posture checks.
- ✗
RADIUS authentication to an external OTP token server without any endpoint compliance agent
Why it's wrong here
Incorrect. RADIUS handles authentication, but not device posture and disk encryption checks required by ZTNA.
- ✓
GlobalProtect HIP (Host Information Profile) checks combined with HIP-based Security Policy rules on the firewall
Why this is correct
Correct. HIP gathers endpoint posture data, and HIP objects/profiles are used in security rules to enforce continuous posture assessment.
About these practice questions
One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.