Courseiva

PCNSE Core Concepts and Architecture Practice Question

A security administrator is designing a zero-trust architecture using Palo Alto Networks firewalls. They want to ensure that traffic between two internal zones is inspected and that access is granted based on user identity and device posture rather than IP address alone. Which two PAN-OS features must be implemented to meet these requirements? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse inspection features like App-ID or SSL decryption with identity and posture features, when only User-ID and HIP provide the required context for zero-trust access decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure User-ID to map users to IP addresses via GlobalProtect or AD agent.

Zero-trust access based on user identity and device posture requires User-ID to map users to IP addresses and GlobalProtect with HIP profiles to assess endpoint compliance. User-ID provides the identity context, while HIP provides posture context. Together, they allow security policies to grant or deny access based on both who the user is and the security state of their device, which is the essence of zero-trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable App-ID to identify applications regardless of port or protocol.

    Why it's wrong here

    App-ID is critical for identifying applications and enforcing granular policy, but the scenario specifically requires access based on user identity and device posture. App-ID alone does not provide user or device context. While App-ID is a foundational PAN-OS feature, it does not satisfy the identity and posture requirements described. The question asks for features that directly enable identity and posture-based access, not application identification.

  • ✓

    Configure User-ID to map users to IP addresses via GlobalProtect or AD agent.

    Why this is correct

    User-ID is essential for enforcing policy based on user identity rather than IP. By integrating with Active Directory or GlobalProtect, the firewall learns which user is associated with each IP address. Security policies can then reference users or groups directly. This is a core requirement for zero-trust because it ensures that access decisions are tied to authenticated identity, not just network location, and it enables dynamic policy that follows the user.

  • ✓

    Deploy GlobalProtect with HIP profiles to assess device posture.

    Why this is correct

    GlobalProtect with Host Information Profile (HIP) collects endpoint information such as OS patch level, antivirus status, and disk encryption, and makes it available for policy enforcement. HIP profiles can be referenced in security policies to allow or deny access based on device compliance. This directly addresses the device posture requirement in a zero-trust architecture, complementing User-ID for identity-based access control.

  • ✗

    Configure a DNS sinkhole to block malicious domains.

    Why it's wrong here

    DNS sinkholing is a threat prevention technique that redirects malicious DNS queries to a sinkhole IP, preventing communication with known bad domains. It does not provide user identity or device posture information, nor does it enforce access based on those attributes. While useful for security, it is unrelated to the zero-trust requirements of identity and posture-based access control described in the scenario.

  • ✗

    Enable SSL decryption to inspect encrypted traffic.

    Why it's wrong here

    SSL decryption allows the firewall to inspect encrypted traffic for threats and application identification, but it does not provide user identity or device posture context. Decryption is an inspection enhancement, not an access control mechanism based on identity or posture. The scenario requires features that enable zero-trust access decisions based on who the user is and the health of their device, which decryption does not address.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.