Courseiva
SOC OperationsmediumMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner SOC Operations Practice Question

A security architect is designing a Zero Trust network segmentation model using Palo Alto Networks Next-Generation Firewalls. To prevent lateral movement of malware across internal VLANs, which operational rule must be strictly enforced?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Inspect and restrict all east-west internal traffic based on least-privilege application context

Zero Trust requires micro-segmentation and inspecting all traffic—including east-west traffic between internal segments—based on explicit application and user context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trust all traffic originating from authenticated internal subnets by default

    Why it's wrong here

    Zero Trust assumes zero implicit trust, even for authenticated internal networks.

  • Permit all communication between endpoints sharing the same Active Directory domain

    Why it's wrong here

    Active Directory domain membership does not imply security trust; micro-segmentation must still apply.

  • Inspect and restrict all east-west internal traffic based on least-privilege application context

    Why this is correct

    Zero Trust dictates that all internal (east-west) traffic must be inspected and authorized based on context.

  • Rely solely on perimeter firewalls to block inbound threats from the internet

    Why it's wrong here

    Perimeter defenses alone do not protect against lateral movement once an attacker breaches the network.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.