Courseiva
Zero Trust Architecture And DesignhardMultiple ChoiceObjective-mapped

NetSec-Architect Zero Trust Architecture And Design Practice Question

An architect is designing a Zero Trust secure access solution where remote users must authenticate using multi-factor authentication (MFA) and have their device health verified before accessing internal applications. However, certain unmanaged third-party vendor laptops cannot install the GlobalProtect agent. Which architectural solution should be implemented for these specific third-party vendors?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy GlobalProtect Clientless VPN portals combined with SAML-based MFA and strict application-level URL filtering

GlobalProtect Clientless VPN allows unmanaged endpoints to access specific web-based applications securely via a browser portal without requiring an endpoint client installation, while still supporting SAML/MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide local administrative credentials to the vendor over phone support

    Why it's wrong here

    Incorrect. Sharing admin credentials violates all security best practices.

  • Deploy GlobalProtect Clientless VPN portals combined with SAML-based MFA and strict application-level URL filtering

    Why this is correct

    Correct. Clientless VPN provides secure access for unmanaged devices via browser portals with MFA and strict controls.

  • Send pre-configured full-tunnel IPsec client software via unencrypted email attachments

    Why it's wrong here

    Incorrect. Full-tunnel VPN on unmanaged devices without posture checks violates Zero Trust.

  • Block third-party vendors entirely with no access options under any circumstances

    Why it's wrong here

    Incorrect. Business requirements often dictate vendor access; blocking outright without evaluation is poor architecture.

About these practice questions

This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.