NetSec-Architect Zero Trust Architecture And Design Practice Question
An architect is designing a Zero Trust secure access solution where remote users must authenticate using multi-factor authentication (MFA) and have their device health verified before accessing internal applications. However, certain unmanaged third-party vendor laptops cannot install the GlobalProtect agent. Which architectural solution should be implemented for these specific third-party vendors?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy GlobalProtect Clientless VPN portals combined with SAML-based MFA and strict application-level URL filtering
GlobalProtect Clientless VPN allows unmanaged endpoints to access specific web-based applications securely via a browser portal without requiring an endpoint client installation, while still supporting SAML/MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide local administrative credentials to the vendor over phone support
Why it's wrong here
Incorrect. Sharing admin credentials violates all security best practices.
- ✓
Deploy GlobalProtect Clientless VPN portals combined with SAML-based MFA and strict application-level URL filtering
Why this is correct
Correct. Clientless VPN provides secure access for unmanaged devices via browser portals with MFA and strict controls.
- ✗
Send pre-configured full-tunnel IPsec client software via unencrypted email attachments
Why it's wrong here
Incorrect. Full-tunnel VPN on unmanaged devices without posture checks violates Zero Trust.
- ✗
Block third-party vendors entirely with no access options under any circumstances
Why it's wrong here
Incorrect. Business requirements often dictate vendor access; blocking outright without evaluation is poor architecture.
About these practice questions
This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.