Courseiva
Zero Trust Architecture And DesignhardMultiple ChoiceObjective-mapped

NetSec-Architect Zero Trust Architecture And Design Practice Question

An architect is designing security policy optimization for a Prisma Access deployment protecting remote workers. Security rules have grown organically over five years, resulting in thousands of shadowed and redundant rules. Which feature within Panorama's Policy Optimizer should the architect use to safely identify and convert legacy port-based rules into App-ID based Zero Trust policies without disrupting production business applications?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use Panorama Policy Optimizer to analyze unused rules, view recommended App-IDs for port-based rules, and stage rule conversions

Policy Optimizer in Panorama allows administrators to view unused rules, shadowed rules, and gives specific App-ID adoption recommendations based on traffic seen on the firewall, enabling safe migration to Layer 7 policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use Panorama Policy Optimizer to analyze unused rules, view recommended App-IDs for port-based rules, and stage rule conversions

    Why this is correct

    Correct. Policy Optimizer is specifically designed to analyze existing rules, suggest App-IDs, and track adoption progress for Zero Trust migration.

  • Delete all rules older than one year and create a single wildcard 'any-any' allow rule with WildFire enabled

    Why it's wrong here

    Incorrect. This violates all core principles of Zero Trust and drastically reduces security posture.

  • Enable strict pre-rules on Panorama that automatically drop any traffic matching application-default without human intervention

    Why it's wrong here

    Incorrect. Automatically dropping traffic without analysis will cause widespread business application outages.

  • Run theACC (Application Command Center) to manually export all traffic logs into CSV format and rewrite rules via CLI scripts

    Why it's wrong here

    Incorrect. ACC is for visibility, and manual script rewriting is error-prone and does not leverage native Policy Optimizer workflows.

About these practice questions

One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.