NetSec-Architect Zero Trust Architecture And Design Practice Question
An architect is designing security policy optimization for a Prisma Access deployment protecting remote workers. Security rules have grown organically over five years, resulting in thousands of shadowed and redundant rules. Which feature within Panorama's Policy Optimizer should the architect use to safely identify and convert legacy port-based rules into App-ID based Zero Trust policies without disrupting production business applications?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Panorama Policy Optimizer to analyze unused rules, view recommended App-IDs for port-based rules, and stage rule conversions
Policy Optimizer in Panorama allows administrators to view unused rules, shadowed rules, and gives specific App-ID adoption recommendations based on traffic seen on the firewall, enabling safe migration to Layer 7 policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Panorama Policy Optimizer to analyze unused rules, view recommended App-IDs for port-based rules, and stage rule conversions
Why this is correct
Correct. Policy Optimizer is specifically designed to analyze existing rules, suggest App-IDs, and track adoption progress for Zero Trust migration.
- ✗
Delete all rules older than one year and create a single wildcard 'any-any' allow rule with WildFire enabled
Why it's wrong here
Incorrect. This violates all core principles of Zero Trust and drastically reduces security posture.
- ✗
Enable strict pre-rules on Panorama that automatically drop any traffic matching application-default without human intervention
Why it's wrong here
Incorrect. Automatically dropping traffic without analysis will cause widespread business application outages.
- ✗
Run theACC (Application Command Center) to manually export all traffic logs into CSV format and rewrite rules via CLI scripts
Why it's wrong here
Incorrect. ACC is for visibility, and manual script rewriting is error-prone and does not leverage native Policy Optimizer workflows.
About these practice questions
One of 228 original NetSec-Architect practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.