NetSec-Architect Practice Question: Centralized Management And Security Automation AT Scale
An architect is troubleshooting an automated workflow where Cortex XSOAR attempts to quarantine a compromised host by registering an IP address to a Dynamic Address Group on Panorama. The API returns a success code, but the firewall does not apply the security rule action. Which THREE potential issues should the architect investigate? (Choose three)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that Panorama has successfully pushed the updated Dynamic Address Group policy configuration to the managed firewalls.
When DAG tagging succeeds via API but policy enforcement fails, potential issues include tag name mismatches between registration and security rules, the firewall not receiving the dynamic object updates, or the security rule not referencing the correct DAG.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the physical firewall chassis has active power redundancy on both power supply units.
Why it's wrong here
Power supplies do not impact logical User-ID tag matching.
- ✗
Ensure that the BGP routing table on the core switch is advertising the quarantined IP address.
Why it's wrong here
Quarantining via DAG is a firewall security policy function, not a BGP routing operation.
- ✓
Confirm that Panorama has successfully pushed the updated Dynamic Address Group policy configuration to the managed firewalls.
Why this is correct
If the security rule referencing the DAG hasn't been committed and pushed to the firewall, traffic matching will not occur.
- ✓
Check that the target firewall is successfully receiving User-ID updates and communicating with Panorama/User-ID agents.
Why this is correct
Firewalls must receive the tag-to-IP mapping updates to evaluate traffic against the DAG.
- ✓
Verify that the tag name used in the User-ID API registration exactly matches the tag specified in the Dynamic Address Group object configuration.
Why this is correct
Tag names are case-sensitive and must match identically between the registration call and the DAG definition.
About these practice questions
This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.