Courseiva
Specialized Security DomainsmediumMultiple ChoiceObjective-mapped

NetSec-Architect Specialized Security Domains Practice Question

An OT security architect needs to ensure that unauthorized remote access tools (such as unauthorized TeamViewer or RDP sessions) cannot be used by third-party vendors to access sensitive industrial control networks. Which security profile should be configured to detect and control these specific remote desktop applications?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A Security policy rule blocking specific remote-access App-IDs (e.g., teamviewer, ms-rdp) combined with User-ID and authentication enforcement.

App-ID identifies specific applications like TeamViewer and RDP, and Security policy rules combined with App-ID allow granular control or blocking of these tools. Additionally, Anti-Spyware or custom App-ID decoders can restrict specific behaviors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A Data Loss Prevention profile set to block screen scraping.

    Why it's wrong here

    DLP does not block application connection setup sessions.

  • A Zone Protection profile dropping TCP SYN floods on port 3389.

    Why it's wrong here

    Zone Protection guards against floods, not authorized/unauthorized RDP application usage.

  • An SSL Decryption profile configured to drop non-compliant certificates.

    Why it's wrong here

    Decryption controls SSL visibility, not application classification of RDP tools.

  • A Security policy rule blocking specific remote-access App-IDs (e.g., teamviewer, ms-rdp) combined with User-ID and authentication enforcement.

    Why this is correct

    Blocking specific remote access App-IDs in Security policy rules prevents unauthorized remote desktop tools from operating.

About these practice questions

This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.