nerdexam
Palo_Alto_Networks

PSE-SASE · Question #5

What is a benefit of a cloud-based secure access service edge (SASE) infrastructure over a Zero Trust Network Access (ZTNA) product based on a software-defined perimeter (SDP) model?

The correct answer is A. Users, devices, and apps are identified no matter where they connect from. SASE's defining advantage is its cloud-native architecture, which enforces identity-aware access for users, devices, and applications regardless of their physical location - because the policy engine lives in the cloud, not tied to a perimeter. ZTNA/SDP solutions also use…

SASE Architecture and Concepts

Question

What is a benefit of a cloud-based secure access service edge (SASE) infrastructure over a Zero Trust Network Access (ZTNA) product based on a software-defined perimeter (SDP) model?

Options

  • AUsers, devices, and apps are identified no matter where they connect from.
  • BConnection to physical SD-WAN hubs in ther locations provides increased interconnectivity
  • CComplexity of connecting to a gateway is increased, providing additional protection.
  • DVirtual private network (VPN) services are used for remote access to the internal data center, but

How the community answered

(37 responses)
  • A
    84% (31)
  • B
    8% (3)
  • C
    5% (2)
  • D
    3% (1)

Explanation

SASE's defining advantage is its cloud-native architecture, which enforces identity-aware access for users, devices, and applications regardless of their physical location - because the policy engine lives in the cloud, not tied to a perimeter. ZTNA/SDP solutions also use identity verification, but they tend to be narrower in scope (focused on specific app access) and may still rely on on-premises components, whereas SASE natively extends consistent policy enforcement across web, cloud, and private-app traffic from any location.

Why the distractors are wrong:

  • B is wrong because SASE is explicitly cloud-based and moves away from physical SD-WAN hubs - physical hubs belong to legacy WAN architectures.
  • C is wrong because increased complexity is never a security benefit; SASE actually reduces connection complexity by consolidating security functions in the cloud.
  • D is wrong because SASE is specifically designed to replace VPN-based remote access, not continue using it.

Memory tip: Think of SASE as "security that travels with the user" - since it lives in the cloud, it follows any user, device, or app anywhere. The keyword in the question is "cloud-based": that's what enables the universal identity enforcement in option A that a more localized SDP/ZTNA product can't match at the same scale.

Topics

#SASE vs ZTNA#SDP model#cloud-based security#identity-based access

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice