PSE-SASE · Question #69
Which solution will help a prospective customer reach their private applications without having to manage IPsec tunnels?
The correct answer is C. ZTNA Connector. ZTNA Connector enables prospective customers to securely access private applications without managing IPsec tunnels by acting as a lightweight agent deployed near the application that establishes outbound connections to the ZTNA broker - no inbound firewall rules or tunnel…
Question
Which solution will help a prospective customer reach their private applications without having to manage IPsec tunnels?
Options
- ACloud Access Security Broker (CASB)
- BExplicit Proxy
- CZTNA Connector
- DService Connection
How the community answered
(53 responses)- A2% (1)
- B2% (1)
- C89% (47)
- D8% (4)
Explanation
ZTNA Connector enables prospective customers to securely access private applications without managing IPsec tunnels by acting as a lightweight agent deployed near the application that establishes outbound connections to the ZTNA broker - no inbound firewall rules or tunnel configuration required on the customer side.
- A (CASB) is wrong because CASB governs cloud application usage and data security policy, not private application access.
- B (Explicit Proxy) is wrong because it routes web traffic through a proxy server but doesn't solve private app access and still requires network-level configuration.
- D (Service Connection) is wrong because Service Connections (in platforms like Prisma Access) are used to connect your own data centers to the SASE fabric - they require IPsec or GRE tunnel setup, which is exactly what the question says to avoid.
Memory tip: Think "Connector = connect without complexity" - the ZTNA Connector does the heavy lifting so the customer never touches a tunnel. If the question mentions avoiding IPsec or simplifying private app access for external users, ZTNA Connector is the answer.
Topics
Community Discussion
No community discussion yet for this question.