PSE-SASE · Question #79
An organization wants to adopt a Zero Trust Network Access (ZTNA) model for enhanced security across its network, especially for protecting cloud applications and branch office connectivity. Which…
The correct answer is C. Integration with ZTNA 2.0 through Prisma Access. C is correct because Prisma SD-WAN achieves ZTNA by integrating with Prisma Access, which is Palo Alto Networks' cloud-delivered security service that natively provides ZTNA 2.0 - covering continuous trust verification, least-privileged access, and deep inspection of all…
Question
An organization wants to adopt a Zero Trust Network Access (ZTNA) model for enhanced security across its network, especially for protecting cloud applications and branch office connectivity. Which specific feature of Prisma SD-WAN should be recommended to this organization?
Options
- ATraditional perimeter security measures
- BCloudBlades API for ZTNA 2.0 to protect the cloud applications
- CIntegration with ZTNA 2.0 through Prisma Access
- DZTNA 2.0 plug-in to integrate with the branch firewall
How the community answered
(26 responses)- A4% (1)
- B15% (4)
- C73% (19)
- D8% (2)
Explanation
C is correct because Prisma SD-WAN achieves ZTNA by integrating with Prisma Access, which is Palo Alto Networks' cloud-delivered security service that natively provides ZTNA 2.0 - covering continuous trust verification, least-privileged access, and deep inspection of all sessions, including cloud apps and branch connectivity.
Why the distractors are wrong:
- A (Traditional perimeter security) is the opposite of Zero Trust; ZTNA explicitly replaces the "trust everything inside the perimeter" model.
- B (CloudBlades API for ZTNA 2.0) - CloudBlades is Prisma SD-WAN's API framework for third-party integrations; it is not itself the ZTNA 2.0 solution and is not the recommended path for ZTNA deployment.
- D (ZTNA 2.0 plug-in to integrate with branch firewall) - Prisma SD-WAN does not use a standalone plug-in to bolt ZTNA onto a branch firewall; the integration is at the platform level via Prisma Access, not a firewall plug-in.
Memory tip: Think "SD-WAN + Prisma Access = ZTNA 2.0" - Prisma SD-WAN handles the underlay/overlay network, while Prisma Access handles security enforcement. They pair together like a highway (SD-WAN) with security checkpoints (Prisma Access), not standalone firewalls or APIs.
Topics
Community Discussion
No community discussion yet for this question.