PSE-STRATA · Question #219
Which statement describes how Palo Alto Networks can eliminate implicit user trust, regardless of user location?
The correct answer is D. User-ID is continually monitored and validated throughout the transaction. D is correct because Palo Alto Networks implements Zero Trust by continuously monitoring and validating User-ID throughout the entire transaction - not just at the start or end. This means trust is never assumed or granted permanently; the user's identity is repeatedly…
Question
Which statement describes how Palo Alto Networks can eliminate implicit user trust, regardless of user location?
Options
- AUser-ID is only available with a valid Threat Prevention subscription
- BUser-ID is verified at the start of a transaction and is then explicitly trusted
- CUser-ID is verified at the end of a transaction and is then explicitly trusted
- DUser-ID is continually monitored and validated throughout the transaction
How the community answered
(31 responses)- A16% (5)
- B6% (2)
- C3% (1)
- D74% (23)
Explanation
D is correct because Palo Alto Networks implements Zero Trust by continuously monitoring and validating User-ID throughout the entire transaction - not just at the start or end. This means trust is never assumed or granted permanently; the user's identity is repeatedly verified, eliminating implicit trust regardless of whether they're on-premises or remote.
Why the distractors are wrong:
- A is wrong because User-ID is a core platform feature, not tied to a Threat Prevention subscription - it works independently of that license.
- B is wrong because verifying identity only at the start and then trusting the user explicitly is the old perimeter-based security model, not Zero Trust.
- C is wrong for the same reason as B, just shifted to the end - a single checkpoint (start or end) still leaves a window of implicit trust during the transaction.
Memory tip: Think of Zero Trust as a nightclub bouncer who checks your ID every time you order a drink, not just at the door. "Continual" = Zero Trust; "once and done" = old-school perimeter security.
Community Discussion
No community discussion yet for this question.