Question 1
A financial services company is deploying a Zero Trust architecture. A key requirement is to ensure that only authenticated and authorized users on compliant devices can access internal applications. A security architect has configured GlobalProtect with Host Information Profile (HIP) checks and User-ID. During testing, a user on a non-compliant device is still able to access a sensitive application. The Security policy rule for this application correctly specifies the user's group. What is the most likely misconfiguration causing this policy failure?
Answer and explanation
Correct answer: B
In a Zero Trust model using GlobalProtect, enforcing device compliance requires both collecting HIP data and applying it in policy. While the Security policy rule correctly identifies the user group via User-ID, it is ineffective at checking device posture without a HIP Profile attached. The HIP Profile defines what constitutes a 'compliant' device, and adding this profile to the rule ensures that traffic will only match if both the user and the device posture criteria are met.