Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks NetSec-Pro Palo Alto Networks Network Security Professional Exam Practice Test

Page: 1 / 7
Total 73 questions

Palo Alto Networks Network Security Professional Questions and Answers

Question 1

How can a firewall administrator block a list of 300 unique URLs in the most time-efficient manner?

Options:

A.

Use application filters to block the App-IDs.

B.

Use application groups to block the App-IDs.

C.

Import the list into a custom URL category.

D.

Block multiple predefined URL categories.

Question 2

In a service provider environment, what key advantage does implementing virtual systems provide for managing multiple customer environments?

Options:

A.

Shared threat prevention policies across all tenants

B.

Centralized authentication for all customer domains

C.

Unified logging across all virtual systems

D.

Logical separation of control and Security policy

Question 3

In a Prisma SD-WAN environment experiencing voice quality degradation, which initial action is recommended?

Options:

A.

Immediately modify path quality thresholds.

B.

Review real-time analytics of path performance.

C.

Switch all VoIP traffic to backup paths.

D.

Request an RMA of the ION devices.

Question 4

Which Prisma Access operations are the administrator responsible for?

Options:

A.

Management plane upgrades

B.

Content updates

C.

Data plane upgrades

D.

Client upgrades

Question 5

When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?

Options:

A.

Configure port-based policies, check threat logs weekly, conduct software updates annually, and enable decryption.

B.

Configure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles to rules, and update regularly with dynamic updates.

C.

Configure all default policies provided by the firewall, use Policy Optimizer, and adjust security rules after an incident occurs.

D.

Configure a block policy for all malicious inbound traffic, configure an allow policy for all outbound traffic, and update regularly with dynamic updates.

Question 6

An NGFW administrator is updating PAN-OS on company data center firewalls managed by Panorama. Prior to installing the update, what must the administrator verify to ensure the devices will continue to be supported by Panorama?

Options:

A.

Device telemetry is enabled.

B.

Panorama is configured as the primary device in the log collecting group for the data center firewalls.

C.

All devices are in the same template stack.

D.

Panorama is running the same or newer PAN-OS release as the one being installed.

Question 7

Which functionality does an NGFW use to determine whether new session setups are legitimate or illegitimate?

Options:

A.

SYN bit

B.

SYN cookies

C.

Random Early Detection (RED)

D.

SYN flood protection

Question 8

Which two GlobalProtect modes allow partial users to access internal apps via GlobalProtect while other users access internal apps through third-party VPN?

Options:

A.

Proxy

B.

Hybrid, Proxy + Tunnel

C.

Clientless VPN only

D.

Always-On Tunnel only

Question 9

Which action optimizes user experience across a segmented network architecture and implements the most effective method to maintain secure connectivity between branch and campus locations?

Options:

A.

Establish site-to-site tunnels on each branch and campus firewall and have individual VLANs for each department.

B.

Configure all branch and campus firewalls to use a single shared broadcast domain.

C.

Implement SD-WAN to route all traffic based on network performance metrics and use zone protection profiles.

D.

Configure a single campus firewall to handle the routing of all branch traffic.

Question 10

Which configurations on hosts are supported for detection by HIP?

Options:

A.

Anti-malware

B.

Disk Encryption

C.

VLAN ID

D.

BGP peer state

Question 11

A network administrator obtains Palo Alto Networks Advanced Threat Prevention and Advanced DNS Security subscriptions for edge NGFWs and is setting up security profiles. Which step should be included in the initial configuration of the Advanced DNS Security service?

Options:

A.

Create a decryption policy rule to decrypt DNS-over-TLS / port 853 traffic.

B.

Create overrides for all company owned FQDNs.

C.

Configure DNS Security signature policy settings to sinkhole malicious DNS queries.

D.

Enable Advanced Threat Prevention with default settings and only focus on high-risk traffic.

Question 12

What is a necessary step for creation of a custom Prisma Access report on Strata Cloud Manager (SCM)?

Options:

A.

Open a support ticket.

B.

Set up Cloud Identity Engine.

C.

Generate a PDF summary report.

D.

Configure a dashboard.

Question 13

How often does the firewall retrieve signature database updates from Advanced WildFire?

Options:

A.

Real-time

B.

Within 5 to 10 minutes

C.

10 to 20 minutes

D.

Every 24 hours

Question 14

What configurations are supported for Traffic Steering of Remote Network in Prisma Access?

Options:

A.

EDL

B.

DAG, Dynamic Address Group

C.

BGP AS Path prepend only

D.

Static NAT policy only

Question 15

Which security profile provides real-time protection against threat actors who exploit the misconfigurations of DNS infrastructure and redirect traffic to malicious domains?

Options:

A.

Antivirus

B.

URL Filtering

C.

Vulnerability Protection

D.

Anti-spyware

Question 16

A network security engineer has created a Security policy in Prisma Access that includes a negated region in the source address. Which configuration will ensure there is no connectivity loss due to the negated region?

Options:

A.

Set the service to be application-default.

B.

Create a Security policy for the negated region with destination address “any”.

C.

Add a Dynamic Application Group to the Security policy.

D.

Add all regions that contain private IP addresses to the source address.

Question 17

An administrator wants to optimize the attack surface and check if configurations comply with CIS standards. Where in SCM can this function be accessed?

Options:

A.

BPA

B.

Command Center

C.

Policy Optimizer

D.

Executive Summary

Question 18

Which set of attributes is used by IoT Security to identify and classify appliances on a network when determining Device-ID?

Options:

A.

IP address, network traffic patterns, and device type

B.

MAC address, device manufacturer, and operating system

C.

Hostname, application usage, and encryption method

D.

Device model, firmware version, and user credential

Question 19

Which subscription sends non-file format-based traffic that matches Data Filtering Profile criteria to a cloud service to render a verdict?

Options:

A.

Enterprise DLP

B.

Advanced URL Filtering

C.

SaaS Security Inline

D.

Advanced WildFire

Question 20

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

Options:

A.

Cloud Identity Engine

B.

Autonomous Digital Experience Manager (ADEM)

C.

GlobalProtect agent

D.

IPSec termination node

Question 21

Which AI-powered solution provides unified management and operations for NGFWs and Prisma Access?

Options:

A.

Strata Cloud Manager (SCM)

B.

Autonomous Digital Experience Manager (ADEM)

C.

Prisma Access Browser

D.

Panorama

Page: 1 / 7
Total 73 questions