NETSEC Pro Practice Exam — 78 Free Palo Alto Networks Questions
QuestionQ1
Palo Alto Networks Network Security Overview
Save question
When a rule is configured to block the upload of all Portable Executable (PE) files, which log type displays blocked files that attempt to pass through the network?
ATraffic
BData filtering
CURL filtering
DThreat
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Palo Alto Networks Network Security Overview
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Entry-Level Maintenance, Configuration, Installation, and Deployment
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Palo Alto Networks Network Security Overview
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Palo Alto Networks Network Security Overview
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Which two features can a network administrator use to troubleshoot a Prisma Access mobile user issue in which the user cannot access SaaS applications?
Choose two
AAutonomous Digital Experience Manager (ADEM) console
BCapacity Analyzer
CGlobal Protect logs
DSaaS Application Risk Portal
A primary firewall in a high-availability (HA) pair is currently experiencing a failover issue involving ICMP pings to the secondary device.
Which metric should be reviewed to ensure proper ICMP pings between the firewall pair?
ANon-functional state
BBidirectional Forwarding Detection (BFD)
CLink monitoring
DHeartbeat polling
How does Strata Logging Service help address the continually growing log-retention requirements of a company that uses Prisma Access?
ALog traffic using the licensed bandwidth purchased for Prisma Access reduces overhead.
BAutomatic selection of physical data storage regions decreases adoption time.
CIt scales to meet the capacity needs of new locations as business grows.
DIt increases resilience due to decentralized collection and storage of logs.
In what order of precedence is App-ID evaluated and determined?
A
ACE cloud2. Content-based3. Custom
B
Custom2. ACE cloud3. Content-based
C
Content-based2. Custom3. ACE cloud
D
Custom2. Content-based3. ACE cloud
QuestionQ6
Palo Alto Networks Network Security Overview
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ8
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ9
Palo Alto Networks Network Security Overview
QuestionQ10
Palo Alto Networks Network Security Overview
QuestionQ11
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ12
Palo Alto Networks Network Security Overview
QuestionQ13
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ14
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ15
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ16
Palo Alto Networks Network Security Overview
QuestionQ17
Palo Alto Networks Network Security Overview
QuestionQ18
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ19
Palo Alto Networks Network Security Overview
QuestionQ20
Palo Alto Networks Network Security Overview
QuestionQ21
Palo Alto Networks Network Security Overview
QuestionQ22
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ23
Entry-Level Maintenance, Configuration, Installation, and Deployment
QuestionQ24
Palo Alto Networks Network Security Overview
QuestionQ25
Entry-Level Maintenance, Configuration, Installation, and Deployment
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which two frameworks does the Compliance Summary dashboard in Strata Cloud Manager (SCM) compare?
Choose two
AGDPR
BNIST
CPCI-DSS
DCIS
When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, at what point can the firewall be powered on?
ADuring license activation
BAfter activating registration and completing license deployment profile
CAfter all required installation and setup procedures are completed
DDuring installation
Which two tools can be used to configure Cloud NGFWs for AWS?
Choose two
APrisma Cloud management console
BCortex XSIAM
CCloud service provider (CSP) management console
DPanorama
An administrator is setting up a new Enterprise DLP policy to standardize the data loss prevention (DLP) strategy across the full infrastructure, including physical NGFWs and Prisma Access.
Regarding profile configuration, what is the main benefit of this approach?
AEach NGFW and Prisma Access gateway requires its own locally defined DLP profile.
BA single data profile is created in the cloud and applied consistently across enforcement points.
CThe NGFW profile is first exported and then imported into the Prisma Access configuration.
DProfiles are created on Panorama and synced securely to a separate cloud instance for Prisma Access.
Which security profile delivers real-time protection against threat actors that exploit DNS-infrastructure misconfigurations and redirect traffic to malicious domains?
AIntelligent Run-time Memory Analysis
BMachine learning (ML)
CDynamic analysis
DStatic analysis
What is a required step when creating a custom Prisma Access report in Strata Cloud Manager (SCM)?
AOpen a support ticket.
BConfigure a dashboard.
CGenerate a PDF summary report.
DSet up Cloud Identity Engine.
How does a firewall operate when SSL Inbound Inspection is enabled?
AIt decrypts inbound and outbound SSH connections.
BIt acts as meddler-in-the-middle between the client and the internal server.
CIt acts transparently between the client and the internal server.
DIt decrypts traffic between the client and the external server.
How are Cloud NGFW instances created when using AWS centralized deployments?
AA security VPC will be created as transit gateways to push all traffic through the area.
BThey are placed in a vWAN with a virtual hub.
CSelected VPCs will have Cloud NGFW workloads added to them.
DThey replace the internet gateway service.
Which two content updates can Panorama push to NGFWs?
Choose two
AWildFire
BApplications and threats
CAdvanced URL Filtering
DGlobalProtect data file
What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?
A9.1 --> 11.2
B9.1 --> 11.0 --> 11.2
C9.1 --> 10.0 --> 11.0 --> 11.2
D9.1 --> 10.0 --> 11.0 --> 11.1 --> 11.2
Which profile can help stop sensitive information from being transmitted to internet applications?
AAntivirus
BData Filtering
CAnti-spyware
DURL Filtering
As part of implementing Zero Trust, a security team has finished defining its micro-perimeters and writing all initial context-based Security policy rules. It is now concentrating on collecting and analyzing logs to confirm that the policies work as intended.
Which step in the Palo Alto Networks five-step methodology is the team performing now?
AMonitor and Maintain Your Network
BArchitect a Zero Trust Network
CMap Your Transaction Flows
DDefine Your Attack Surface
A network security engineer must implement segmentation but is subject to strict compliance requirements that place security enforcement as close as possible to the private applications hosted in Azure.
Which deployment style is valid and satisfies the requirements in this scenario?
AOn a PA-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.
BOn a VM-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.
COn a VM-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.
DOn a PA-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.
In which security profile is the DNS sinkholing action enabled?
AFile Blocking
BAntivirus
CAnti-spyware
DDoS Protection
Which function does an NGFW use to decide whether new session-establishment attempts are legitimate or illegitimate?
ASYN bit
BSYN flood protection
CSYN cookies
DRandom Early Detection (RED)
Which firewall attribute makes rule creation easier and automatically adjusts to changes in server roles or security posture based on log events?
ADynamic Address Groups
BDynamic User Groups
CPredefined IP addresses
DAddress objects
After associating a firewall with Strata Cloud Manager (SCM), which two additional actions are required to enable management of the firewall through SCM?
Choose two
AInstall a device certificate.
BConfigure a Security policy allowing "stratacloudmanager.paloaltonetworks.com" for all users.
CConfigure NTP and DNS servers for the firewall.
DDeploy a service connection for each branch site and connect with SCM.
When physical ION devices are allocated, which two states are shown for them in the Prisma SD-WAN web interface under Devices?
Choose two
AOffline
BStandby
CUnclaimed
DNeeds attention
Why is a packet processed through the slow path on an NGFW?
AIt does not require application identification or user identification.
BIt is part of an already established session.
CIt is part of a new or unestablished session.
DIt only needs basic NAT and Security policy enforcement.
An administrator created a security profile group that contains the organization’s standard Antivirus, Anti-Spyware, and Vulnerability Protection profiles. This particular group must be applied by default to every new security rule created in Prisma Access.
What step is required for the group to be automatically attached to new rules?
APlace the group at the top of the security profile groups list.
BIn the Prisma Access settings, specify the group as “Default Security Group”.
CName the security profile group “default”.
DName each individual profile within the group “default”.
Community Discussion