Practice Cybersecurity-Practitioner Network Security questions with full explanations on every answer.
Start practicing
Network Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization wants to inspect encrypted outbound HTTPS traffic to detect malware without causing certificate warnings on user workstations. Which component must be installed on the client endpoints to achieve this?
2A firewall is deployed in an environment with asymmetric routing. Packets belonging to the same TCP session enter on different interfaces due to multi-path upstream routing. What configuration change is required on the Palo Alto Networks firewall to prevent the traffic from being dropped?
3An administrator needs to configure a security rule that applies specifically to traffic destined for a DMZ web server using its public NAT IP address (Destination NAT). Which IP address must be specified in the Destination field of the Security policy rule?
4An administrator configures a dynamic address group (DAG) based on User-ID tags, but security rules referencing this DAG fail to match traffic from users who have successfully authenticated via GlobalProtect. What is the most likely root cause?
5An administrator configures a Security policy rule to block all file-sharing applications. However, users are still able to upload files using an authorized cloud collaboration tool that shares the same parent application family. Which feature should the administrator use to granularly block file uploads while permitting standard document viewing?
6An administrator needs to restrict access to malicious command-and-control (C2) domains. Which security profile should be attached to the outbound Security policy rules to inspect and block this traffic?
7An administrator configures an external dynamic list (EDL) pointing to a URL hosting a plain-text list of malicious IP addresses. The firewall successfully downloads the EDL, but security rules referencing this EDL fail to block traffic to those IPs. Inspection reveals that the EDL entries are showing as 'parsing error' in the system logs. What is the most likely cause of this issue?
8An administrator wants to ensure that critical database servers are protected against vulnerability exploits, SQL injections, and buffer overflows. Which security profile must be applied to the relevant Security policy rule to provide this protection?
9An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard signatures. The administrator wants to configure WildFire inline machine learning to block this zero-day threat in real-time. Which feature must be enabled and configured?
10An administrator is reviewing the Palo Alto Networks firewall traffic logs and sees a session marked with the application 'unknown-tcp'. What does this application classification typically indicate?
11An administrator configures high availability (HA) active/passive mode between two Palo Alto Networks firewalls. During a failover test, the administrator observes that stateful sessions are dropped, forcing users to re-authenticate and re-establish their TCP connections. What is the most likely configuration error?
12An administrator configures a QoS profile to prioritize VoIP traffic over bulk data transfers. However, after applying the profile, VoIP packets are still experiencing high latency during peak business hours. Inspection shows that the QoS profile is applied correctly to the security rules, but the packets are not being placed into the correct QoS class. What is missing in the interface configuration?
13An administrator wants to prevent users from accessing specific URL categories such as 'gambling' and 'adult' while allowing all other business-related sites. Where should this restriction be configured?
14An administrator configures a decryption policy to 'No Decrypt' for financial institution websites to comply with privacy regulations. However, the firewall is still decrypting traffic to certain banking sites. Upon investigation, the administrator discovers that the firewall is matching a pre-defined PAN-OS SSL Decryption Exclusion list. How can the administrator override or modify this behavior?
15An administrator deploys User-ID using Palo Alto Networks User-ID Agent on a Windows Server. Users report that after logging off their workstations, the firewall continues to attribute their web traffic to them for up to 45 minutes. How can the administrator reduce this timeout duration?
16An administrator needs to configure a Palo Alto Networks firewall interface to connect to an untrusted ISP router. Which interface type is appropriate for this connection?
17An administrator is configuring a Destination NAT rule to forward inbound web traffic from the internet to an internal web server. The administrator notices that when internal users try to access the web server using its public IP address (Hairpinning/NAT Loopback), the connection fails. What additional rule is required to support NAT Loopback?
18An administrator is troubleshooting a BGP routing peer connection between the Palo Alto Networks firewall and an external provider router. The BGP session is stuck in the 'Connect' state. Inspection of system logs indicates TCP port 179 packets sent by the firewall are being transmitted, but no SYN-ACK is received. Which troubleshooting step or feature verification should be performed first?
19An administrator wants to view real-time session information, including source/destination ports, translated IPs, and matched security rules, for active traffic flowing through the firewall. Which CLI command should the administrator execute?
20An administrator is configuring security policies on a Palo Alto Networks firewall and wants to ensure best practices for rule organization and management. Which TWO practices are recommended when designing security rules? (Choose two)
21An administrator configures a decryption exclusion based on the 'Pre-defined SSL Decryption Exclusions' list. However, an internal audit reveals that a specific sensitive medical portal is still being intercepted and decrypted. The portal uses certificate pinning and a non-standard port (TCP 8443). How can the administrator ensure this specific traffic is never decrypted?
22An administrator is troubleshooting a scenario where internal clients cannot resolve external domain names through the firewall configured as a DNS proxy. Which TWO settings should be verified on the firewall? (Choose two)
23An administrator notices that the firewall's management plane CPU utilization is consistently at 99%. Which THREE factors or troubleshooting steps should the administrator investigate? (Choose three)
24An administrator configures a dynamic update schedule for Antivirus and WildFire signatures. The firewall successfully downloads the updates, but fails to install them automatically. Where should the administrator check to verify and configure the installation schedule settings in PAN-OS?
25An administrator needs to configure Active Directory-based User-ID mapping without installing a dedicated User-ID agent on a Windows Server. Which TWO methods are natively supported by PAN-OS for agentless user mapping? (Choose two)
26An administrator is troubleshooting a high availability (HA1) heartbeat failure between two firewall peers. Which THREE configuration or physical items should be checked? (Choose three)
27An administrator is configuring a complex network environment with multiple virtual routers and needs to ensure proper routing and path selection. Which THREE statements regarding Palo Alto Networks virtual routers are accurate? (Choose three)
28An administrator wants to configure Zone Protection Profiles to safeguard the internal network against common layer 2 and layer 3 attacks. Which THREE attack mitigation features are available within a Zone Protection Profile? (Choose three)
29An administrator wants to secure outbound web browsing traffic by inspecting HTTP/HTTPS traffic for malicious URLs, malware, and exploits. Which TWO security profiles should be attached to the Security policy rule to achieve comprehensive protection? (Choose two)
30An administrator needs to implement authentication for administrative access to the Palo Alto Networks firewall using an external RADIUS server. Which TWO components must be configured on the firewall to achieve this? (Choose two)
31An administrator is configuring Source NAT (SNAT) and wants to understand how translation addresses are allocated when using Dynamic IP and Port (DIPP). Which TWO characteristics describe DIPP behavior on Palo Alto Networks firewalls? (Choose two)
32An administrator needs to configure a Palo Alto Networks firewall to decrypt inbound SSL traffic destined for a public-facing web server. Which type of Decryption rule must be created?
33A security administrator is troubleshooting an issue where internal users cannot reach a specific external website, and the traffic is being dropped by the firewall. The administrator suspects a Threat Prevention profile is blocking the response as a command-and-control callback. Where should the administrator look to verify the exact threat signature ID and packet capture that triggered the block?
34A network engineer has deployed an active/passive HA pair of PA-5220 firewalls. During a routine failover test, the engineer notices that existing TCP sessions are dropped and must be re-established. Which feature should be enabled to prevent session disruption during failover?
35An administrator wants to ensure that critical server traffic is always prioritized over standard guest internet traffic during periods of network congestion. Which feature should be configured?
36An administrator configures a Security policy rule with an application dependency on 'ssl', but the target application is 'custom-app'. When committing the configuration, the firewall generates a warning or error regarding application dependencies. What is the correct way to handle application dependencies in Palo Alto Networks firewalls?
37An administrator is designing a high-availability network using Panorama and Palo Alto Networks firewalls. Which TWO tasks can be performed directly by Panorama regarding firewall management and deployment? (Choose two)
38An administrator needs to prevent known malware and spyware from entering the network through downloaded files and web traffic. Which security profile type should be attached to the Security policy rule?
39Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)
40An administrator is configuring Zone Protection profiles to mitigate potential network attacks. Which TWO flood protection mechanisms are available within a Zone Protection profile? (Choose two)
The Network Security domain covers the key concepts tested in this area of the Cybersecurity-Practitioner exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cybersecurity-Practitioner domains — no account required.
The Courseiva Cybersecurity-Practitioner question bank contains 40 questions in the Network Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included