Cybersecurity-Apprentice · domain
Network Security
Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Network Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Network Security
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Network Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Network Security questions (32)
Click any question to see the full explanation, or start a practice session above.
An administrator observes that specific internal users are bypassing security policies by utilizing unauthorized tunneling applications disguised as standard web traffic. Which PAN-OS feature should be used to identify and block these hidden application tunnels?
Hard2A network administrator needs to verify whether a specific security policy rule is matching incoming traffic during a live troubleshooting session. Which CLI command provides real-time packet evaluation against the security rulebase?
Hard3An administrator needs to configure a Palo Alto Networks firewall to prevent unauthorized outbound traffic by restricting users to only access approved internal web applications. Which security control should be implemented in the Security policy?
Easy4A security analyst notices that internal hosts are resolving domains associated with known command and control (C2) servers. Which profile should be attached to the Security policy rule to automatically block this DNS-based threat?
Medium5Which security control is primarily responsible for inspecting decrypted web traffic for known viruses, trojans, and worms entering the network?
Easy6An enterprise requires remote access users to connect securely via GlobalProtect. Which TWO authentication methods are natively supported by PAN-OS for verifying GlobalProtect user credentials? (Choose two)
Medium7An administrator configures high availability (HA) active/passive mode between two identical firewall models. What happens to active sessions when a failover occurs if 'Session Synchronization' is enabled?
Medium8A security engineer notices that a specific vulnerability signature is generating false positives for a critical internal custom application. What is the recommended way to prevent this signature from blocking the application without disabling the entire vulnerability profile?
Medium9Which THREE components are required to successfully configure an SSL Forward Proxy decryption policy on a PAN-OS firewall? (Choose three)
Medium10An organization is adopting a Zero Trust architecture. Which foundational principle must be applied to all network traffic traversing the Palo Alto Networks firewall?
Easy11An administrator is configuring Zone Protection Profiles on a Palo Alto Networks firewall. Which THREE types of network-layer attacks can be mitigated using this profile? (Choose three)
Hard12An administrator wants to dynamically block connections from IP addresses published on a trusted third-party threat feed. Which feature should be used to ingest this feed into firewall policies?
Medium13An administrator needs to troubleshoot why a specific user is unable to access an internal application mapped via User-ID. Which TWO tools or commands can verify User-ID mapping status? (Choose two)
Hard14A company requires remote workers to establish a secure tunnel back to the corporate data center using GlobalProtect. Which component authenticates the users before assigning an IP address pool?
Medium15An administrator wants to protect a server farm from TCP SYN flood attacks. Which security control should be deployed on the external ingress zone?
Easy16An administrator wants to configure High Availability (HA) Active/Passive on two firewalls. Which THREE prerequisites must be verified before enabling HA? (Choose three)
Medium17An administrator wants to restrict administrative access to the firewall GUI so that only members of the 'Domain Admins' group can log in using their Active Directory credentials. Which authentication method should be configured?
Medium18A network administrator needs to prioritize VoIP traffic over bulk file transfers using QoS on a PAN-OS firewall. Where must the QoS profile be applied to shape the traffic effectively?
Hard19An administrator configures a Security policy rule to block access to known malicious websites categorized by PAN-DB. Which profile must be attached to the rule?
Easy20Which TWO actions can a Security policy rule execute when traffic matches the rule criteria? (Choose two)
Easy21An administrator is reviewing security logs and notices several sessions marked as 'App-ID' change mid-session from 'unknown-tcp' to a specific application like 'ssl' or 'web-browsing'. Which TWO mechanisms explain this behavior? (Choose two)
Hard22An administrator is designing a Zero Trust network architecture on a Palo Alto Networks firewall. Which TWO best practices should be implemented in the Security policy rulebase? (Choose two)
Medium23An administrator needs to ensure that users cannot upload sensitive corporate data containing specific credit card patterns to external cloud storage. Which security profile meets this requirement?
Medium24An administrator configures a WildFire analysis profile and attaches it to a Security policy rule. Under what condition does the firewall forward a sample to the WildFire cloud?
Medium25An administrator wants to inspect HTTPS traffic originating from an internal network segment without triggering certificate warnings on user browsers. What is the mandatory deployment prerequisite on the Palo Alto Networks firewall?
Hard26An administrator is troubleshooting a scenario where internal clients cannot establish connections to a newly published public web server hosted behind the firewall using its public NAT IP. What common firewall misconfiguration causes this behavior?
Hard27A security auditor reports that internal administrative sessions to firewall management interfaces are vulnerable to downgrade attacks and weak cipher suites. Where should an administrator modify the settings to enforce secure TLS versions and strong ciphers for management access?
Hard28An administrator needs to monitor traffic and generate logs without blocking packets when evaluating a new application rule. Which TWO actions or logging configurations should be applied? (Choose two)
Medium29An administrator is configuring External Dynamic Lists (EDLs) in PAN-OS. Which THREE list types are natively supported for import into the firewall? (Choose three)
Hard30An organization deploys a Palo Alto Networks firewall in 'Virtual Wire' mode. How does this deployment mode process incoming Ethernet frames?
Easy31Which object type should an administrator create in PAN-OS to group multiple internal server IP addresses together for simplified Security policy management?
Easy32An administrator observes that CPU utilization on the dataplane is spiking due to extensive regular expression inspections in security profiles. Which feature can be leveraged to optimize inspection performance on supported hardware models?
HardOther domains
All Cybersecurity-Apprentice exam domains
Frequently asked questions
- What does the Network Security domain cover on the Cybersecurity-Apprentice exam?
- Network Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 32 Network Security questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Network Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.