Courseiva

Cybersecurity-Apprentice · domain

Network Security

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

32 questions8 easy13 medium11 hard

Focused practice

Practice Network Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Network Security

Network Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Network Security questions (32)

Click any question to see the full explanation, or start a practice session above.

1

An administrator observes that specific internal users are bypassing security policies by utilizing unauthorized tunneling applications disguised as standard web traffic. Which PAN-OS feature should be used to identify and block these hidden application tunnels?

Hard
2

A network administrator needs to verify whether a specific security policy rule is matching incoming traffic during a live troubleshooting session. Which CLI command provides real-time packet evaluation against the security rulebase?

Hard
3

An administrator needs to configure a Palo Alto Networks firewall to prevent unauthorized outbound traffic by restricting users to only access approved internal web applications. Which security control should be implemented in the Security policy?

Easy
4

A security analyst notices that internal hosts are resolving domains associated with known command and control (C2) servers. Which profile should be attached to the Security policy rule to automatically block this DNS-based threat?

Medium
5

Which security control is primarily responsible for inspecting decrypted web traffic for known viruses, trojans, and worms entering the network?

Easy
6

An enterprise requires remote access users to connect securely via GlobalProtect. Which TWO authentication methods are natively supported by PAN-OS for verifying GlobalProtect user credentials? (Choose two)

Medium
7

An administrator configures high availability (HA) active/passive mode between two identical firewall models. What happens to active sessions when a failover occurs if 'Session Synchronization' is enabled?

Medium
8

A security engineer notices that a specific vulnerability signature is generating false positives for a critical internal custom application. What is the recommended way to prevent this signature from blocking the application without disabling the entire vulnerability profile?

Medium
9

Which THREE components are required to successfully configure an SSL Forward Proxy decryption policy on a PAN-OS firewall? (Choose three)

Medium
10

An organization is adopting a Zero Trust architecture. Which foundational principle must be applied to all network traffic traversing the Palo Alto Networks firewall?

Easy
11

An administrator is configuring Zone Protection Profiles on a Palo Alto Networks firewall. Which THREE types of network-layer attacks can be mitigated using this profile? (Choose three)

Hard
12

An administrator wants to dynamically block connections from IP addresses published on a trusted third-party threat feed. Which feature should be used to ingest this feed into firewall policies?

Medium
13

An administrator needs to troubleshoot why a specific user is unable to access an internal application mapped via User-ID. Which TWO tools or commands can verify User-ID mapping status? (Choose two)

Hard
14

A company requires remote workers to establish a secure tunnel back to the corporate data center using GlobalProtect. Which component authenticates the users before assigning an IP address pool?

Medium
15

An administrator wants to protect a server farm from TCP SYN flood attacks. Which security control should be deployed on the external ingress zone?

Easy
16

An administrator wants to configure High Availability (HA) Active/Passive on two firewalls. Which THREE prerequisites must be verified before enabling HA? (Choose three)

Medium
17

An administrator wants to restrict administrative access to the firewall GUI so that only members of the 'Domain Admins' group can log in using their Active Directory credentials. Which authentication method should be configured?

Medium
18

A network administrator needs to prioritize VoIP traffic over bulk file transfers using QoS on a PAN-OS firewall. Where must the QoS profile be applied to shape the traffic effectively?

Hard
19

An administrator configures a Security policy rule to block access to known malicious websites categorized by PAN-DB. Which profile must be attached to the rule?

Easy
20

Which TWO actions can a Security policy rule execute when traffic matches the rule criteria? (Choose two)

Easy
21

An administrator is reviewing security logs and notices several sessions marked as 'App-ID' change mid-session from 'unknown-tcp' to a specific application like 'ssl' or 'web-browsing'. Which TWO mechanisms explain this behavior? (Choose two)

Hard
22

An administrator is designing a Zero Trust network architecture on a Palo Alto Networks firewall. Which TWO best practices should be implemented in the Security policy rulebase? (Choose two)

Medium
23

An administrator needs to ensure that users cannot upload sensitive corporate data containing specific credit card patterns to external cloud storage. Which security profile meets this requirement?

Medium
24

An administrator configures a WildFire analysis profile and attaches it to a Security policy rule. Under what condition does the firewall forward a sample to the WildFire cloud?

Medium
25

An administrator wants to inspect HTTPS traffic originating from an internal network segment without triggering certificate warnings on user browsers. What is the mandatory deployment prerequisite on the Palo Alto Networks firewall?

Hard
26

An administrator is troubleshooting a scenario where internal clients cannot establish connections to a newly published public web server hosted behind the firewall using its public NAT IP. What common firewall misconfiguration causes this behavior?

Hard
27

A security auditor reports that internal administrative sessions to firewall management interfaces are vulnerable to downgrade attacks and weak cipher suites. Where should an administrator modify the settings to enforce secure TLS versions and strong ciphers for management access?

Hard
28

An administrator needs to monitor traffic and generate logs without blocking packets when evaluating a new application rule. Which TWO actions or logging configurations should be applied? (Choose two)

Medium
29

An administrator is configuring External Dynamic Lists (EDLs) in PAN-OS. Which THREE list types are natively supported for import into the firewall? (Choose three)

Hard
30

An organization deploys a Palo Alto Networks firewall in 'Virtual Wire' mode. How does this deployment mode process incoming Ethernet frames?

Easy
31

Which object type should an administrator create in PAN-OS to group multiple internal server IP addresses together for simplified Security policy management?

Easy
32

An administrator observes that CPU utilization on the dataplane is spiking due to extensive regular expression inspections in security profiles. Which feature can be leveraged to optimize inspection performance on supported hardware models?

Hard

Frequently asked questions

What does the Network Security domain cover on the Cybersecurity-Apprentice exam?
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 32 Network Security questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cybersec-apprentice PANW-CYBERSEC-APPRENTICE network security Practice Questions