Cybersecurity-Practitioner · domain
Network Security
Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Network Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Network Security
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Network Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Network Security questions (40)
Click any question to see the full explanation, or start a practice session above.
An organization wants to inspect encrypted outbound HTTPS traffic to detect malware without causing certificate warnings on user workstations. Which component must be installed on the client endpoints to achieve this?
Easy2An administrator notices that the firewall's management plane CPU utilization is consistently at 99%. Which THREE factors or troubleshooting steps should the administrator investigate? (Choose three)
Hard3An administrator wants to ensure that critical database servers are protected against vulnerability exploits, SQL injections, and buffer overflows. Which security profile must be applied to the relevant Security policy rule to provide this protection?
Medium4An administrator configures an external dynamic list (EDL) pointing to a URL hosting a plain-text list of malicious IP addresses. The firewall successfully downloads the EDL, but security rules referencing this EDL fail to block traffic to those IPs. Inspection reveals that the EDL entries are showing as 'parsing error' in the system logs. What is the most likely cause of this issue?
Hard5An administrator needs to configure Active Directory-based User-ID mapping without installing a dedicated User-ID agent on a Windows Server. Which TWO methods are natively supported by PAN-OS for agentless user mapping? (Choose two)
Medium6An administrator configures a decryption exclusion based on the 'Pre-defined SSL Decryption Exclusions' list. However, an internal audit reveals that a specific sensitive medical portal is still being intercepted and decrypted. The portal uses certificate pinning and a non-standard port (TCP 8443). How can the administrator ensure this specific traffic is never decrypted?
Hard7An administrator configures a dynamic address group (DAG) based on User-ID tags, but security rules referencing this DAG fail to match traffic from users who have successfully authenticated via GlobalProtect. What is the most likely root cause?
Hard8An administrator is troubleshooting a high availability (HA1) heartbeat failure between two firewall peers. Which THREE configuration or physical items should be checked? (Choose three)
Hard9An administrator needs to configure a Palo Alto Networks firewall interface to connect to an untrusted ISP router. Which interface type is appropriate for this connection?
Easy10Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)
Hard11An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard signatures. The administrator wants to configure WildFire inline machine learning to block this zero-day threat in real-time. Which feature must be enabled and configured?
Hard12An administrator wants to prevent users from accessing specific URL categories such as 'gambling' and 'adult' while allowing all other business-related sites. Where should this restriction be configured?
Easy13An administrator needs to configure a Palo Alto Networks firewall to decrypt inbound SSL traffic destined for a public-facing web server. Which type of Decryption rule must be created?
Easy14An administrator wants to configure Zone Protection Profiles to safeguard the internal network against common layer 2 and layer 3 attacks. Which THREE attack mitigation features are available within a Zone Protection Profile? (Choose three)
Hard15An administrator configures a QoS profile to prioritize VoIP traffic over bulk data transfers. However, after applying the profile, VoIP packets are still experiencing high latency during peak business hours. Inspection shows that the QoS profile is applied correctly to the security rules, but the packets are not being placed into the correct QoS class. What is missing in the interface configuration?
Hard16An administrator is configuring Zone Protection profiles to mitigate potential network attacks. Which TWO flood protection mechanisms are available within a Zone Protection profile? (Choose two)
Medium17An administrator is troubleshooting a BGP routing peer connection between the Palo Alto Networks firewall and an external provider router. The BGP session is stuck in the 'Connect' state. Inspection of system logs indicates TCP port 179 packets sent by the firewall are being transmitted, but no SYN-ACK is received. Which troubleshooting step or feature verification should be performed first?
Hard18An administrator configures a Security policy rule with an application dependency on 'ssl', but the target application is 'custom-app'. When committing the configuration, the firewall generates a warning or error regarding application dependencies. What is the correct way to handle application dependencies in Palo Alto Networks firewalls?
Hard19An administrator wants to view real-time session information, including source/destination ports, translated IPs, and matched security rules, for active traffic flowing through the firewall. Which CLI command should the administrator execute?
Easy20A firewall is deployed in an environment with asymmetric routing. Packets belonging to the same TCP session enter on different interfaces due to multi-path upstream routing. What configuration change is required on the Palo Alto Networks firewall to prevent the traffic from being dropped?
Medium21An administrator is configuring security policies on a Palo Alto Networks firewall and wants to ensure best practices for rule organization and management. Which TWO practices are recommended when designing security rules? (Choose two)
Medium22An administrator needs to restrict access to malicious command-and-control (C2) domains. Which security profile should be attached to the outbound Security policy rules to inspect and block this traffic?
Easy23An administrator configures a Security policy rule to block all file-sharing applications. However, users are still able to upload files using an authorized cloud collaboration tool that shares the same parent application family. Which feature should the administrator use to granularly block file uploads while permitting standard document viewing?
Easy24A security administrator is troubleshooting an issue where internal users cannot reach a specific external website, and the traffic is being dropped by the firewall. The administrator suspects a Threat Prevention profile is blocking the response as a command-and-control callback. Where should the administrator look to verify the exact threat signature ID and packet capture that triggered the block?
Medium25An administrator is troubleshooting a scenario where internal clients cannot resolve external domain names through the firewall configured as a DNS proxy. Which TWO settings should be verified on the firewall? (Choose two)
Medium26An administrator configures a decryption policy to 'No Decrypt' for financial institution websites to comply with privacy regulations. However, the firewall is still decrypting traffic to certain banking sites. Upon investigation, the administrator discovers that the firewall is matching a pre-defined PAN-OS SSL Decryption Exclusion list. How can the administrator override or modify this behavior?
Hard27An administrator configures high availability (HA) active/passive mode between two Palo Alto Networks firewalls. During a failover test, the administrator observes that stateful sessions are dropped, forcing users to re-authenticate and re-establish their TCP connections. What is the most likely configuration error?
Medium28An administrator deploys User-ID using Palo Alto Networks User-ID Agent on a Windows Server. Users report that after logging off their workstations, the firewall continues to attribute their web traffic to them for up to 45 minutes. How can the administrator reduce this timeout duration?
Medium29An administrator is reviewing the Palo Alto Networks firewall traffic logs and sees a session marked with the application 'unknown-tcp'. What does this application classification typically indicate?
Easy30A network engineer has deployed an active/passive HA pair of PA-5220 firewalls. During a routine failover test, the engineer notices that existing TCP sessions are dropped and must be re-established. Which feature should be enabled to prevent session disruption during failover?
Medium31An administrator needs to prevent known malware and spyware from entering the network through downloaded files and web traffic. Which security profile type should be attached to the Security policy rule?
Easy32An administrator is configuring Source NAT (SNAT) and wants to understand how translation addresses are allocated when using Dynamic IP and Port (DIPP). Which TWO characteristics describe DIPP behavior on Palo Alto Networks firewalls? (Choose two)
Medium33An administrator is configuring a Destination NAT rule to forward inbound web traffic from the internet to an internal web server. The administrator notices that when internal users try to access the web server using its public IP address (Hairpinning/NAT Loopback), the connection fails. What additional rule is required to support NAT Loopback?
Medium34An administrator is configuring a complex network environment with multiple virtual routers and needs to ensure proper routing and path selection. Which THREE statements regarding Palo Alto Networks virtual routers are accurate? (Choose three)
Hard35An administrator configures a dynamic update schedule for Antivirus and WildFire signatures. The firewall successfully downloads the updates, but fails to install them automatically. Where should the administrator check to verify and configure the installation schedule settings in PAN-OS?
Medium36An administrator needs to configure a security rule that applies specifically to traffic destined for a DMZ web server using its public NAT IP address (Destination NAT). Which IP address must be specified in the Destination field of the Security policy rule?
Easy37An administrator needs to implement authentication for administrative access to the Palo Alto Networks firewall using an external RADIUS server. Which TWO components must be configured on the firewall to achieve this? (Choose two)
Medium38An administrator is designing a high-availability network using Panorama and Palo Alto Networks firewalls. Which TWO tasks can be performed directly by Panorama regarding firewall management and deployment? (Choose two)
Medium39An administrator wants to secure outbound web browsing traffic by inspecting HTTP/HTTPS traffic for malicious URLs, malware, and exploits. Which TWO security profiles should be attached to the Security policy rule to achieve comprehensive protection? (Choose two)
Easy40An administrator wants to ensure that critical server traffic is always prioritized over standard guest internet traffic during periods of network congestion. Which feature should be configured?
EasyOther domains
All Cybersecurity-Practitioner exam domains
Frequently asked questions
- What does the Network Security domain cover on the Cybersecurity-Practitioner exam?
- Network Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 40 Network Security questions in the Cybersecurity-Practitioner question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Network Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.