Courseiva
Network SecurityhardMultiple SelectObjective-mapped

Cybersecurity-Practitioner Network Security Practice Question

Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable administrative services like HTTP and Telnet, utilizing HTTPS and SSH instead.

Management plane security best practices include restricting access via IP, using dedicated management interfaces, and disabling unnecessary services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable administrative services like HTTP and Telnet, utilizing HTTPS and SSH instead.

    Why this is correct

    Correct. Disabling unencrypted protocols prevents cleartext credential interception.

  • Restrict administrative access to the management interface using a dedicated Management Profile with allowed source IP addresses.

    Why this is correct

    Correct. Restricting management access sources mitigates unauthorized access risks.

  • Assign all administrative users the 'superuser' role to simplify troubleshooting.

    Why it's wrong here

    Incorrect. Role-based access control (RBAC) should be used following the principle of least privilege.

  • Configure a dedicated out-of-band management network separated from data traffic.

    Why this is correct

    Correct. Using a dedicated management network isolates administrative traffic from user data planes.

  • Enable SSHv1 and SSLv2 to ensure legacy administrative tool compatibility.

    Why it's wrong here

    Incorrect. Legacy protocols like SSHv1 and SSLv2 are insecure and should remain disabled.

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.