Courseiva

Certified Network Security Analyst (NetSec-Analyst) (NetSec-Analyst) — Questions 76150

181 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
Multi-Selecthard

Which THREE items are required for a valid QoS policy match?

Select 3 answers
A.NAT policy status
B.App-ID or IP address
C.Security profile
D.Source/Destination zones
E.Ingress interface
AnswersB, D, E

Classifier is required.

Why this answer

QoS policies match on the ingress interface, source/destination zone, and the traffic classifier (App-ID/IP).

77
Multi-Selecthard

Which THREE pieces of information are displayed on the firewall Dashboard by default?

Select 3 answers
A.System Resources (CPU/Memory).
B.Active Threat Activity.
C.Individual user session details.
D.General Information (serial, version, etc.).
E.Raw traffic packet hex dumps.
AnswersA, B, D

This is a core widget on the default dashboard.

Why this answer

The Dashboard is designed to provide high-level health and security metrics, including system status and threat activity.

78
MCQmedium

You are migrating configurations to Strata Cloud Manager. What is the benefit of using Snippets?

A.They allow for reusable configuration templates across device groups
B.They are only for firewall hardware settings
C.They automatically detect viruses
D.They replace the need for security policies
AnswerA

Snippets provide modularity and reusability.

Why this answer

Snippets allow for the creation of reusable configuration templates that can be pushed to multiple device groups.

79
MCQmedium

Which component is required to enable User-ID integration with Microsoft Active Directory using the Windows-based User-ID Agent?

A.GlobalProtect
B.A dedicated User-ID Agent
C.XML API
D.Syslog server
AnswerB

The agent is the standard method for collecting logs from AD.

Why this answer

The User-ID Agent acts as a bridge between the Active Directory domain controller and the PAN-OS firewall.

80
MCQeasy

What is the purpose of the 'Zone' field in an Address Object?

A.It defines the IP range
B.It binds the object to a specific zone for policy context
C.It is not used in address objects
D.It defines the service port
AnswerB

This is its purpose.

Why this answer

The Zone field links an address object to a specific security zone, helping the firewall identify valid traffic paths.

81
MCQmedium

Which object type should be used when you want to group several address objects together?

A.Service Group
B.Zone
C.Interface
D.Address Group
AnswerD

This is the correct object type.

Why this answer

An 'Address Group' allows for grouping multiple address objects for easier policy management.

82
MCQmedium

An administrator wants to automate the deployment of security policy updates across 50 branch firewalls using Strata Cloud Manager. Which feature should they use?

A.Device Groups
B.Templates
C.API Key Management
D.Dynamic Address Groups
AnswerA

Device groups are the standard way to group firewalls for shared security policies.

Why this answer

Device groups allow for the grouping of firewalls so that policies can be pushed to all members simultaneously from SCM.

83
MCQmedium

What is the primary difference between a 'Service' object and an 'App-ID' in a security policy?

A.App-ID is L7, Service is L4
B.Service is L7, App-ID is L4
C.They are identical
D.App-ID is port-based
AnswerA

Correct distinction.

Why this answer

Service objects match based on static ports (L4), while App-ID matches based on traffic behavior and signature analysis (L7).

84
MCQeasy

Where are objects typically defined in Strata Cloud Manager to be available for use across multiple firewalls?

A.In the global global settings only
B.At the Device Group level
C.On the local firewall only
D.They cannot be shared
AnswerB

Device groups are the containers for shared objects.

Why this answer

Objects defined at the Device Group level are available to all firewalls within that group and its child groups.

85
MCQmedium

An administrator wants to verify that a specific security policy rule is hitting traffic. Which tool should they use?

A.Rule Hit Count
B.Packet Capture
C.Threat Logs
D.System Logs
AnswerA

Hit counts directly show how often a policy rule has matched traffic.

Why this answer

The Policy Optimizer and the hit count feature in the Security Policy rule list are designed to track how often a rule matches traffic.

86
MCQmedium

An administrator needs to manage multiple NGFWs from a single interface using Strata Cloud Manager. Which task must be performed first to enable centralized policy management?

A.Configure an external dynamic list for device grouping.
B.Assign a valid license key to the firewall locally.
C.Enable Panorama mode on the NGFW local CLI.
D.Register the firewall serial number in Strata Cloud Manager.
AnswerD

Onboarding the device via its serial number is the mandatory first step for SCM integration.

Why this answer

To manage devices in Strata Cloud Manager, the firewalls must be onboarded using the serial number and assigned to a device group within the SCM portal.

87
MCQmedium

When configuring a firewall for Strata Cloud Manager, which connectivity requirement must be met?

A.The firewall must be in transparent mode.
B.The management interface must be on a public IP address.
C.SNMP must be enabled on all interfaces.
D.The firewall must have outbound access to SCM via HTTPS.
AnswerD

SCM requires outbound HTTPS communication from the firewall.

Why this answer

The firewall must be able to reach specific Palo Alto Networks cloud service URLs to establish a connection to SCM.

88
Multi-Selectmedium

What information can you see in the object list view in SCM? (Choose THREE)

Select 3 answers
A.Real-time traffic volume
B.Object Type
C.Object Name
D.User password
E.Assigned Tags
AnswersB, C, E

Correct.

Why this answer

The object list view typically shows the name, type, and associated tags for each object.

89
MCQmedium

An administrator wants to permit traffic based on a specific User-ID group. Where should this group be referenced in the Security Policy?

A.Application
B.Service
C.Source User
D.Destination Address
AnswerC

This is the location for user/group matching.

Why this answer

The 'Source User' field in the security policy is where groups are added to permit/deny traffic.

90
MCQeasy

Where can an administrator view the current version of the App-ID database installed on a firewall?

A.Monitor > Logs > System
B.Dashboard > System Resources
C.Device > Dynamic Updates
D.Network > GlobalProtect > Status
AnswerC

This page displays the current version and release date of dynamic update packages.

Why this answer

The Device > Dynamic Updates page lists the versions of all installed dynamic updates, including Applications, Threats, and WildFire.

91
Multi-Selecthard

Which THREE resources should an administrator use to stay updated on security advisories and product changes?

Select 3 answers
A.Official PAN-OS Documentation site.
B.Customer Support Portal (CSP) news.
C.Random IT forums on the internet.
D.Palo Alto Networks Security Advisories page.
E.The local system logs.
AnswersA, B, D

The definitive source for feature changes.

Why this answer

Official Palo Alto Networks resources include the Security Advisories page, the Customer Support Portal, and the official documentation site.

92
Multi-Selecthard

Which THREE criteria are used to determine which security policy rule a packet matches?

Select 3 answers
A.QoS class
B.Source Zone
C.NAT rule
D.Destination Zone
E.Source Address
AnswersB, D, E

Zones are the first differentiator.

Why this answer

The firewall matches packets based on source zone, destination zone, and source/destination addresses in a specific order defined in the policy base.

93
MCQeasy

You are configuring a Security policy to allow web traffic. Why should you place the most specific rules at the top of the Security policy list?

A.To reduce the size of the rulebase configuration file.
B.To improve hardware CPU performance.
C.To ensure the most specific criteria are matched before a broader rule captures the traffic.
D.To comply with the zone-based architecture requirements.
AnswerC

Policies are evaluated top-down and stop at the first match.

Why this answer

Palo Alto Networks firewalls evaluate policies from top to bottom and stop at the first match.

94
Multi-Selecthard

Which THREE conditions must be met for a NAT policy to be successfully applied to an incoming packet?

Select 3 answers
A.Source Zone match
B.QoS marking must be set
C.Destination Zone match
D.Destination Address match
E.User-ID must be enabled
AnswersA, C, D

NAT policy requires the source zone to be correct.

Why this answer

NAT policy matches require a match on the source zone, destination zone, and destination address (or service) to correctly translate the packet.

95
MCQmedium

An administrator wants to verify that a specific Threat Prevention profile is applied to a security rule. Where is the most accurate place to check this?

A.Policies > Security > [Rule] > Actions
B.Objects > Security Profiles
C.Monitor > Threat
D.Device > Setup
AnswerA

This is where profile assignment is configured for the rule.

Why this answer

Within the Security Policy rule definitions, each rule has a dedicated 'Actions' tab where the Profile Group or specific profile is mapped.

96
Multi-Selectmedium

Which TWO items can be managed or configured within the Device > Setup > Services tab?

Select 2 answers
A.GlobalProtect portal settings.
B.DNS server settings.
C.NTP server configuration.
D.Interface MTU settings.
E.Security policy rules.
AnswersB, C

DNS is a standard setting in the Services tab.

Why this answer

Services configuration covers essential network-level connectivity functions like DNS and NTP.

97
MCQmedium

When configuring App-ID, how does the firewall identify traffic?

A.By deep packet inspection and protocol analysis
B.Only by IP address
C.Only by port
D.By user identity only
AnswerA

This is the core App-ID mechanism.

Why this answer

App-ID uses packet inspection (signatures, heuristics, and protocol decoders) to identify applications.

98
MCQhard

If an administrator forgets the password for the 'admin' account, how can it be recovered?

A.Use the 'Reset Password' button on the login screen.
B.Reboot into maintenance mode and follow the recovery sequence.
C.Contact TAC for a universal override password.
D.Factory reset the device.
AnswerB

This is the standard, secure procedure for password recovery.

Why this answer

On newer PAN-OS versions, password recovery involves using the 'maintenance' mode during boot, which requires physical console access.

99
MCQeasy

What is the function of the 'Commit' operation regarding objects?

A.It deletes the object
B.It saves the object to the disk
C.It pushes the configuration changes to the data plane
D.It creates the object
AnswerC

Commit makes changes active.

Why this answer

Objects created in the configuration are only active and enforced on the firewall after a 'Commit' is performed.

100
MCQhard

You are migrating policies to Strata Cloud Manager. You notice that an Address Object is being used in a security policy, but the object is defined at the 'Device Group' level. What happens if you try to use this object in a policy at a higher hierarchy level?

A.The policy will automatically push the object to the parent level.
B.The object will be unavailable for selection in the higher-level policy.
C.The object will be converted to a local override.
D.The firewall will generate a shadow error during commit.
AnswerB

Inheritance flows downwards, not upwards.

Why this answer

Objects defined at lower levels (Device Groups) are not visible to policies at higher levels (Global/Parent).

101
Multi-Selectmedium

Which TWO log types can be forwarded to an external collector from a Palo Alto firewall?

Select 2 answers
A.Keyboard input logs.
B.Hardware diagnostic sensor readings.
C.Traffic logs.
D.BIOS boot sequences.
E.Threat logs.
AnswersC, E

Traffic logs are commonly forwarded for analysis.

Why this answer

The firewall supports forwarding various log types including Traffic, Threat, System, and URL logs.

102
MCQhard

In a multi-vsys environment, how do you manage shared objects?

A.You must define the object in the 'Shared' scope
B.You must copy the object to each vsys
C.Objects cannot be shared across vsys
D.Use a tag to share them
AnswerA

The 'Shared' scope makes them available to all vsys.

Why this answer

Objects can be defined as 'Shared' to make them available across all virtual systems on the firewall.

103
Multi-Selectmedium

Which TWO items are considered 'Objects' in the PAN-OS environment?

Select 2 answers
A.Service objects
B.User names
C.Security zones
D.Address objects
E.Policy rules
AnswersA, D

Correct.

Why this answer

Addresses, services, and application groups are all examples of objects that can be referenced in policies.

104
MCQhard

A user is accessing an application, but the traffic is logged as 'unknown-udp'. What is the recommended way to secure this without allowing all UDP traffic?

A.Disable all UDP traffic
B.Use a Service object for the port
C.Allow all UDP traffic
D.Create a custom App-ID
AnswerD

Best practice for custom traffic identification.

Why this answer

Create a custom App-ID that identifies the traffic pattern, or if it is a standard custom service, use an Application Override if you have identified the port/protocol, but a custom App-ID is the best way to keep L7 visibility.

105
MCQeasy

Which feature allows you to group multiple Address Objects together to simplify Security Policy management?

A.Tagging
B.Address Object Registry
C.Address Group
D.Snippet
AnswerC

Address Groups serve the purpose of aggregating address objects.

Why this answer

Address Groups allow administrators to bundle multiple individual address objects into a single logical entity.

106
MCQmedium

Which object category is used to group various network services to simplify policy definitions?

A.Service Group
B.Tag Group
C.Address Group
D.Profile Group
AnswerA

Service groups contain services.

Why this answer

Service Groups are used to bundle individual service objects together.

107
MCQeasy

Which menu path in the NGFW GUI allows an administrator to view the status of all active security subscriptions?

A.Device > Licenses
B.Device > Setup > Management
C.Policies > Security > Subscriptions
D.Network > Interfaces > Global
AnswerA

This page displays the current licensing status for all software and services.

Why this answer

The Device > Licenses page provides a comprehensive view of all active subscriptions, their expiration dates, and activation status.

108
Multi-Selecthard

Which of the following are true regarding Dynamic Address Groups? (Choose TWO)

Select 2 answers
A.They do not require a commit to update membership
B.They must be manually updated
C.They are populated based on tag-based filters
D.They are slower than static groups
E.They only support IPv6
AnswersA, C

Correct for the DAG member list, though policy changes usually require a commit.

Why this answer

DAGs use tags to determine membership and are updated dynamically without a full commit in many modern PAN-OS versions.

109
MCQmedium

When an administrator sees 'incomplete' in the Application column of the traffic logs, what does this usually signify?

A.The application is unknown
B.The rule was denied
C.The session closed before App-ID could be determined
D.The traffic is encrypted
AnswerC

This is the standard definition of 'incomplete' sessions.

Why this answer

Incomplete means the firewall did not see enough packets to successfully identify the application (e.g., the session closed too early).

110
MCQmedium

What is the primary function of a Security Profile Group in the context of object creation?

A.To create dynamic address filters
B.To group firewall interfaces
C.To group multiple security profiles for policy application
D.To define user access levels
AnswerC

This simplifies policy management.

Why this answer

Security Profile Groups bundle multiple individual security profiles (e.g., Antivirus, Anti-Spyware, Vulnerability Protection) into a single object for easier policy assignment.

111
MCQhard

A firewall is reporting 'License Expired' for Threat Prevention. The administrator renewed the license in the Support Portal. What is the most likely cause for the warning to persist?

A.The firewall needs a firmware upgrade.
B.The license server is down.
C.The administrator has not clicked 'Retrieve license keys from license server'.
D.The Threat Prevention license is not compatible with the current PAN-OS version.
AnswerC

The firewall does not pull the new status automatically unless the command is initiated.

Why this answer

Often, the firewall has not yet synced its local database with the updated information on the Palo Alto Networks license server.

112
MCQeasy

Which type of account is typically used to manage Palo Alto Networks assets in the Customer Support Portal?

A.Default 'admin' account
B.Strata Cloud Manager admin account
C.Customer Support Portal account
D.Local Administrator account
AnswerC

The CSP is the central portal for all Palo Alto Networks hardware and software assets.

Why this answer

A Customer Support Portal (CSP) account allows users to view registered assets, manage licenses, and open support tickets.

113
Multi-Selecthard

Which THREE factors can impact the performance of a firewall during a log-intensive period?

Select 3 answers
A.Congested log forwarding network.
B.The color of the firewall chassis.
C.High volume of log generation.
D.Management plane resource exhaustion.
E.The type of ethernet cable used.
AnswersA, C, D

Bottlenecks here can cause log backups.

Why this answer

High traffic volume, logging to external servers (slow network), and management plane saturation can all impact performance.

114
Multi-Selecthard

Which THREE CLI commands help in diagnosing routing issues?

Select 3 answers
A.show session info
B.show system info
C.show network arp
D.show routing route
E.test routing fib-lookup
AnswersC, D, E

Verifies neighbor connectivity.

Why this answer

These commands show the routing table, specific route resolution, and ARP table/neighbor status.

115
MCQmedium

A user is unable to access a web application. The security policy log shows the traffic is hitting the default 'deny' rule. What is the most effective way to troubleshoot the App-ID identification?

A.Check the Threat Log
B.Analyze the Traffic Log for the specific session
C.Restart the management plane
D.Clear the session table
AnswerB

The traffic log shows the App-ID that was detected, helping identify if a policy needs an update.

Why this answer

Checking the Traffic Log and looking at the 'App-ID' column shows what the firewall identified the traffic as; if it shows 'incomplete' or 'unknown-tcp', that identifies the issue.

116
MCQhard

How can an administrator ensure that only specific IP addresses can access the firewall management interface?

A.By configuring an Allowed IP list in the Management Interface settings.
B.By using a static route.
C.By adding an explicit Deny policy in the security policy list.
D.By enabling MFA on the local admin account.
AnswerA

This restricts management access to trusted source IPs.

Why this answer

Management Interface Settings (in Device > Setup) allow for the definition of an allowed IP address list for management access.

117
MCQhard

An administrator is unable to add an object to a specific Device Group. What is the most likely reason?

A.The firewall is in maintenance mode
B.The object is already in use
C.The object is inherited from a parent device group
D.The object name contains invalid characters
AnswerC

Inherited objects are read-only in child groups.

Why this answer

If the object is defined in a parent Device Group, it is read-only in the child Device Group; it cannot be modified there.

118
MCQeasy

What is the purpose of the 'Zone' in a Palo Alto Networks firewall?

A.To identify applications
B.To route traffic
C.To group interfaces for security enforcement
D.To group IP addresses
AnswerC

Zones are for interface grouping.

Why this answer

Zones are logical groupings of interfaces that allow for granular security policy enforcement.

119
MCQmedium

What is the difference between 'Candidate Configuration' and 'Running Configuration'?

A.Candidate is what is live; Running is what was last saved.
B.There is no difference.
C.Candidate contains pending changes; Running is currently active.
D.Candidate is a backup; Running is for active edits.
AnswerC

This is the correct distinction between the two states.

Why this answer

The candidate configuration is the set of pending changes that have not yet been applied, while the running configuration is what is currently active.

120
MCQmedium

Which object type would you use to define a range of IP addresses (e.g., 10.1.1.1 to 10.1.1.50) in PAN-OS?

A.IP Netmask
B.FQDN
C.IP Range
D.Address Group
AnswerC

The IP Range object allows defining a start and end IP.

Why this answer

An IP Range object is specifically designed to cover a non-CIDR block range of IP addresses.

121
MCQeasy

Which of the following is considered an operational task performed via the firewall Dashboard?

A.Updating the App-ID database.
B.Defining a security policy rule.
C.Creating an address object.
D.Monitoring system resource utilization.
AnswerD

System resource monitoring is a primary function of the Dashboard.

Why this answer

The Dashboard provides a real-time overview of system health, active threats, and interface status.

122
MCQhard

If an administrator creates an object in a local firewall that is also managed by SCM, what happens during the next push?

A.The push will fail
B.The object will be overwritten by the SCM configuration
C.The object is preserved
D.The object is merged
AnswerB

SCM policies override local configs.

Why this answer

SCM push operations typically overwrite local configuration changes to ensure that the centrally managed policy remains the source of truth.

123
MCQmedium

How can an administrator quickly determine if the firewall is experiencing high CPU usage?

A.Check the Traffic Logs.
B.Use the 'show interface' CLI command.
C.View the Dashboard System Resources widget.
D.Monitor the Threat logs.
AnswerC

This is the standard way to monitor hardware health.

Why this answer

The Dashboard provides a 'System Resources' widget that shows real-time CPU and memory usage statistics.

124
MCQeasy

Which log would display an event regarding an administrator logging into the WebUI?

A.Threat Log
B.Config Log
C.Traffic Log
D.System Log
AnswerD

System logs record events like logins, config changes, and system errors.

Why this answer

Configuration and administrative access logs are stored in the System log.

125
MCQmedium

When configuring an FQDN object, how frequently does the firewall refresh the DNS resolution?

A.Every 5 minutes
B.Only during a manual commit
C.Every 24 hours
D.Based on the TTL of the DNS record
AnswerD

The firewall respects the TTL.

Why this answer

The firewall automatically refreshes FQDN objects based on the TTL returned by the DNS server.

126
MCQhard

An administrator attempts to commit configuration changes from SCM to a firewall, but the commit fails due to an 'invalid reference'. What is the most effective way to troubleshoot this?

A.Force a firmware reinstall.
B.Review the Task Manager logs for error details.
C.Delete all current policies and re-import.
D.Restart the firewall management plane.
AnswerB

Task Manager contains specific error codes and descriptions for failed commits.

Why this answer

The 'Task Manager' in the SCM or the firewall GUI provides detailed logs about why a commit operation failed, including specific invalid references.

127
MCQhard

A DHCP server configured on the firewall is not assigning IPs to clients. Which tool is best to troubleshoot the DHCP relay/server process?

A.debug dhcp
B.show network interface
C.show system stats
D.Packet capture on the interface
AnswerA

This is the dedicated debugging tool for DHCP-related issues on the firewall.

Why this answer

The 'debug dhcp' commands allow the administrator to see the DHCP request/offer process in the logs.

128
MCQmedium

If an administrator wants to ensure that a specific server can only be accessed from a specific internal subnet, where is this best configured?

A.Decryption Policy
B.NAT Policy
C.Security Policy
D.QoS Policy
AnswerC

Security policies are for traffic filtering.

Why this answer

The Security Policy is the correct place to enforce source-to-destination-to-application access control.

129
Multi-Selecthard

Which THREE actions occur when a 'Commit' is executed on a firewall?

Select 3 answers
A.Updating the running configuration file.
B.Applying changes to the data plane.
C.Automatically upgrading the PAN-OS version.
D.Configuration syntax validation.
E.Purging all existing log entries.
AnswersA, B, D

The config is written to the active store.

Why this answer

The commit process validates the syntax, saves the configuration file, and applies the changes to the system's data plane.

130
Multi-Selecteasy

Which TWO log types are stored on the Palo Alto Networks firewall locally?

Select 2 answers
A.Threat Log
B.Traffic Log
C.Cloud Logging
D.Panorama Log
E.External Syslog
AnswersA, B

Local storage.

Why this answer

Traffic and Threat logs are the most common logs stored locally by default.

131
Multi-Selecthard

Which THREE types of dynamic updates are managed in the Device > Dynamic Updates menu?

Select 3 answers
A.WildFire signatures.
B.Applications (App-ID).
C.Routing protocol updates (BGP/OSPF).
D.Threats (Antivirus, IPS).
E.PAN-OS firmware images.
AnswersA, B, D

WildFire updates are a primary dynamic update type.

Why this answer

Dynamic updates allow the firewall to stay current with evolving threats and application definitions.

132
Multi-Selecthard

Which THREE components are required for an Application Override policy?

Select 3 answers
A.User Group
B.Protocol and Port
C.Application name
D.QoS profile
E.Source and Destination Zone
AnswersB, C, E

The specific port/protocol must be defined.

Why this answer

Application Override requires the source zone, destination zone, protocol, port, and the custom application name to bypass standard App-ID detection.

133
MCQeasy

Where do you configure custom tags for use in your security policies?

A.Device tab
B.Policies tab
C.Objects tab
D.Network tab
AnswerC

This is the location for tags.

Why this answer

Tags are created and managed within the 'Objects' tab under the 'Tags' section.

134
Multi-Selectmedium

Which TWO of the following settings must be verified to ensure successful SSL Decryption?

Select 2 answers
A.SSL Decryption Policy
B.CA Certificate trust
C.GlobalProtect configuration
D.Client-side browser cache
E.App-ID database version
AnswersA, B

Required to trigger decryption.

Why this answer

Successful decryption requires both a valid CA certificate and the appropriate SSL decryption policy enabled.

135
MCQhard

A policy rule is configured for 'web-browsing' and 'ssl', but the traffic is being dropped. The logs indicate the application is 'google-base'. What is the most appropriate fix?

A.Change the service to 'any'
B.Disable App-ID
C.Create an Application Override
D.Add 'google-base' to the policy
AnswerD

The policy must explicitly include the identified application.

Why this answer

Since 'google-base' is a distinct App-ID from 'web-browsing', the policy must either be updated to include 'google-base' or use an application filter.

136
MCQhard

When deploying a new firewall, why is it critical to synchronize the clock with an NTP server?

A.To ensure the license server accepts the activation.
B.To ensure accurate log timestamps and SSL certificate validation.
C.To prevent unauthorized access to the web interface.
D.To allow for faster software downloads.
AnswerB

Time skew causes major issues with certificate chains and log ordering.

Why this answer

Accurate system time is essential for correct logging, certificate validation, and threat detection timing.

137
MCQmedium

Which CLI command is used to verify the current status of the high availability (HA) pair?

A.show ha status
B.show high-availability state
C.show system ha
D.show system info
AnswerB

Provides the HA mode, state, and peer info.

Why this answer

The 'show high-availability state' command provides the current operational status and role of each firewall in the HA pair.

138
MCQmedium

Which configuration setting in a security policy rule is responsible for matching users based on their active directory group?

A.Application
B.Source User
C.Source Address
D.Service
AnswerB

This is for group matching.

Why this answer

The 'Source User' field allows you to select Active Directory groups to match traffic coming from those specific users.

139
MCQeasy

When troubleshooting a connection, an administrator sees 'aged-out' in the session table. What does this indicate?

A.The session is currently active
B.The session was terminated by a TCP RST packet
C.The session was blocked by a threat profile
D.The session timed out due to inactivity
AnswerD

Aged-out indicates the inactivity timer expired.

Why this answer

Aged-out means the session was closed by the firewall because no traffic was seen for that session for a duration exceeding the timeout value.

140
MCQeasy

Which configuration menu allows you to define an address object?

A.Objects > Addresses
B.Device > Setup
C.Network > Interfaces
D.Policies > Security
AnswerA

This is the correct path.

Why this answer

Address objects are defined under 'Objects' > 'Addresses'.

141
MCQmedium

You need to define a service for a protocol that uses both TCP and UDP on the same port. How can you represent this?

A.Create one object with 'TCP/UDP' selected
B.Create two objects and put them in a Service Group
C.This is not possible
D.Use an application object instead
AnswerB

Bundling in a Service Group is the correct approach.

Why this answer

Because PAN-OS service objects are protocol-specific, you must create two separate service objects (one TCP, one UDP) and add them to a Service Group.

142
MCQhard

An administrator needs to perform NAT for a server that is in a DMZ but accessed via the public internet. Which NAT rule type is used for this?

A.Destination NAT
B.Source NAT
C.Dynamic NAT
D.Static NAT
AnswerA

Destination NAT is for inbound traffic.

Why this answer

Destination NAT is used to allow inbound access from the internet to an internal server by mapping a public address to a private one.

143
MCQhard

An administrator is configuring a high-availability (HA) pair. Which step is essential to ensure consistent configuration across both firewalls?

A.Manually copy the config file to both units.
B.Install two separate licenses.
C.Use a load balancer.
D.Enable 'Configuration Sync' in the HA settings.
AnswerD

Syncing is the required feature for HA configuration management.

Why this answer

Configuring HA requires setting up synchronization, which ensures that the configuration is automatically shared between the active and passive units.

144
MCQmedium

What happens if a packet matches multiple security policies?

A.It is dropped automatically
B.It matches the first one in the list
C.It matches the last one
D.It matches all of them
AnswerB

Policy order is top-down.

Why this answer

The firewall evaluates policies from top to bottom and matches the first rule that criteria apply to.

145
Multi-Selectmedium

Which TWO options describe valid ways to handle traffic that is identified as 'unknown-tcp' in a security policy?

Select 2 answers
A.Use an Application Override policy
B.Change the zone to 'Internal'
C.Disable NAT
D.Create a custom App-ID
E.Enable QoS on the interface
AnswersA, D

Application Override can force the firewall to identify traffic by port/protocol.

Why this answer

Unknown traffic can be explicitly allowed, dropped, or managed via an Application Override policy to identify it as a custom app.

146
MCQmedium

Which of the following describes an 'Address Object'?

A.A named representation of an IP address or subnet
B.A list of users
C.A grouping of applications
D.A hardware port
AnswerA

Correct definition.

Why this answer

An address object is a reusable entity that represents a single IP, a range of IPs, or a subnet.

147
Multi-Selecthard

Which THREE criteria can be used to filter traffic logs in the Monitor tab?

Select 3 answers
A.Destination port.
B.Power supply voltage.
C.CPU temperature.
D.Application name.
E.Source IP address.
AnswersA, D, E

Port filtering is a standard and essential feature.

Why this answer

The Monitor tab provides powerful filtering tools, allowing administrators to narrow down logs by specific fields like source IP, destination port, or application.

148
MCQhard

An administrator configured a security policy with an App-ID of 'web-browsing' and 'ssl', but users cannot access a specific internal portal. The logs show 'ssl' and 'web-browsing' are matched, but the session is dropped. What is the likely cause?

A.The policy lacks the 'web-searching' application dependency
B.The application dependency 'web-browsing' is not sufficient for 'ssl'
C.The zone protection profile is blocking the traffic
D.The session requires allowing the dependent application explicitly
AnswerD

Many applications have implicit dependencies that must be added to the policy for the traffic to pass.

Why this answer

The firewall requires 'web-browsing' and 'ssl' to be in the policy, but if the application has dependencies, those must also be explicitly allowed.

149
Multi-Selecthard

Which THREE items are required to successfully register a new firewall in the Customer Support Portal?

Select 3 answers
A.A list of all connected switch ports.
B.Valid Customer Support Portal account.
C.The public SSH key of the firewall.
D.Hardware serial number.
E.Registration authorization code.
AnswersB, D, E

Necessary to link the device to a user.

Why this answer

Registration requires the hardware serial number, the registration authorization code, and a valid account.

150
Multi-Selecthard

Which THREE of the following are valid methods for registering tags to IP addresses to populate Dynamic Address Groups?

Select 3 answers
A.Assigning the tag directly to the interface in the Network tab.
B.Configuring the VM-Series to monitor cloud provider metadata.
C.Creating a custom App-ID that identifies the traffic.
D.Using the User-ID agent to map IP-to-Tag relationships.
E.Using the XML API to send a registration request.
AnswersB, D, E

Cloud integration allows automatic tag registration based on instance metadata.

Why this answer

DAGs are populated by external entities or specific internal processes that register tags.

Page 1

Page 2 of 3

Page 3

All pages