Courseiva

Certified Network Security Analyst (NetSec-Analyst) (NetSec-Analyst) — Questions 151181

181 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
MCQeasy

Which tab in the Palo Alto Networks GUI is primarily used to manage Security and NAT policies?

A.Objects
B.Monitor
C.Policies
D.Network
AnswerC

Policies are configured here.

Why this answer

The 'Policies' tab is the central location for managing all types of policies.

152
MCQeasy

A user reports that they cannot access a website, receiving a 'page cannot be displayed' error. Which log type should the administrator check first to see if the traffic is reaching the firewall?

A.System Log
B.URL Filtering Log
C.Traffic Log
D.Threat Log
AnswerC

The Traffic log is the first stop to verify if the firewall is receiving and processing the traffic.

Why this answer

The Traffic log tracks every session that hits the firewall, making it the primary source for connectivity troubleshooting.

153
Multi-Selectmedium

When managing objects in SCM, which actions can be performed on tags? (Choose TWO)

Select 2 answers
A.Assigning a color
B.Defining an IP range
C.Defining a port protocol
D.Applying to objects for organization
E.Creating a security policy
AnswersA, D

Correct.

Why this answer

Tags can be assigned colors and applied to various objects for organization.

154
Multi-Selectmedium

Which elements are required when creating a new custom Service Object? (Choose THREE)

Select 3 answers
A.Protocol
B.Tag
C.Port
D.Name
E.Description
AnswersA, C, D

Correct.

Why this answer

Service objects require a name, a protocol, and at least one port.

155
MCQeasy

Which of the following is NOT a valid type of address object?

A.FQDN
B.IP Netmask
C.IP Range
D.IP Protocol
AnswerD

IP Protocol is not an address object.

Why this answer

Palo Alto Networks supports IP Netmask, IP Range, and FQDN objects. IP Protocol is not an address object type.

156
MCQeasy

When creating a NAT policy, which field defines the address that the traffic will be translated to on the destination side?

A.Destination Address
B.Service Port
C.Source Address
D.Translated Address
AnswerD

This specifies the new destination IP.

Why this answer

In Destination NAT, the 'Translated Packet' section defines the destination IP address that the traffic is rewritten to.

157
Multi-Selectmedium

Which TWO of the following are benefits of using Strata Cloud Manager for enterprise firewall management?

Select 2 answers
A.Centralized visibility and reporting.
B.Reduced need for local power supplies.
C.Uniform policy distribution across device groups.
D.Automatic physical hardware replacement.
E.Increased local firewall interface speed.
AnswersA, C

SCM consolidates data for easier analysis.

Why this answer

SCM provides centralized visibility and simplified policy management across distributed environments.

158
MCQhard

Why might an Application Override policy be preferred over a Security Policy for a specific custom application?

A.To enable NAT
B.To increase security
C.To identify custom traffic that App-ID fails to detect
D.To enable QoS
AnswerC

This is the primary use case.

Why this answer

When an application is proprietary and the firewall cannot identify it using standard App-ID, an override forces the firewall to treat it as a specific 'App-ID' object, bypassing signature inspection.

159
MCQeasy

Which of the following is an example of a 'Service' object?

A.10.0.0.1
B.TCP/80
C.Marketing_Dept
D.USA_Region
AnswerB

This defines a protocol and port.

Why this answer

HTTP, HTTPS, and SSH are common services defined as objects specifying the protocol and port.

160
Multi-Selectmedium

Which TWO pieces of information must an administrator provide when setting up a Log Forwarding profile?

Select 2 answers
A.Local user account list.
B.Destination server IP address.
C.The firewall root password.
D.The physical chassis weight.
E.Log types to forward (e.g., Traffic, Threat).
AnswersB, E

The server needs to be identified.

Why this answer

Log forwarding requires identifying the destination (Syslog server) and the traffic types to be forwarded.

161
Multi-Selectmedium

Which TWO of the following are valid source types for a Security Policy?

Select 2 answers
A.QoS profile
B.Interface speed
C.Source Address
D.Source Zone
E.NAT policy
AnswersC, D

Addresses are valid.

Why this answer

Security policies can match on Source Zones and Source Address objects.

162
MCQmedium

You are designing a QoS policy. You want to prioritize VoIP traffic over bulk file transfers. Which component must you create to classify the VoIP traffic?

A.An App-ID override.
B.A QoS profile with a specific class and priority.
C.A Security policy with a QoS tag.
D.A Traffic Shaping policy.
AnswerB

QoS profiles define how traffic is treated after classification.

Why this answer

QoS profiles are applied to QoS policies to define the class and priority of the traffic.

163
Multi-Selectmedium

Which TWO of the following characteristics apply to Service Objects in Strata Cloud Manager?

Select 2 answers
A.They automatically inherit tags from the policy rule they are applied to.
B.They allow the use of port ranges, such as 1000-2000.
C.They are globally unique across all Device Groups.
D.They support the definition of both TCP and UDP ports in a single object.
E.They can be added to Service Groups to simplify policy rulebases.
AnswersB, E

Port ranges are a standard feature of service object definitions.

Why this answer

Service objects define protocol and port, and they can be grouped for easier management.

164
Multi-Selecthard

Which THREE steps are required to correctly implement User-ID mapping using the Windows-based User-ID agent?

Select 3 answers
A.Install the GlobalProtect agent on all workstations.
B.Install the User-ID agent on a Windows server.
C.Enable User-ID on the zone interface.
D.Set the firewall to use a captive portal for all users.
E.Configure the agent to monitor Security Event Logs on Domain Controllers.
AnswersB, C, E

The agent is a service installed on a Windows server.

Why this answer

The agent must be installed, configured to monitor logs, and the firewall must be told to query the agent.

165
Multi-Selectmedium

Which THREE features are associated with an 'Application Filter'?

Select 3 answers
A.Destination port
B.Technology
C.Category
D.Subcategory
E.Source IP address
AnswersB, C, D

Filter by the technology used.

Why this answer

Application Filters group applications based on category, subcategory, and technology, and these filters update automatically as new applications are added to the PAN-OS database.

166
Multi-Selecthard

What are the primary characteristics of Service Groups? (Choose TWO)

Select 2 answers
A.They are used to bundle multiple service objects
B.They are only for inbound traffic
C.They allow mixing of TCP and UDP services
D.They contain only one service
E.They must have a unique color
AnswersA, C

Correct.

Why this answer

Service Groups are used for grouping multiple services and allow for the mixing of different protocols.

167
MCQeasy

When creating a Dynamic Address Group (DAG), what is the primary prerequisite for the object to populate successfully?

A.The interface must be configured as a DHCP server.
B.The IP address must be defined as a static Address Object.
C.The IP address must have a tag associated with it via registration.
D.The object must be added to a Service Group.
AnswerC

The registration of a tag to an IP is what triggers the DAG membership.

Why this answer

DAGs rely on Tags being registered to the IP address via VM-Series monitoring, XML API, or User-ID.

168
MCQmedium

An administrator wants to schedule signature updates to occur at 3:00 AM daily. Where is this configured?

A.Policies > Security > Schedules
B.Monitor > Reports > Schedules
C.Device > Setup > Services
D.Device > Dynamic Updates
AnswerD

This is where update schedules are defined.

Why this answer

The Device > Dynamic Updates page contains the schedule settings for various update types like Applications, Threats, and WildFire.

169
MCQmedium

What is the primary purpose of a 'Device Group' in the context of SCM?

A.To group firewalls by physical location only.
B.To apply consistent security policies to multiple firewalls.
C.To manage local user authentication.
D.To manage interface settings exclusively.
AnswerB

Device groups enable centralized security policy management.

Why this answer

Device groups allow for the hierarchical grouping of firewalls for shared policy management, providing consistent security across the enterprise.

170
Multi-Selecthard

Which of the following are benefits of using Device Groups in SCM? (Choose THREE)

Select 3 answers
A.Local-only access
B.Inheritance of configuration
C.Shared object management
D.Automatic hardware replacement
E.Configuration modularity
AnswersB, C, E

Correct.

Why this answer

Device groups allow for hierarchical inheritance, shared objects, and policy modularity.

171
MCQeasy

How does an administrator perform a software update on a standalone firewall?

A.Network > Interfaces
B.Objects > Software
C.Device > Software
D.Device > Dynamic Updates
AnswerC

The Software page is where PAN-OS images are managed.

Why this answer

Software updates are managed in the Device > Software page, where you can download and install new versions of PAN-OS.

172
Multi-Selecthard

Which THREE requirements must be met to enable User-ID integration with Microsoft Active Directory?

Select 3 answers
A.Service account for the agent
B.NAT policy configuration
C.QoS priority classes
D.Group mapping configuration
E.Connectivity to the domain controller
AnswersA, D, E

Needed to query AD.

Why this answer

You need an AD service account, connectivity between the firewall/agent and the domain controller, and group mapping enabled on the firewall.

173
MCQmedium

When you define a 'Service Group', can you include both TCP and UDP services?

A.Yes, you can mix different protocols
B.Only if the firewall supports it
C.No, they must be the same protocol
D.Only if they use the same port number
AnswerA

Service groups are protocol-agnostic regarding their members.

Why this answer

Yes, Service Groups are designed to aggregate different protocols (TCP, UDP, SCTP) into a single service bundle.

174
Multi-Selectmedium

Which TWO ways can an administrator verify that a security subscription is active?

Select 2 answers
A.Via the Device > Licenses GUI page.
B.By reviewing the firewall's physical serial number label.
C.By checking the Traffic Logs.
D.By pinging the license server.
E.By running 'show system license' in the CLI.
AnswersA, E

The GUI is the standard way to check status.

Why this answer

Subscription status can be checked in the GUI (Device > Licenses) or via the CLI.

175
MCQhard

Why might an Address Object using an IP Netmask return a validation error even if the IP is valid?

A.The netmask is too small
B.The address is in a private range
C.The IP address bits outside the mask are not zeroed out
D.The address is already in use
AnswerC

The network address must be correctly calculated.

Why this answer

The IP address must match the specified netmask (e.g., 10.1.1.5/24 is invalid because the host bits are set).

176
MCQhard

In PAN-OS, what is the impact of configuring an FQDN Address Object for a site that uses multiple IP addresses returned via DNS load balancing?

A.The firewall will block all traffic until a single IP is specified.
B.Only the first IP returned by the DNS server is stored.
C.The firewall converts the FQDN to a static object upon the first refresh.
D.The firewall updates the object member list with all IPs returned during periodic refreshes.
AnswerD

The firewall performs periodic DNS queries and updates the internal list of IPs associated with the object.

Why this answer

The firewall periodically resolves the FQDN and maintains a list of all returned IPs in the object.

177
MCQhard

What is the 'Read-Only' state of an object indicating in SCM?

A.The administrator lacks permissions
B.The object is inherited from a parent device group
C.The object is corrupted
D.The object is in use by a rule
AnswerB

Inherited objects are read-only locally.

Why this answer

An object is read-only if it is inherited from a parent device group, meaning it cannot be modified at the current level.

178
MCQmedium

An administrator wants to run a report on all traffic blocked by the 'Block_Bad_Sites' security rule. Which tool should they use?

A.The Dashboard Widgets
B.ACC (Application Command Center)
C.Packet Capture
D.Custom Reports
AnswerD

Custom reports allow filtering by rule name and action.

Why this answer

The 'Report' functionality allows users to customize views based on specific policy rule names, actions, and timeframes.

179
MCQeasy

Which section of the NGFW GUI allows an administrator to configure local administrative accounts?

A.Network > Users
B.Device > Administrators
C.Device > Setup > Management
D.Objects > Access
AnswerB

This is the dedicated menu for managing administrative access.

Why this answer

Device > Administrators is where local admin accounts and their roles are defined.

180
MCQhard

Traffic is failing the 'Service' check in a security policy. Which CLI tool can be used to confirm which application is being identified for a specific source-destination pair?

A.debug dataplane packet-diag
B.test security-policy-match
C.show session all
D.show policy rulebase
AnswerB

This utility simulates traffic to see which security policy rule would match.

Why this answer

The 'test security-policy-match' tool simulates a policy lookup to determine which rule and application-ID will be matched for a given flow.

181
Multi-Selectmedium

Which TWO methods can be used to identify traffic using App-ID when port-based rules are insufficient?

Select 2 answers
A.Behavioral analysis of the traffic flow.
B.IP address reputation filtering.
C.Deep Packet Inspection (DPI) signatures.
D.MAC address filtering.
E.URL filtering categories.
AnswersA, C

The firewall analyzes patterns to identify applications.

Why this answer

App-ID relies on packet inspection and signature matching.

Page 2

Page 3 of 3

All pages