Which tab in the Palo Alto Networks GUI is primarily used to manage Security and NAT policies?
Policies are configured here.
Why this answer
The 'Policies' tab is the central location for managing all types of policies.
181 questions total · 3pages · All types, answers revealed
Page 3 of 3
Which tab in the Palo Alto Networks GUI is primarily used to manage Security and NAT policies?
Policies are configured here.
Why this answer
The 'Policies' tab is the central location for managing all types of policies.
A user reports that they cannot access a website, receiving a 'page cannot be displayed' error. Which log type should the administrator check first to see if the traffic is reaching the firewall?
The Traffic log is the first stop to verify if the firewall is receiving and processing the traffic.
Why this answer
The Traffic log tracks every session that hits the firewall, making it the primary source for connectivity troubleshooting.
When managing objects in SCM, which actions can be performed on tags? (Choose TWO)
Correct.
Why this answer
Tags can be assigned colors and applied to various objects for organization.
Which elements are required when creating a new custom Service Object? (Choose THREE)
Correct.
Why this answer
Service objects require a name, a protocol, and at least one port.
Which of the following is NOT a valid type of address object?
IP Protocol is not an address object.
Why this answer
Palo Alto Networks supports IP Netmask, IP Range, and FQDN objects. IP Protocol is not an address object type.
When creating a NAT policy, which field defines the address that the traffic will be translated to on the destination side?
This specifies the new destination IP.
Why this answer
In Destination NAT, the 'Translated Packet' section defines the destination IP address that the traffic is rewritten to.
Which TWO of the following are benefits of using Strata Cloud Manager for enterprise firewall management?
SCM consolidates data for easier analysis.
Why this answer
SCM provides centralized visibility and simplified policy management across distributed environments.
Why might an Application Override policy be preferred over a Security Policy for a specific custom application?
This is the primary use case.
Why this answer
When an application is proprietary and the firewall cannot identify it using standard App-ID, an override forces the firewall to treat it as a specific 'App-ID' object, bypassing signature inspection.
Which of the following is an example of a 'Service' object?
This defines a protocol and port.
Which TWO pieces of information must an administrator provide when setting up a Log Forwarding profile?
The server needs to be identified.
Why this answer
Log forwarding requires identifying the destination (Syslog server) and the traffic types to be forwarded.
Which TWO of the following are valid source types for a Security Policy?
Addresses are valid.
Why this answer
Security policies can match on Source Zones and Source Address objects.
You are designing a QoS policy. You want to prioritize VoIP traffic over bulk file transfers. Which component must you create to classify the VoIP traffic?
QoS profiles define how traffic is treated after classification.
Why this answer
QoS profiles are applied to QoS policies to define the class and priority of the traffic.
Which TWO of the following characteristics apply to Service Objects in Strata Cloud Manager?
Port ranges are a standard feature of service object definitions.
Why this answer
Service objects define protocol and port, and they can be grouped for easier management.
Which THREE steps are required to correctly implement User-ID mapping using the Windows-based User-ID agent?
The agent is a service installed on a Windows server.
Why this answer
The agent must be installed, configured to monitor logs, and the firewall must be told to query the agent.
Which THREE features are associated with an 'Application Filter'?
Filter by the technology used.
Why this answer
Application Filters group applications based on category, subcategory, and technology, and these filters update automatically as new applications are added to the PAN-OS database.
What are the primary characteristics of Service Groups? (Choose TWO)
Correct.
Why this answer
Service Groups are used for grouping multiple services and allow for the mixing of different protocols.
When creating a Dynamic Address Group (DAG), what is the primary prerequisite for the object to populate successfully?
The registration of a tag to an IP is what triggers the DAG membership.
Why this answer
DAGs rely on Tags being registered to the IP address via VM-Series monitoring, XML API, or User-ID.
An administrator wants to schedule signature updates to occur at 3:00 AM daily. Where is this configured?
This is where update schedules are defined.
Why this answer
The Device > Dynamic Updates page contains the schedule settings for various update types like Applications, Threats, and WildFire.
What is the primary purpose of a 'Device Group' in the context of SCM?
Device groups enable centralized security policy management.
Why this answer
Device groups allow for the hierarchical grouping of firewalls for shared policy management, providing consistent security across the enterprise.
Which of the following are benefits of using Device Groups in SCM? (Choose THREE)
Correct.
Why this answer
Device groups allow for hierarchical inheritance, shared objects, and policy modularity.
How does an administrator perform a software update on a standalone firewall?
The Software page is where PAN-OS images are managed.
Why this answer
Software updates are managed in the Device > Software page, where you can download and install new versions of PAN-OS.
Which THREE requirements must be met to enable User-ID integration with Microsoft Active Directory?
Needed to query AD.
Service groups are protocol-agnostic regarding their members.
Which TWO ways can an administrator verify that a security subscription is active?
The GUI is the standard way to check status.
Why this answer
Subscription status can be checked in the GUI (Device > Licenses) or via the CLI.
Why might an Address Object using an IP Netmask return a validation error even if the IP is valid?
The network address must be correctly calculated.
Why this answer
The IP address must match the specified netmask (e.g., 10.1.1.5/24 is invalid because the host bits are set).
In PAN-OS, what is the impact of configuring an FQDN Address Object for a site that uses multiple IP addresses returned via DNS load balancing?
The firewall performs periodic DNS queries and updates the internal list of IPs associated with the object.
What is the 'Read-Only' state of an object indicating in SCM?
Inherited objects are read-only locally.
Why this answer
An object is read-only if it is inherited from a parent device group, meaning it cannot be modified at the current level.
An administrator wants to run a report on all traffic blocked by the 'Block_Bad_Sites' security rule. Which tool should they use?
Custom reports allow filtering by rule name and action.
Why this answer
The 'Report' functionality allows users to customize views based on specific policy rule names, actions, and timeframes.
Which section of the NGFW GUI allows an administrator to configure local administrative accounts?
This is the dedicated menu for managing administrative access.
Why this answer
Device > Administrators is where local admin accounts and their roles are defined.
Traffic is failing the 'Service' check in a security policy. Which CLI tool can be used to confirm which application is being identified for a specific source-destination pair?
This utility simulates traffic to see which security policy rule would match.
Why this answer
The 'test security-policy-match' tool simulates a policy lookup to determine which rule and application-ID will be matched for a given flow.
Which TWO methods can be used to identify traffic using App-ID when port-based rules are insufficient?
The firewall analyzes patterns to identify applications.
Why this answer
App-ID relies on packet inspection and signature matching.
Page 3 of 3
Practice NetSec-Analyst by domain
Target a specific domain to shore up weak areas.