Courseiva

Cybersecurity-Practitioner · topic practice

Network Security practice questions

Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Network Security

What the exam tests

What to know about Network Security

Network Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Network Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Review the full subnetting walkthrough →

A network administrator observes that a specific internal subnet is experiencing intermittent connectivity to an external SaaS application. Inspection shows that packets exceeding a certain size are being dropped because the intermediate router does not support Path MTU Discovery, and the firewall is not adjusting the MSS. Where should the administrator enable Maximum Segment Size (MSS) adjustment on the firewall?

An administrator implements a decryption policy to block outbound traffic using obsolete TLS 1.0 protocols. When users attempt to access a legacy partner portal that only supports TLS 1.0, the connection fails with an decryption error. The administrator wants to gracefully alert users with a customizable response page instead of dropping the connection outright. Which setting must be enabled in the Decryption Profile?

Question 3mediummultiple choice
Read the full NAT/PAT explanation →

A company is utilizing User-ID to identify Active Directory users. The administrator notices that users logging into workstations are not being mapped correctly, and IP-to-user mappings are missing for a specific subnet. The subnet is behind a router that performs NAT before traffic reaches the firewall. How should the administrator resolve this User-ID mapping issue?

An administrator needs to configure a Palo Alto Networks NGFW security rule to log traffic only when a new session is successfully established. Which setting in the Security Policy Rule options tab accomplishes this requirement?

Question 5mediummultiple choice
Read the full NAT/PAT explanation →

A network engineer is configuring Source NAT (SNAT) with Dynamic IP and Port (DIPP). The administrator wants to ensure that a specific critical server always translates to the exact same public IP address and port range whenever it initiates outbound connections. Which DIPP translation allocation method should be selected?

Question 6hardmultiple choice
Review the full routing breakdown →

An enterprise firewall is configured with multiple virtual systems (vsys). An administrator needs to configure inter-vsys routing to allow traffic to flow securely between Vsys1 and Vsys2 without traversing physical external interfaces. What is the correct method to achieve this in PAN-OS?

An administrator configures High Availability (HA) Active/Active mode on a pair of Palo Alto Networks firewalls. Which THREE operational considerations or configurations apply specifically to Active/Active deployments compared to Active/Passive? (Choose three)

An administrator is deploying WildFire to protect an organization from zero-day malware. Which TWO configuration steps are required to ensure files are successfully forwarded to the WildFire cloud for analysis? (Choose two)

An organization requires that internal clients accessing external HTTPS websites undergo URL filtering and decryption, but users must be able to opt-out of decryption for sensitive categories like Finance and Healthcare. Which configuration option inside the Decryption rule best achieves this bypass requirement?

An organization wants to inspect encrypted outbound HTTPS traffic to detect malware without causing certificate warnings on user workstations. Which component must be installed on the client endpoints to achieve this?

Question 11mediummultiple choice
Review the full routing breakdown →

A firewall is deployed in an environment with asymmetric routing. Packets belonging to the same TCP session enter on different interfaces due to multi-path upstream routing. What configuration change is required on the Palo Alto Networks firewall to prevent the traffic from being dropped?

Question 12easymultiple choice
Read the full NAT/PAT explanation →

An administrator needs to configure a security rule that applies specifically to traffic destined for a DMZ web server using its public NAT IP address (Destination NAT). Which IP address must be specified in the Destination field of the Security policy rule?

An administrator configures a dynamic address group (DAG) based on User-ID tags, but security rules referencing this DAG fail to match traffic from users who have successfully authenticated via GlobalProtect. What is the most likely root cause?

An administrator configures a Security policy rule to block all file-sharing applications. However, users are still able to upload files using an authorized cloud collaboration tool that shares the same parent application family. Which feature should the administrator use to granularly block file uploads while permitting standard document viewing?

An administrator needs to restrict access to malicious command-and-control (C2) domains. Which security profile should be attached to the outbound Security policy rules to inspect and block this traffic?

An administrator configures an external dynamic list (EDL) pointing to a URL hosting a plain-text list of malicious IP addresses. The firewall successfully downloads the EDL, but security rules referencing this EDL fail to block traffic to those IPs. Inspection reveals that the EDL entries are showing as 'parsing error' in the system logs. What is the most likely cause of this issue?

Question 17mediummultiple choice
Read the full Network Security explanation →

An administrator wants to ensure that critical database servers are protected against vulnerability exploits, SQL injections, and buffer overflows. Which security profile must be applied to the relevant Security policy rule to provide this protection?

An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard signatures. The administrator wants to configure WildFire inline machine learning to block this zero-day threat in real-time. Which feature must be enabled and configured?

An administrator is reviewing the Palo Alto Networks firewall traffic logs and sees a session marked with the application 'unknown-tcp'. What does this application classification typically indicate?

Question 20mediummultiple choice
Read the full Network Security explanation →

An administrator configures high availability (HA) active/passive mode between two Palo Alto Networks firewalls. During a failover test, the administrator observes that stateful sessions are dropped, forcing users to re-authenticate and re-establish their TCP connections. What is the most likely configuration error?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Security sessions

Start a Network Security only practice session

Every question in these sessions is drawn from the Network Security domain — nothing else.

Related practice questions

Related Cybersecurity-Practitioner topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cybersecurity-Practitioner exam test about Network Security?
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cybersecurity-Practitioner topics?
Use the topic links above to move to related areas, or go back to the Cybersecurity-Practitioner question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cybersecurity-Practitioner exam covers. They are not copied from any real exam or dump site.