Courseiva

Certified Network Security Analyst (NetSec-Analyst) (NetSec-Analyst) — Questions 175

181 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQmedium

Which license is required to receive real-time updates for malicious file identification in the cloud?

A.GlobalProtect
B.WildFire
C.URL Filtering
D.Threat Prevention
AnswerB

WildFire is the dedicated service for advanced malware analysis.

Why this answer

The WildFire subscription is specifically responsible for cloud-based malware analysis and real-time signature delivery.

2
MCQmedium

An administrator notices high CPU usage on the management plane. Which command should be used to identify which process is causing the load?

A.debug dataplane packet-diag
B.show system statistics
C.show system info
D.show system resources
AnswerD

This command displays process-specific resource utilization.

Why this answer

The 'show system resources' command provides a real-time view of CPU and memory utilization per process.

3
MCQhard

What is the 'Any' object?

A.A user-created object
B.An object for internal traffic only
C.An object that matches no traffic
D.A system-defined object representing all IP addresses
AnswerD

It matches everything.

Why this answer

The 'Any' object is a pre-defined system object that represents all possible IP addresses and subnets.

4
Multi-Selecthard

Which THREE items can be used as filters in the 'test security-policy-match' command?

Select 3 answers
A.Destination IP
B.Source IP
C.Device serial number
D.Application
E.Log level
AnswersA, B, D

Standard filter.

Why this answer

The test tool requires source, destination, and application/service parameters to accurately simulate the match.

5
Multi-Selecthard

Which THREE things can be done via the CLI to check the health of a firewall?

Select 3 answers
A.Check CPU/Memory (show system resources).
B.Check system uptime (show system info).
C.Format the hard drive.
D.Check environment (fans, power, temp) (show system environment).
E.Check user password hashes.
AnswersA, B, D

A core health check command.

Why this answer

The CLI is very powerful for health checks, using commands like 'show system resources', 'show system environment', and 'show system info'.

6
MCQhard

You are troubleshooting a policy that fails to match traffic for a group of servers. The servers are represented by an Address Group. What is the most likely cause if the Address Group is dynamic?

A.The objects are in a different Device Group
B.The group does not have a description
C.The dynamic filter does not match the tags assigned to the intended objects
D.The static members were not added manually
AnswerC

Dynamic Address Group membership is determined strictly by matching tags.

Why this answer

A dynamic address group uses tag-based registration to populate its membership. If the tags on the underlying objects do not match the filter, the group remains empty.

7
Multi-Selectmedium

Which TWO conditions must be met to use the Panorama/SCM 'Push' functionality to a managed firewall?

Select 2 answers
A.The firewall must have no local policies.
B.The firewall must be currently connected to the management service.
C.The user must be logged into the firewall via SSH.
D.The configuration must pass validation.
E.The firewall must be in maintenance mode.
AnswersB, D

Connection is required for command propagation.

Why this answer

For a successful push, the device must be currently connected and the configuration validation must pass.

8
MCQeasy

Which action in the web interface generates a configuration commit operation?

A.Clicking 'Commit'.
B.Saving a rule.
C.Creating a new object.
D.Logging out.
AnswerA

The commit button initiates the process to apply changes.

Why this answer

Clicking 'Commit' in the upper right-hand corner of the GUI is the standard method for pushing configuration changes to the device.

9
Multi-Selectmedium

Which components can be included in a 'Security Profile Group'? (Choose TWO)

Select 2 answers
A.Antivirus Profile
B.Tag Object
C.Vulnerability Protection Profile
D.Service Object
E.Address Object
AnswersA, C

Correct.

Why this answer

Security Profile Groups combine profile types like Antivirus and Vulnerability Protection.

10
MCQmedium

When you use an Application Group in a policy, what happens if you add a new application to that group?

A.The policy breaks
B.The policies using the group are updated automatically
C.You must recreate the policy
D.You must re-save all policies
AnswerB

This is the benefit of grouping.

Why this answer

Any security policy referencing that Application Group will automatically include the new application, improving policy agility.

11
Multi-Selectmedium

Which TWO of the following statements are true regarding the use of 'Address Groups' in PAN-OS?

Select 2 answers
A.Dynamic Address Groups use manual member selection.
B.Address groups can only be used in the Source field of a policy.
C.You can include FQDN objects as members of a Static Address Group.
D.Address groups are mandatory for all security policies.
E.Static Address Groups can contain both IP addresses and other Address Groups.
AnswersC, E

FQDN objects are valid members of static groups.

Why this answer

Address groups can be static or dynamic, and they simplify rulebase management by allowing references to multiple objects in a single rule.

12
Multi-Selectmedium

Which TWO of the following actions in a security policy will result in an entry in the Threat Log?

Select 2 answers
A.Drop
B.Bypass
C.Reset-both
D.Allow
E.Alert
AnswersA, E

Triggers threat log.

Why this answer

The 'alert' and 'drop' actions in security profiles (within a policy) trigger threat logs.

13
MCQeasy

What is the result of applying a 'Log at Session End' setting in a security policy?

A.Bypass security
B.Record log when the connection closes
C.Log every packet
D.Deny all traffic
AnswerB

This is the correct function.

Why this answer

Logging at session end ensures a summary of the session (bytes transferred, duration) is recorded when the session terminates.

14
MCQmedium

An administrator suspects that a specific App-ID is not correctly identifying traffic. Which log column should they examine to confirm the application match?

A.Application
B.Category
C.Policy
D.Service
AnswerA

This column displays the identified application.

Why this answer

The 'Application' column in the Traffic log explicitly displays what the firewall identified as the application for the session.

15
Multi-Selecteasy

Which TWO of the following represent valid interface types on a Palo Alto Networks firewall?

Select 2 answers
A.Layer 4
B.Layer 3
C.Layer 5
D.Layer 1
E.Layer 2
AnswersB, E

Standard routed interface.

Why this answer

Layer 3 and Layer 2 are the most common interface types used for traffic handling.

16
MCQmedium

Which object type is most appropriate for a web proxy that uses a hostname?

A.Address Group
B.IP Netmask
C.Service Object
D.FQDN
AnswerD

Handles hostnames.

Why this answer

FQDN objects are designed to handle hostnames that resolve to changing IP addresses.

17
Multi-Selecthard

Which THREE of the following are components of the dataplane in the Palo Alto Networks architecture?

Select 3 answers
A.Session Management
B.Management UI process
C.Configuration database
D.Hardware Acceleration (FPGA/ASIC)
E.Security Processing (App-ID/Content-ID)
AnswersA, D, E

Core dataplane function.

Why this answer

The dataplane consists of the security processing, session management, and hardware acceleration components.

18
MCQhard

What is the significance of the 'Inheritance' setting when creating objects in a Device Group hierarchy?

A.It prevents the object from being deleted
B.It requires all objects to have the same name
C.It automatically creates a copy of the object in the child group
D.It allows the object to be visible in child device groups
AnswerD

Inheritance is the mechanism for sharing objects downward.

Why this answer

Objects created in a parent device group are inherited by child groups, ensuring consistency and reducing redundancy.

19
MCQmedium

What happens if you delete an object that is currently in use by a Security Policy?

A.The system prevents the deletion until the reference is removed
B.The policy is deleted
C.The policy is automatically disabled
D.The policy uses 'any' instead
AnswerA

The system enforces referential integrity.

Why this answer

PAN-OS prevents the deletion of an object if it is referenced by a policy, requiring the administrator to remove the reference first.

20
MCQhard

A firewall is reporting 'Packet buffer protection' drops. What is the most likely cause of this issue?

A.Hardware failure
B.License expiration
C.High volume of traffic exceeding processing capacity
D.Policy misconfiguration
AnswerC

Buffer protection is designed to prevent exhaustion during traffic bursts.

Why this answer

Packet buffer protection is triggered when the firewall receives traffic faster than it can process, often due to a DoS attack or massive traffic spike.

21
MCQhard

In a scenario where you use an Application Object in a Security Policy, how does the firewall identify the traffic?

A.By the DNS request
B.By the source IP
C.By the destination port
D.By App-ID inspection
AnswerD

App-ID inspects the traffic signature.

Why this answer

The firewall uses App-ID, which performs deep packet inspection to identify the application, regardless of the port being used.

22
MCQeasy

When creating tags, what is the best practice for naming conventions?

A.Keep names short, under 3 characters
B.Use a consistent and descriptive naming convention
C.Use random strings for security
D.Always start with a number
AnswerB

Consistency is key for operational efficiency.

Why this answer

A clear, consistent naming convention (e.g., 'Location-Department-Role') makes management and filtering much easier in large environments.

23
MCQhard

An administrator notices that some traffic is not hitting the desired QoS policy. What is the most likely reason?

A.The traffic is not hitting the interface with QoS enabled
B.The session is not SSL
C.NAT policy is missing
D.The App-ID is not identified
AnswerA

QoS must be enabled on the egress interface.

Why this answer

If traffic matches a security policy that doesn't have a corresponding QoS marking or the QoS policy matching criteria (zone/interface) is wrong, the traffic will use the default class.

24
MCQeasy

When creating a Service object, what is the maximum number of ports that can be defined in a single Service object?

A.1
B.Only one port is allowed
C.Unlimited, provided they are within the protocol's range
D.10
AnswerC

Service objects support lists and ranges of ports.

Why this answer

A single service object can define one port, a range of ports, or multiple individual ports separated by commas.

25
MCQhard

An organization has a strict requirement that all web traffic must be inspected. Which policy is required in addition to the Security policy to achieve this?

A.Device Policy
B.NAT Policy
C.QoS Policy
D.Decryption Policy
AnswerD

Decryption is required for deep inspection.

Why this answer

Decryption policy is necessary for the firewall to see inside SSL/TLS traffic.

26
Multi-Selecthard

What are the limitations of FQDN address objects? (Choose THREE)

Select 3 answers
A.They require the firewall to successfully resolve the FQDN
B.They are only supported for internal IPs
C.They cannot be used in NAT policies
D.They require the firewall to be able to reach a DNS server
E.They may not match traffic if the SNI does not match
AnswersA, D, E

Correct.

Why this answer

FQDN objects rely on DNS resolution, may not match traffic using different SNIs, and require the firewall to have DNS access.

27
MCQhard

If an administrator creates an Application Override policy, what impact does it have on security inspection?

A.It enables SSL inspection
B.It forces traffic through the scanner
C.It improves inspection
D.It bypasses Layer 7 inspection
AnswerD

This is the definition of Application Override.

Why this answer

Application Override bypasses App-ID detection and Layer 7 inspection, meaning threats are not inspected.

28
MCQhard

When using a Dynamic Address Group (DAG) in a policy, what is the prerequisite for the traffic to match the intended members?

A.The objects must be tagged with the value defined in the DAG filter
B.The objects must be in the same subnet
C.The objects must have a static IP
D.The objects must be added to a static group first
AnswerA

The tag-matching logic is the core functionality of a DAG.

Why this answer

Objects must be registered with the specific tag that the DAG filter is searching for.

29
MCQhard

A security analyst is reviewing logs in SCM and realizes that logs from a specific firewall are missing. What is the most likely cause?

A.The firewall is too busy to send logs.
B.The firewall license is expired.
C.The App-ID database is outdated.
D.The Log Forwarding profile is not configured to send to SCM.
AnswerD

Log forwarding must be explicitly enabled to send data to the centralized repository.

Why this answer

If log forwarding is not correctly configured or the firewall cannot reach the log collection service, logs will not appear in SCM.

30
MCQmedium

An administrator is using SCM to manage multiple firewalls. What happens when an administrator pushes a configuration that contains a duplicate object name?

A.The object is ignored, and the policy uses the old value.
B.SCM automatically renames the object.
C.The firewall automatically deletes the duplicate object.
D.The commit fails with an error indicating the conflict.
AnswerD

Validation logic prevents the deployment of invalid or conflicting configurations.

Why this answer

SCM performs validation checks. If a conflict or duplicate exists that violates the configuration model, the commit will fail, and the administrator will be notified.

31
MCQeasy

What is the main advantage of using an object over manually entering an IP address in a policy?

A.They are required for NAT
B.They are faster to type
C.They increase the firewall throughput
D.Centralized management and reusability
AnswerD

Updating once changes all references.

Why this answer

Objects allow for central management; updating the object updates all policies that use it simultaneously.

32
MCQhard

A administrator is troubleshooting an intermittent application failure. The Traffic log shows the session is aging out due to 'tcp-rst-from-client'. What is the most effective way to determine if the Palo Alto Networks firewall is prematurely closing the session?

A.Increase the TCP session timeout in the Application override
B.View the ACC tab for TCP reset trends
C.Disable hardware offload
D.Monitor 'show counter global filter packet-filter yes' while performing a test
AnswerD

This command identifies real-time drops happening within the dataplane.

Why this answer

Running a debug flow filter and then observing the output via 'show counter global' helps identify if the firewall is dropping the packet due to internal resource exhaustion or state mismatches.

33
MCQeasy

When configuring a QoS policy, what is the first step the administrator must take to ensure the traffic is correctly prioritized?

A.Create a new zone
B.Enable QoS on the egress interface
C.Configure NAT policy
D.Delete all App-IDs
AnswerB

QoS must be enabled on the egress interface for the shaping/prioritization to take effect.

Why this answer

Before QoS can be applied, the traffic must be identified and classified by the QoS policy based on the ingress interface and traffic matching criteria.

34
MCQeasy

If an administrator needs to check the status of a physical interface to see if it is 'up/up', which CLI command is most appropriate?

A.show network interface
B.show interface all
C.show chassis status
D.show system status
AnswerB

This command displays detailed status for all configured interfaces.

Why this answer

The 'show interface' command provides the link state and operational status of physical interfaces.

35
MCQeasy

Which of the following is a valid use case for a Tag?

A.To filter and organize objects in the GUI
B.To block specific ports
C.To authenticate users
D.To define a subnet
AnswerA

Tags are primarily for organization.

Why this answer

Tags are used for filtering, organizing, and color-coding objects, policies, and device groups.

36
MCQmedium

You want to color-code objects in Strata Cloud Manager to improve visibility. Which feature do you use?

A.Tags
B.Device Groups
C.Descriptions
D.Object Filtering
AnswerA

Tags allow the assignment of colors to objects.

Why this answer

Tags are used to provide metadata, including colors, to objects for better organization and visual identification.

37
MCQhard

An administrator wants to ensure that all administrative sessions are logged out after 30 minutes of inactivity. Where is this configured?

A.Device > Administrators
B.Monitor > Logs
C.Device > Setup > Management
D.Policies > Security
AnswerC

General management settings contain the idle timeout parameter.

Why this answer

The 'Idle Timeout' for administrative sessions is configured in Device > Setup > Management > General Settings.

38
Multi-Selectmedium

Which TWO of the following are valid methods for performing a configuration backup on a firewall?

Select 2 answers
A.Performing a hard reset.
B.Taking a snapshot of the interface status.
C.Exporting the configuration file via Device > Setup > Operations.
D.Scheduling an export to a remote server.
E.Using the 'save config' command in the CLI.
AnswersC, D

This is a standard manual backup method.

Why this answer

Backups can be performed manually via the GUI or automatically using scheduled export to an SCP/SFTP server.

39
Multi-Selectmedium

Which TWO administrative roles are standard within a Palo Alto Networks firewall?

Select 2 answers
A.Superuser.
B.Hardware Maintenance Tech.
C.Junior Packet Analyser.
D.Data Plane Observer.
E.Device Admin.
AnswersA, E

The highest level role.

Why this answer

The firewall defines several roles, including 'Superuser' and 'Device Admin', which have specific access levels.

40
MCQmedium

An administrator has configured a new NAT rule, but traffic is not traversing it. Which column in the NAT logs is the most useful for verifying the NAT translation is occurring?

A.Application
B.Action
C.Rule Name
D.Translated Address
AnswerD

This shows the result of the NAT rule application.

Why this answer

The NAT logs show the 'Source Translated' and 'Destination Translated' addresses, confirming if the rule was applied.

41
MCQmedium

An administrator wants to group multiple existing FQDN Address Objects into a single logical container for easier policy management. Which object type should they use?

A.Dynamic Address Group
B.Service Group
C.Region Object
D.Static Address Group
AnswerD

Static groups allow manual selection of FQDN objects as members.

Why this answer

Address Groups can contain FQDN objects to simplify policy rulebases.

42
MCQeasy

What is the primary function of a 'Service Route' in a Palo Alto Networks firewall?

A.To enable load balancing on external links.
B.To manage VPN tunnels.
C.To route internal traffic between zones.
D.To specify which interface is used for system-level services.
AnswerD

Service routes are specifically for management traffic origins.

Why this answer

Service routes allow the administrator to specify which interface the firewall uses to reach specific external services like DNS, NTP, or update servers.

43
Multi-Selectmedium

Which TWO of the following logs are most useful when troubleshooting a potential Denial of Service (DoS) attack?

Select 2 answers
A.URL Filtering Log
B.Traffic Log
C.System Log
D.Data Filtering Log
E.Threat Log
AnswersC, E

Captures system resource alerts.

Why this answer

Threat logs show the specific DoS event triggering, and System logs provide the overall context and resource alerts.

44
MCQhard

When configuring log forwarding, which protocol is recommended for secure, encrypted transmission of logs to an external collector?

A.SNMPv2
B.Syslog over TLS
C.Cleartext HTTP
D.Telnet
AnswerB

Syslog over TLS provides the necessary encryption for secure log transport.

Why this answer

Syslog over TLS (or SCP/SFTP where applicable) ensures that logs are encrypted in transit to protect sensitive network data.

45
MCQmedium

You need to create a service object for a legacy application that uses a custom TCP port 8888. How should this be defined in PAN-OS?

A.Create an Address object for the port
B.Create a Service Group with port 8888
C.Define a Service object specifying Protocol TCP and Destination Port 8888
D.Use an Application Override policy
AnswerC

Defining the protocol and port is the standard way to create a service object.

Why this answer

Service objects require specifying the protocol (TCP/UDP) and the specific port or port range required by the application.

46
Multi-Selectmedium

Which THREE actions can be applied to a Security Policy rule?

Select 3 answers
A.Reset
B.Redirect
C.Encrypt
D.Allow
E.Deny
AnswersA, D, E

Drops with TCP RST/ICMP response.

Why this answer

Security policies can Allow, Deny, or Drop traffic, and can also Reset connections.

47
MCQmedium

When creating a new tag, what is the default color assigned if not specified?

A.None/System Default
B.Green
C.Red
D.Blue
AnswerA

Often there is no color or a neutral system default.

Why this answer

If no specific color is selected, the firewall assigns a default color or no color depending on the interface version.

48
MCQeasy

What is the purpose of the 'Policy Optimizer' feature?

A.To create new rules
B.To identify unused or overly permissive policies
C.To configure NAT
D.To manage zones
AnswerB

That is its main function.

Why this answer

Policy Optimizer identifies unused, redundant, or overly permissive rules to improve firewall performance and security posture.

49
MCQmedium

What is the purpose of the 'Service' field in a Security Policy?

A.To define the NAT rule
B.To define the application
C.To define the user
D.To define the port
AnswerD

Service defines the ports allowed.

Why this answer

The 'Service' field specifies the TCP/UDP ports to be allowed or denied, though App-ID is preferred.

50
MCQeasy

When creating a custom Tag, which action is performed in the 'Objects' > 'Tags' menu?

A.Defining the source zone for the traffic.
B.Defining the TCP port range for the tag.
C.Associating the tag with a specific security profile.
D.Assigning a color to the tag for organizational visibility.
AnswerD

Color-coding is a primary feature of tags for dashboard and rule management.

Why this answer

Tags are created with a name and an optional color for visual identification in the GUI.

51
MCQeasy

What action should be taken before upgrading the PAN-OS version on a production firewall?

A.Delete all existing logs.
B.Take a configuration snapshot.
C.Change the management IP address.
D.Disable all security policies.
AnswerB

Backing up the configuration is mandatory before any major change.

Why this answer

Taking a backup (configuration snapshot) is the most critical step to ensure a recovery path exists if the upgrade fails.

52
MCQeasy

You are configuring an Address Object in Strata Cloud Manager for a new web server. Which field must be unique within the configuration scope?

A.Object Name
B.Tag
C.IP Netmask
D.Description
AnswerA

The name of an object is its unique identifier within the configuration hierarchy.

Why this answer

The name field of an object must be unique within its context (Device Group or Snippet) to prevent configuration conflicts.

53
Multi-Selecthard

Which THREE settings must be configured to allow inbound NAT traffic for a web server?

Select 3 answers
A.QoS policy
B.Security policy
C.Destination address mapping
D.NAT policy
E.App-ID override
AnswersB, C, D

Security policy must allow the traffic.

Why this answer

You need a NAT policy, a security policy allowing traffic from the external zone to the DMZ, and a properly configured destination NAT address mapping.

54
Multi-Selectmedium

Which TWO items must be matched in a QoS policy?

Select 2 answers
A.Source Zone
B.Security Profile
C.NAT Pool
D.App-ID
E.User Group
AnswersA, D

Zone matching is required.

Why this answer

QoS policies match on the Source/Destination zones, Source/Destination addresses, and the App-ID to determine the QoS class.

55
MCQmedium

You are managing security policies in Strata Cloud Manager and need to create an Address Object that represents a subnet used by multiple regional offices. Which approach is best practice for organizational visibility?

A.Create an Address Object with a descriptive name and assign a tag for geographic identification.
B.Use an Address Group containing only one Address Object.
C.Assign the address to the 'Any' zone to ensure it is reachable.
D.Hardcode the IP address directly in the security policy rule.
AnswerA

Tags are the recommended way to categorize and filter objects in SCM.

Why this answer

Using tags allows for better filtering and reporting across large object sets.

56
MCQhard

An administrator wants to prioritize VoIP traffic over all other traffic. Which policy type is the best choice?

A.QoS Policy
B.Security Policy
C.NAT Policy
D.Decryption Policy
AnswerA

QoS is for prioritization.

Why this answer

QoS policy allows classifying and prioritizing traffic based on class settings and interface bandwidth.

57
MCQmedium

You want to create a group that contains both individual address objects and other address groups. Is this supported?

A.No, groups can only contain static objects
B.Yes, address groups support nesting
C.Only if they are in the same device group
D.Only one level of nesting is allowed
AnswerB

Nesting is a standard feature.

Why this answer

Yes, Address Groups support nesting, where they can contain both static objects and other groups.

58
MCQeasy

Where can an administrator view the total number of sessions currently active on the firewall?

A.Dashboard > System Resources
B.Device > Setup > Session
C.Network > Interfaces
D.Monitor > Traffic Logs
AnswerA

The widget typically displays session count information.

Why this answer

The Dashboard > Session Browser or the 'show session info' CLI command provides this data.

59
MCQmedium

What is the benefit of using an Address Group over a single Address Object?

A.It allows for faster packet matching
B.It is required for NAT
C.It improves security
D.It simplifies policy management by allowing you to add/remove members in one place
AnswerD

This is the core management benefit.

Why this answer

Address Groups allow you to manage a collection of objects as a single unit, which is highly efficient for policy grouping.

60
MCQeasy

Which tab would you use to add a new Security policy rule?

A.Monitor
B.Policies
C.Network
D.Objects
AnswerB

For policies.

Why this answer

The 'Policies' > 'Security' tab is where you define the rulebase.

61
MCQhard

You have an FQDN address object set to 'www.example.com'. Why might the firewall fail to block traffic to this FQDN?

A.FQDN objects are not supported in security policies
B.The object name is incorrect
C.The object is too long
D.The firewall has not successfully resolved the FQDN to an IP
AnswerD

FQDN objects are essentially dynamic IP objects that require successful DNS resolution.

Why this answer

FQDN objects rely on the firewall's DNS resolution; if the resolution fails or the traffic uses a different SNI/IP, the policy may not trigger.

62
MCQmedium

An administrator needs to allow traffic from the internal network to a public web server using Source NAT. Which configuration is required to ensure the internal client IP is translated to the firewall's public interface IP?

A.Configure a Dynamic IP and Port translation using the interface address.
B.Configure a U-Turn NAT policy.
C.Configure a Destination NAT policy.
D.Configure a Static NAT policy.
AnswerA

DIPP allows multiple internal addresses to share a single public interface address.

Why this answer

Dynamic IP and Port translation (DIPP) is the standard method for mapping internal IPs to an interface IP.

63
MCQmedium

You are creating a new policy and realize you need a new Address Object. Can you create it from within the policy window?

A.Yes, by clicking the 'Add' button in the Source or Destination field
B.Only if you have Superuser privileges
C.Only for Address Groups, not single objects
D.No, you must go to the Objects tab first
AnswerA

This is a standard workflow improvement in the interface.

Why this answer

Yes, PAN-OS and SCM allow for the creation of new objects directly from the policy configuration menu without having to leave the screen.

64
MCQmedium

An administrator wants to ensure that all internal traffic to the internet is encrypted. Which policy type would be used to enforce this?

A.NAT Policy
B.Security Policy
C.QoS Policy
D.Decryption Policy
AnswerD

Decryption policies control the decryption of SSL/TLS traffic.

Why this answer

The Decryption Policy is used to configure SSL Forward Proxy or SSL Inbound Inspection to inspect and enforce encryption requirements.

65
Multi-Selectmedium

Which of the following are valid types of address objects? (Choose TWO)

Select 2 answers
A.Service Port
B.IP Netmask
C.Application ID
D.FQDN
E.Security Profile
AnswersB, D

Correct.

Why this answer

IP Netmask and FQDN are both standard address object types in PAN-OS.

66
MCQmedium

What is the function of an 'Application Group' in PAN-OS policy creation?

A.To apply QoS markings to specific apps
B.To define the port for the application
C.To bundle multiple applications for use in a single policy rule
D.To map users to applications
AnswerC

This simplifies policy maintenance.

Why this answer

Application Groups allow grouping multiple applications into a single object, simplifying policy creation.

67
MCQeasy

Where do you go in SCM to manage all your network objects in one location?

A.Policies tab
B.Objects tab
C.Monitor tab
D.Device Settings tab
AnswerB

The primary location for object management.

Why this answer

The 'Objects' tab is the centralized location for creating and managing all configuration objects.

68
MCQmedium

Which of the following is the most efficient way to manage NAT policies for multiple similar servers?

A.Use address groups in a single NAT rule
B.Disable NAT
C.Use a single interface IP for all
D.Create one NAT rule per server
AnswerA

Address groups simplify rules.

Why this answer

Creating a NAT rule with a single rule that uses dynamic address objects or address groups is more efficient than individual rules.

69
Multi-Selectmedium

Which TWO settings must be correctly configured to ensure User-ID can properly map an IP address to a user identity in a multi-site environment?

Select 2 answers
A.QoS policy settings
B.IP-User Mapping
C.Security policy zones
D.NAT policy configuration
E.Group Mapping
AnswersB, E

This is the core mapping mechanism needed for policy enforcement.

Why this answer

The User-ID Agent and the Group Mapping configuration are essential for retrieving group and user information from Active Directory.

70
MCQmedium

A user reports that they are seeing a 'Server Certificate Warning' when accessing an internal site. Which feature should the administrator investigate?

A.Security Policy rules
B.URL Filtering profile
C.SSL Decryption policy
D.App-ID configuration
AnswerC

The decryption policy controls how the firewall re-signs traffic; incorrect CA trust causes these warnings.

Why this answer

SSL Forward Proxy decryption issues usually manifest as certificate warnings if the users do not trust the CA that signed the re-signed certificate.

71
MCQeasy

If you are unable to ping a management interface from a remote subnet, what is the first setting you should check?

A.Routing table
B.NAT rules
C.Management Interface Settings
D.Security Policy rules
AnswerC

This defines which protocols are permitted on the management interface.

Why this answer

The 'Management Interface Settings' control which services (like Ping/HTTPS) are allowed on the management port.

72
Multi-Selectmedium

Which THREE items can be used as a match criterion in a Security Policy?

Select 3 answers
A.Source User
B.QoS Profile Name
C.Application
D.Source Zone
E.NAT Pool
AnswersA, C, D

User-ID allows matching on users.

Why this answer

Security policies match on source/destination zones, source/destination addresses, users, applications, and services.

73
MCQhard

If you update an Address Object that is referenced by multiple Security Policies, what happens?

A.The object will be duplicated
B.The policies reference the object by name, so the update applies automatically upon commit
C.The policies must be manually updated
D.The policies will become invalid
AnswerB

Policies point to the object identifier, not a static copy of the data.

Why this answer

Changes to an object propagate to all policies that reference that object immediately upon commit.

74
MCQmedium

An administrator needs to identify which rule is blocking legitimate traffic. What is the most effective approach?

A.Review the Traffic Log for 'drop' actions.
B.Reset the firewall to factory defaults.
C.Increase the log severity level to 'Debug'.
D.Run a packet capture on all interfaces.
AnswerA

Traffic logs show the rule name responsible for the drop action.

Why this answer

By checking the Traffic Logs and filtering for 'drop' actions, the administrator can see exactly which rule identifier blocked the traffic.

75
MCQhard

An administrator needs to exclude a specific server from a Dynamic Address Group that uses a filter for all 'Production' tagged servers. What is the most efficient way to achieve this?

A.Change the IP address of the server
B.Use a negative tag in the DAG filter (e.g., 'Production' AND NOT 'Exclude')
C.Remove the server from the network
D.Manually delete the object
AnswerB

Logical operators in the filter allow for precise membership control.

Why this answer

The filter expression in a DAG supports logical operators, allowing the exclusion of specific tags or criteria.

Page 1 of 3

Page 2

All pages