Courseiva

Certified Network Security Professional (NetSec-Pro) (NetSec-Pro) — Questions 175

191 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selecthard

Which THREE components are required to successfully deploy and use Advanced URL Filtering?

Select 3 answers
A.An endpoint agent installed on all user devices.
B.An active Advanced URL Filtering subscription.
C.An enabled Security Policy rule that references the URL Filtering profile.
D.A dedicated management interface for URL updates.
E.A URL Filtering profile configured with the desired actions.
AnswersB, C, E

Subscription is required for the feature to function.

Why this answer

Advanced URL Filtering requires the subscription, a profile, and the enforcement via policy.

2
MCQmedium

You have a Security Policy rule allowing 'web-browsing' and 'ssl'. A user cannot access a specific site, and the logs show the traffic as 'web-browsing' but failing a specific Security Profile. Which action is most appropriate?

A.Disable App-ID for this rule.
B.Increase the timeout settings on the zone.
C.Check the logs for the specific Security Profile trigger.
D.Change the application to 'any'.
AnswerC

The logs will indicate which profile (e.g., URL Filtering) is blocking the request.

Why this answer

If traffic is identified correctly as the app, but the security profile fails, you must check the Security Profile attached to the policy rule.

3
MCQhard

An administrator notices high memory utilization. What is the most effective way to identify which processes are consuming the most resources on the control plane?

A.Check the App-ID cache in the GUI.
B.Navigate to Device > Support > Logs.
C.Use 'show system resources' in the CLI.
D.Perform a packet capture on the management interface.
AnswerC

This command provides a real-time snapshot of CPU and memory usage per process.

Why this answer

The 'debug software process' commands in the CLI are used to monitor resource consumption per process.

4
MCQmedium

You need to ensure that traffic between two internal zones is inspected for threats. What must be configured on the Security Policy?

A.Apply Security Profiles to the inter-zone policy rule.
B.Enable inter-zone routing.
C.Configure a virtual wire.
D.Change the zones to a single zone.
AnswerA

Without profiles, the traffic is permitted but not inspected.

Why this answer

To inspect inter-zone traffic, you must explicitly define a policy rule between the zones and attach the necessary Security Profiles.

5
MCQhard

You are troubleshooting a connectivity issue between an SCM-managed firewall and the SCM cloud service. Which log source in the firewall UI provides the most detailed information regarding the management connection?

A.Configuration logs
B.Threat logs
C.Traffic logs
D.System logs
AnswerD

System logs contain events related to the management service and connectivity to SCM.

Why this answer

The system logs, specifically filtering for 'ssl-vpn' or management service traffic, help identify connection failures.

6
MCQmedium

When deploying a firewall in a Zero Trust environment, what is the recommended stance for the default interzone policy?

A.Deny all traffic by default.
B.Allow all internal traffic, deny external.
C.Allow traffic based on source IP only.
D.Allow all traffic to simplify configuration.
AnswerA

Zero Trust requires implicit deny as the default.

Why this answer

Zero Trust mandates a 'deny all' stance as the starting point for all traffic.

7
Multi-Selectmedium

Which TWO settings are configurable within a URL Filtering profile?

Select 2 answers
A.Application signature override
B.Custom URL list (allow/block)
C.SSL Decryption mode
D.Category-based blocking
E.User-ID mapping source
AnswersB, D

Standard feature.

Why this answer

URL filtering allows category-based blocking and custom URL list management.

8
MCQeasy

Which command is used to restart the management server process on the firewall without impacting traffic flow?

A.request system reboot
B.clear session all
C.debug software restart process management-server
D.exit
AnswerC

This restarts the management server process only.

Why this answer

The 'debug software restart process management-server' command is the safe way to restart the management UI and control plane processes.

9
MCQeasy

Which log type should be filtered if you are searching for specific firewall configuration changes made by an administrator?

A.System Logs
B.Threat Logs
C.Config Logs
D.Traffic Logs
AnswerC

Config logs are the audit trail for administrative changes.

Why this answer

Configuration logs (Config logs) explicitly track changes made to the firewall settings, including who made the change and when.

10
MCQeasy

Where is the configuration located to enable the 'DNS Security' service on a specific security zone?

A.Objects > Security Profiles > DNS Security
B.Network > Zones > [Zone Name]
C.Device > Setup > Services > DNS
D.Policies > Security > [Rule Name] > Actions tab
AnswerD

Security profiles are applied within the Security Policy Rule.

Why this answer

DNS Security profiles are applied to security policy rules, which then process traffic from specific zones.

11
MCQhard

An administrator finds that the 'Threat Prevention' logs are not showing any data, despite having an active subscription. What is the most likely cause?

A.The 'Threats' dynamic update is not scheduled.
B.The firewall is in 'Evaluation Mode'.
C.The log forwarding profile is missing the 'Global' setting.
D.The security policy rules do not have an attached Security Profile Group.
AnswerD

Logs are only generated if a Security Profile is applied to the traffic.

Why this answer

Threat prevention logs are generated by policy rules; if a rule does not have a security profile attached, no logs are generated.

12
MCQeasy

Where do you navigate in PAN-OS to update the App-ID and Threat signatures to the latest versions?

A.Device > Dynamic Updates
B.Network > Interfaces
C.Objects > Applications
D.Policies > Security
AnswerA

Dynamic Updates allows downloading and installing threat and app definitions.

Why this answer

The Device > Dynamic Updates menu is the standard location for managing signature updates.

13
Multi-Selectmedium

Which TWO steps are necessary to ensure that 'Threat Prevention' is protecting traffic against known vulnerabilities?

Select 2 answers
A.Disable 'App-ID' to prevent interference.
B.Ensure the 'Threats' dynamic update is downloaded and installed.
C.Manually restart the firewall after every update.
D.Enable SSL Decryption for all traffic.
E.Apply a Vulnerability Protection profile to the security policy rule.
AnswersB, E

Signatures must be up to date to detect new vulnerabilities.

Why this answer

Threat prevention requires active signatures and the application of those signatures via policy profiles.

14
MCQmedium

When managing multiple firewalls in Panorama, what is the best practice for handling software image updates?

A.Upload images to Panorama and use the 'Software' tab to push them to devices.
B.Use the 'Auto-Update' feature on firewalls only.
C.Download images directly on each firewall.
D.Use an external TFTP server for all devices.
AnswerA

Centralized upload ensures all firewalls receive the approved software version.

Why this answer

Uploading images to the Panorama server first allows for consistent deployment to all managed firewalls.

15
MCQeasy

What is the purpose of a 'Security Profile Group'?

A.To organize firewall administrators by department.
B.To collect all logs from a specific security zone.
C.To group firewall interfaces for load balancing.
D.To combine multiple security profiles into a single object for easier policy assignment.
AnswerD

This is the definition of a Security Profile Group.

Why this answer

A Security Profile Group is a container that holds multiple types of security profiles (AV, URL, Threat, etc.) to be applied as a single unit.

16
MCQmedium

An administrator wants to categorize traffic based on the 'Server' role in the network. Which feature should be used to tag this traffic for policy grouping?

A.Device Groups
B.Dynamic Address Groups
C.Static Address Groups
D.Security Profiles
AnswerB

DAGs use tags to group objects that meet specific criteria.

Why this answer

Dynamic Address Groups (DAGs) allow administrators to use tags to group objects dynamically based on attributes, such as server roles.

17
Multi-Selecthard

Which THREE of the following are valid Security Profile types?

Select 3 answers
A.Zone Routing
B.URL Filtering
C.Policy Optimizer
D.Vulnerability Protection
E.Anti-Spyware
AnswersB, D, E

Standard profile.

Why this answer

Anti-spyware, Vulnerability Protection, and URL Filtering are valid profiles.

18
MCQmedium

You are migrating existing on-premises Panorama appliances to Strata Cloud Manager (SCM). After establishing connectivity, you notice that your device groups are not appearing in the SCM interface. Which action is required to resolve this?

A.Manually export and import XML configurations for every device group.
B.Enable Panorama mode on SCM.
C.Re-register all managed firewalls directly to SCM via serial number.
D.Run the SCM migration utility to map Panorama device groups to SCM containers.
AnswerD

The migration tool is necessary to transition the hierarchy to SCM's container-based architecture.

Why this answer

SCM requires the migration of the Panorama hierarchy into the SCM structure using the SCM migration tool which syncs the configuration objects.

19
Multi-Selectmedium

Which TWO of the following steps are required to implement a successful Site-to-Site VPN with a third-party vendor?

Select 2 answers
A.Assign the tunnel interface to a security zone.
B.Configure an IKE Crypto Profile matching the vendor's settings.
C.Disable all logging on the tunnel interface.
D.Enable DHCP on the tunnel interface.
E.Configure the tunnel as an L2 bridge.
AnswersA, B

Interfaces must belong to a zone to be used in security policies.

Why this answer

Both IKE Phase 1 and Phase 2 crypto profiles must be configured correctly, and the tunnel interface must be assigned to a zone.

20
Multi-Selecthard

Which THREE criteria must be satisfied for a traffic session to match a specific NAT rule?

Select 3 answers
A.Security Profile
B.Destination Zone
C.App-ID
D.Destination Interface
E.Source Zone
AnswersB, D, E

The traffic destination zone must match the rule criteria.

Why this answer

NAT matching is based on the source zone, the destination zone, and the original destination IP/interface specified in the NAT rule configuration.

21
Multi-Selectmedium

Which TWO of the following are valid ways to deploy GlobalProtect?

Select 2 answers
A.Physical wire mode
B.Local Bridge Mode
C.Split Tunnel VPN
D.Full Tunnel VPN
E.Static VPN
AnswersC, D

Sends only specific traffic through the gateway.

Why this answer

GlobalProtect can be deployed as a full VPN or as a split-tunnel VPN, depending on the requirements.

22
MCQeasy

Which protocol does Panorama use to communicate with managed firewalls for configuration synchronization?

A.SSH
B.HTTP
C.SSL/TLS
D.SNMPv3
AnswerC

Panorama uses a secure SSL/TLS connection to manage firewalls.

Why this answer

Panorama uses a secure, encrypted SSL/TLS tunnel (often referred to as the PAN-DB or management tunnel) for configuration sync.

23
Multi-Selecteasy

Which of the following are valid methods for performing an initial configuration of a Palo Alto Networks NGFW? (Choose TWO)

Select 2 answers
A.Automatic Cloud provisioning via USB
B.Console port connection
C.Management interface (192.168.1.1)
D.SSH to the data plane interface
E.Bluetooth pairing
AnswersB, C

Direct serial connection is a standard method.

Why this answer

Initial access is typically performed via the Console port (serial) or the Management interface (default IP).

24
MCQmedium

A administrator needs to ensure that users are authenticated before accessing a web-based internal application. Which User-ID method provides the most granular control by prompting users via a captive portal?

A.Captive Portal
B.IP-to-User Mapping via XML API
C.Clientless VPN
D.GlobalProtect Transparent Authentication
AnswerA

Captive Portal is specifically designed to challenge users for credentials.

Why this answer

Captive portal provides explicit authentication for users accessing specific web resources, ensuring positive identification.

25
MCQhard

An administrator needs to enforce a consistent security policy across 50 branch firewalls using SCM. They want to ensure that any changes made at the local firewall level are overridden by SCM. Which setting must be configured?

A.Enable 'Local Policy Precedence' on all firewalls.
B.Set the 'Device Override' to 'Disabled' in the SCM container settings.
C.Disable 'Management Plane Access' for local admins.
D.Configure 'Auto-Commit' on every firewall.
AnswerB

Disabling device overrides ensures that local changes cannot deviate from the pushed SCM policy.

Why this answer

In SCM, the 'Inheritance' and 'Push' model ensures that central policies are enforced on target devices.

26
Multi-Selecthard

Which three components must be configured to enable GlobalProtect Clientless VPN? (Choose THREE)

Select 3 answers
A.Static NAT Rule
B.SSL/TLS Service Profile
C.RADIUS Server
D.GlobalProtect Portal
E.GlobalProtect Gateway
AnswersB, D, E

Required to secure the connection.

Why this answer

Clientless VPN requires a portal, a gateway, and a portal-to-gateway mapping or configuration.

27
MCQeasy

What is the primary function of the 'DNS Sinkhole' feature in a DNS Security profile?

A.To encrypt DNS traffic between the firewall and the ISP.
B.To allow a firewall to act as a DNS server for internal clients.
C.To cache DNS queries to improve network performance.
D.To redirect requests for malicious domains to a specific IP address to alert the administrator.
AnswerD

Sinkholing is used to identify and log clients attempting to resolve malicious domains.

Why this answer

DNS Sinkhole redirects a malicious DNS query to a fake IP address to identify compromised hosts.

28
Multi-Selectmedium

Which TWO of the following are required to successfully implement an App-ID based Security policy?

Select 2 answers
A.The 'Log at Session Start' option must be enabled.
B.The rule must have a specific URL Category defined.
C.The application must be explicitly defined in the 'Application' field of the Security policy.
D.The 'Service' field must be set to 'application-default'.
E.A 'Security Profile Group' must be attached to the rule.
AnswersC, D

Defining the application enables App-ID inspection.

Why this answer

Security policies require an App-ID (or 'any') and the 'Application Default' service port setting to ensure the application is correctly identified and restricted to its expected ports.

29
Multi-Selecteasy

Which TWO methods can be used to manage administrator access to a Palo Alto Networks firewall?

Select 2 answers
A.GlobalProtect Portal
B.Local Administrator Accounts
C.RADIUS Authentication
D.App-ID Override
E.SSL Forward Proxy
AnswersB, C

Local accounts are a standard management method.

Why this answer

Admin access can be managed via local database accounts or by integrating with external authentication services like RADIUS or TACACS+.

30
MCQeasy

Which command is used on a Palo Alto Networks firewall to verify current license entitlements from the CLI?

A.show system license
B.check license-status
C.request license info
D.debug license fetch
AnswerC

This command provides a detailed list of active and expired license entitlements.

Why this answer

'request license info' is the standard command to display the status and expiration of all installed licenses.

31
MCQhard

An application is failing to function correctly even though the Security policy allows the traffic. The App-ID is showing as 'incomplete'. What is the most likely cause?

A.The client sent a SYN packet but closed the connection before sending application-specific data.
B.The Security policy rule uses an App-ID group that does not include 'unknown-tcp'.
C.The traffic was dropped due to a mismatched TCP sequence number in the session.
D.The application is performing an encrypted handshake that the firewall cannot inspect without a Decryption policy.
AnswerA

The App-ID engine requires application-level data to identify the traffic; if the session terminates early, it remains 'incomplete'.

Why this answer

An 'incomplete' App-ID usually signifies that the TCP 3-way handshake occurred, but no further data was sent, or the data was malformed, preventing the firewall from identifying the application signature.

32
Multi-Selectmedium

Which TWO criteria are used by the firewall to match a security policy rule?

Select 2 answers
A.The number of packets in the flow.
B.The total duration of the session.
C.The physical MAC address of the source.
D.Source and Destination Zone.
E.The identified Application (App-ID).
AnswersD, E

Zones are fundamental for policy matching.

Why this answer

Security policies match traffic based on the packet's source/destination and the identified application.

33
Multi-Selecthard

Which THREE components are involved in configuring an IKE Gateway for a VPN?

Select 3 answers
A.Local interface.
B.VLAN ID.
C.Peer IP address.
D.Pre-Shared Key.
E.DHCP server scope.
AnswersA, C, D

The interface is the physical point of exit.

Why this answer

An IKE Gateway requires the interface used for the connection, the peer IP, and a Pre-Shared Key or certificate for authentication.

34
MCQeasy

Which interface type is used to connect the firewall to a switch for management or routing?

A.Virtual Wire
B.Layer 3
C.Tap
D.Layer 2
AnswerB

Layer 3 interfaces support IP routing.

Why this answer

Layer 3 interfaces are used for standard routing between zones.

35
MCQeasy

Which command is used to display the current User-ID mapping information on the CLI?

A.show logging user-id
B.test user-id
C.show system user-id
D.show user ip-user-mapping all
AnswerD

This is the correct command for viewing mappings.

Why this answer

The command 'show user ip-user-mapping all' provides the current IP to username mapping table.

36
MCQmedium

You are configuring a new Security Policy on a PAN-OS firewall. To adhere to the principle of least privilege, which configuration approach should you take for the destination zone and address?

A.Use the 'intrazone-default' policy to automatically allow traffic to all servers.
B.Define a specific Address Object for the destination server and bind it to the correct zone.
C.Set destination zone to 'any' and destination address to 'any' to ensure traffic flow.
D.Configure the security policy to reference the interface IP rather than an Address Object.
AnswerB

This restricts traffic to a specific destination object.

Why this answer

Least privilege requires restricting access to only the necessary resources. Using specific objects rather than 'any' is the standard method.

37
Multi-Selectmedium

Which TWO actions should an administrator perform to prepare for a large-scale firmware upgrade across an enterprise using Panorama?

Select 2 answers
A.Delete all old logs to free up space.
B.Upload the firmware images to Panorama.
C.Verify the 'Compatibility Matrix' for all firewall models.
D.Disable all security policies.
E.Manually SSH into every firewall to check disk space.
AnswersB, C

Images must be local to Panorama for distribution.

Why this answer

Preparation involves verifying hardware compatibility and ensuring the images are pre-loaded on the Panorama server.

38
Multi-Selectmedium

Which TWO of the following are features of Content-ID?

Select 2 answers
A.Vulnerability Protection
B.Data Filtering
C.User-ID mapping
D.App-ID identification
E.Zone protection
AnswersA, B

Blocks exploit attempts.

Why this answer

Content-ID encompasses both threat prevention (via profiles) and data filtering.

39
MCQhard

You are troubleshooting an issue where a specific Threat Prevention profile is not applying correctly via Panorama. The setting is configured in a Template, but the firewall shows a different value. What should you check?

A.The local device group lockdown setting.
B.The Panorama log collector status.
C.The firewall's OS version compatibility.
D.The order of the templates within the Template Stack.
AnswerD

Templates at the top of the stack override those at the bottom.

Why this answer

Template Stacks can have multiple templates, and the order dictates which takes precedence for shared objects.

40
MCQhard

When migrating from Panorama to SCM, what happens to the existing log data stored on the Panorama appliance?

A.It is automatically moved to SCM storage.
B.It is purged immediately upon successful migration.
C.It is exported as a CSV file to the administrator's desktop.
D.It remains on the Panorama appliance and must be archived manually.
AnswerD

Panorama logs stay local; migration tools typically migrate configuration, not data.

Why this answer

Log data is not migrated to SCM automatically; it remains on the Panorama appliance until purged by local retention policies.

41
MCQhard

You are setting up an SSL Decryption policy. If you want to exclude traffic to financial websites to comply with privacy laws, how do you configure it?

A.Add a 'No Decrypt' rule matching the 'financial-services' URL category.
B.Configure a separate decryption broker.
C.Disable decryption for the entire zone.
D.Delete the financial sites from the allowed list.
AnswerA

This is the standard procedure to bypass decryption for privacy.

Why this answer

You create a 'No Decrypt' rule in the Decryption Policy, using URL categories to match financial sites.

42
Multi-Selectmedium

Which TWO of the following are benefits of using App-ID over port-based security policies?

Select 2 answers
A.Requires no updates to the signature database.
B.Automatically creates security policies.
C.Prevents applications from bypassing security by using non-standard ports.
D.Increases throughput of the firewall.
E.Enables visibility into encrypted traffic (if SSL decryption is used).
AnswersC, E

App-ID identifies the app by signature, not port.

Why this answer

App-ID provides visibility into the actual application, regardless of the port, and allows for better security posture.

43
MCQeasy

Which component of the Palo Alto Networks architecture is responsible for the 'Single Pass' processing engine?

A.Panorama
B.Data Plane
C.Management Plane
D.Control Plane
AnswerB

The data plane performs packet processing via the Single Pass architecture.

Why this answer

The Single Pass Parallel Processing (SP3) architecture integrates networking, security, and management on the dataplane.

44
MCQhard

When configuring an interface for DHCP client, where do you set the default gateway?

A.Network > Interfaces > Advanced
B.Device > Setup > Services
C.Network > Virtual Router > Static Routes
D.The gateway is learned via the DHCP server response.
AnswerD

DHCP client interfaces automatically learn the gateway from the DHCP server.

Why this answer

When an interface is set to DHCP client, it receives the gateway from the DHCP server; you do not manually set it in the interface config.

45
MCQmedium

If a packet matches a Security Policy rule, but the application is not identified yet, what action does the firewall take?

A.It allows the packet based on the port-based match.
B.It drops the packet immediately.
C.It buffers the packet until identification is complete.
D.It rejects the packet and sends a TCP Reset.
AnswerA

The firewall uses the port to allow traffic until the App-ID engine identifies it.

Why this answer

The firewall waits for enough packets to identify the application. If it matches a rule, it keeps the session open; otherwise, it may drop it.

46
Multi-Selecthard

Which THREE components are involved in the Prisma Access architecture for protecting mobile users?

Select 3 answers
A.Service Connection
B.GlobalProtect App
C.Local Branch Firewall
D.GlobalProtect Gateway
E.Identity Provider (SAML/LDAP)
AnswersB, D, E

Used by the client to connect.

Why this answer

Mobile users rely on the GlobalProtect app, the Cloud Service (gateway/portal), and the authentication source.

47
MCQmedium

When using OSPF with a Palo Alto Networks firewall, which area type would you configure to ensure the firewall does not receive external routing information while still maintaining connectivity to the backbone?

A.Totally Stubby Area
B.NSSA
C.Backbone Area (Area 0)
D.Standard Area
AnswerA

Totally Stubby areas minimize the routing table size by injecting only a default route.

Why this answer

A Totally Stubby Area allows the firewall to reach the backbone via a default route while filtering out external and inter-area routes to save resources.

48
MCQhard

A security policy with a 'Log at Session End' setting is missing log entries for long-lived sessions. Why might this happen?

A.The 'Log at Session Start' option was not checked.
B.The session has not yet terminated.
C.The log buffer is full.
D.The session is being decrypted.
AnswerB

Long-lived sessions will not generate a 'Session End' log until the session is actually closed.

Why this answer

By default, logs are generated when the session ends. If a session is very long, it may need a log interval configured to generate interim logs.

49
Multi-Selectmedium

Which three items must be configured to successfully implement a Source NAT rule? (Choose THREE)

Select 3 answers
A.Security Policy Rule
B.Translated Address
C.Decryption Profile
D.Source Zone
E.Destination Zone
AnswersB, D, E

Mandatory to define the new IP address.

Why this answer

NAT rules require source/destination zones, source/destination interfaces, and the translation type.

50
MCQeasy

When a user connects via GlobalProtect, how does the firewall identify the user if they are not in the AD group?

A.It blocks the traffic by default.
B.It falls back to the IP-to-User mapping table.
C.It requests the MAC address.
D.It uses the machine name.
AnswerB

If no GP session exists, the firewall checks its IP-to-User map.

Why this answer

The firewall can identify users via the GlobalProtect portal authentication logs or by falling back to the IP-to-User mapping.

51
MCQhard

You are troubleshooting a performance issue in Prisma Access. Users report slow access to SaaS applications. You suspect the issue is related to the path selection. Which tool should you use to analyze the latency between the user's mobile client and the Service Connection?

A.Traffic Logs in Panorama
B.GlobalProtect App logs
C.Prisma Access Insights
D.ACC (Application Command Center)
AnswerC

Prisma Access Insights is designed specifically for monitoring performance and latency.

Why this answer

The Prisma Access Insights tool provides detailed telemetry regarding user latency and path performance.

52
MCQhard

You are configuring Advanced URL Filtering. Users report that a site is being blocked, but the category is 'Newly Registered Domains'. How can you allow access to this specific site while keeping the policy for other newly registered domains?

A.Add the site to the 'Allow List' in the URL Filtering profile object assigned to the security policy.
B.Move the security policy to the top of the policy list.
C.Add the site to the 'Blocked' list in the URL Filtering profile.
D.Create a new URL category and add the domain to it, then block that category.
AnswerA

The Allow List within a URL Filtering profile overrides category-based blocks.

Why this answer

URL Filtering allows for category overrides within a profile to exempt specific sites from broad category-based blocking.

53
Multi-Selectmedium

Which THREE items are necessary for a properly configured Security Policy rule?

Select 3 answers
A.Application
B.Source Zone
C.Admin Role
D.Panorama Template
E.Destination Zone
AnswersA, B, E

Fundamental match criterion.

Why this answer

Policies require zones, addresses, and applications to function as intended.

54
Multi-Selectmedium

Which three settings are part of a Zone Protection Profile? (Choose THREE)

Select 3 answers
A.User-ID Mapping
B.Flood Protection
C.Decryption Policy
D.Packet-based Attack Protection
E.Reconnaissance Protection
AnswersB, D, E

Included in the profile.

Why this answer

Zone Protection includes DoS protection, reconnaissance protection, and packet-based attack protection.

55
Multi-Selecthard

Which THREE of the following are consequences of enabling 'Log at Session End'?

Select 3 answers
A.Provides accurate session duration.
B.Forces the session to terminate.
C.Provides accurate byte counts.
D.Immediately notifies the administrator.
E.Provides comprehensive App-ID details.
AnswersA, C, E

Only available at session end.

Why this answer

Logging at session end provides total byte counts, accurate duration, and comprehensive application details.

56
Multi-Selecthard

Which THREE criteria can be used to define a security policy for granular control?

Select 3 answers
A.BGP peer status.
B.App-ID.
C.User-ID (User/Group).
D.Interface physical status.
E.Source and Destination Zones.
AnswersB, C, E

App-ID allows filtering by specific application signatures.

Why this answer

Security policies can use source/destination zones, specific user identity, and application identification.

57
MCQmedium

An administrator observes that traffic is being correctly identified by App-ID, but the firewall is not applying the expected security profile. What is the most likely reason?

A.The Zone protection profile is misconfigured.
B.App-ID is disabled globally.
C.Decryption is not enabled.
D.The Security Policy is missing an attached Security Profile Group.
AnswerD

Without a profile group, the firewall will permit traffic without applying advanced security features.

Why this answer

Security profiles are only applied to traffic that is allowed by a Security Policy. If the policy does not have a profile group attached, the action is simply 'allow' without inspection.

58
MCQmedium

You need to allow traffic based on user group membership. Which feature must be configured to map users to their group information?

A.App-ID
B.Device-ID
C.User-ID
D.Content-ID
AnswerC

User-ID is the feature that gathers group membership and identity mapping.

Why this answer

User-ID mappings (via agent or server monitoring) are required to map IP addresses to usernames and group memberships.

59
MCQmedium

An administrator is unable to push a configuration to a firewall managed by Panorama. The error message indicates a 'Template conflict'. What is the most likely cause?

A.The Panorama license has expired.
B.The Template Stack order is incorrectly configured, causing overlapping values.
C.The firewall is in maintenance mode.
D.The device group is locked by another administrator.
AnswerB

Template stacks apply settings in order; conflicts occur when multiple templates in the stack define the same parameter.

Why this answer

A template conflict usually occurs when a setting is defined in both the Device-level configuration and the Panorama Template stack without proper stack ordering.

60
MCQhard

A company requires that traffic from the VPN zone to the Untrust zone undergoes source NAT using a specific interface IP. Which configuration step is mandatory to ensure this traffic is correctly matched?

A.Disable 'Address Translation' in the NAT rule.
B.Enable 'Proxy ARP' on the egress interface.
C.Select the specific source zone and destination zone in the NAT rule.
D.Configure a policy-based forwarding rule instead of NAT.
AnswerC

NAT rules are zone-based; you must specify the source and destination zones for the rule to trigger.

Why this answer

The source NAT rule must explicitly match the source zone and destination zone of the traffic, along with the source interface if specified.

61
MCQeasy

Which object type in PAN-OS should be used to group multiple IP addresses for use in a security policy?

A.Application Group
B.Tag
C.Address Group
D.Service Group
AnswerC

Address groups are the correct container for multiple IP objects.

Why this answer

Address Groups allow grouping of address objects for efficient policy management.

62
MCQhard

What is the primary difference between a 'Pre-rule' and a 'Post-rule' in a Panorama-managed environment?

A.Pre-rules are only for NAT.
B.Post-rules override Pre-rules.
C.Local rules can override Pre-rules.
D.Pre-rules are evaluated before local rules; Post-rules are evaluated after.
AnswerD

This is the order of precedence in Panorama hierarchies.

Why this answer

Pre-rules are evaluated before local rules, while Post-rules are evaluated after local rules.

63
MCQmedium

An administrator needs to ensure that internal users can access a public web server using its public IP address even when they are physically inside the internal network. Which NAT type and configuration approach should be used?

A.Create a static NAT rule with a translation type of 'Bidirectional' in the Source NAT tab.
B.Enable 'DNS Sinkhole' on the Security policy to map the public IP to the private IP internally.
C.Enable 'Proxy ARP' on the external interface for the public IP address.
D.Configure a Destination NAT rule with the internal zone as both the source and destination zone.
AnswerD

This is the standard configuration for NAT Hairpinning on a PAN-OS device.

Why this answer

NAT Hairpinning (or NAT Reflection) allows internal traffic to be translated when destined for an internal resource via a public IP, by creating a NAT rule where the source zone and destination zone are the same.

64
MCQmedium

If a packet matches a Security Policy rule, but the application is not explicitly defined in the rule, what happens to the traffic?

A.The packet is matched based on the defined service (port).
B.The packet is automatically dropped.
C.The traffic is bypassed.
D.The firewall prompts for manual identification.
AnswerA

If App-ID is not specific, the firewall falls back to the defined port/service in the rule.

Why this answer

If App-ID is not explicitly matched or is 'unknown', the firewall follows the action defined in the security policy (e.g., allow or deny).

65
Multi-Selectmedium

Which three actions can be taken when a match occurs in a Security Policy rule? (Choose THREE)

Select 3 answers
A.Allow
B.Reset-Both
C.Monitor
D.Deny
E.Redirect
AnswersA, B, D

Allow is a standard policy action.

Why this answer

Standard Security Policy actions include Allow, Deny, Drop, and Reset.

66
Multi-Selectmedium

Which TWO methods can be used to monitor the status of a configuration push from Panorama?

Select 2 answers
A.Check the firewall's local 'Traffic' log.
B.System log export
C.Use the CLI 'show system state' command.
D.Panorama Tasks menu
E.Commit Status window
AnswersD, E

The Tasks window is the primary place to view progress.

Why this answer

The Tasks interface and the 'Commit Status' window provide real-time updates on push operations.

67
MCQhard

You have a policy matching 'web-browsing' but traffic is being denied. What is the most likely cause?

A.The dependent application, such as 'ssl', is not allowed in the policy.
B.The source zone is incorrect.
C.The firewall is in transparent mode.
D.The security profile is missing.
AnswerA

App-ID dependencies must be explicitly allowed.

Why this answer

If the App-ID is correct but traffic is denied, the dependent application (like ssl) might be missing.

68
MCQeasy

When adding a new Security Policy rule, what is the default position for the rule if you do not specify 'Top' or 'Bottom'?

A.Immediately below the selected rule.
B.Bottom
C.Middle
D.Top
AnswerB

Rules default to the bottom of the rulebase.

Why this answer

By default, new rules are placed at the bottom of the security policy base, above the default cleanup rules.

69
Multi-Selectmedium

Which TWO settings are configured within a GlobalProtect Gateway to manage user access?

Select 2 answers
A.Interface speed settings.
B.Authentication profile.
C.Tunnel interface selection.
D.SNMP community strings.
E.Global NTP server configuration.
AnswersB, C

Authentication profiles manage user credentials.

Why this answer

Gateway settings define the authentication profile and the specific tunnel settings for the client.

70
MCQmedium

When managing infrastructure, what is the best practice for handling 'Security Profile Groups'?

A.Use a common group for similar traffic types to ensure consistent security policy enforcement.
B.Only apply groups to traffic destined for the Internet.
C.Avoid using groups and always apply individual profiles to rules.
D.Create a unique group for every single security policy rule.
AnswerA

Grouping promotes consistency and reduces administrative burden.

Why this answer

Security Profile Groups allow for standardized enforcement across multiple rules, simplifying management and updates.

71
Multi-Selecthard

Which THREE tasks are performed by the Dataplane during traffic processing?

Select 3 answers
A.Session lookup.
B.Packet forwarding.
C.Management interface updates.
D.User-ID mapping updates.
E.Security policy evaluation.
AnswersA, B, E

Session lookup is critical for fast-path traffic.

Why this answer

The dataplane is responsible for session lookup, security policy enforcement, and packet forwarding.

72
MCQhard

When troubleshooting a site-to-site VPN that is stuck in 'INIT' status, what is the most likely cause?

A.Mismatched DH Group in Phase 2.
B.Incorrect peer IP address or network connectivity blocking UDP 500/4500.
C.Incorrect Proxy-ID settings.
D.Expired certificate on the peer.
AnswerB

If the peer doesn't respond to IKE negotiation, the state remains INIT.

Why this answer

An 'INIT' status typically indicates that the firewall is waiting for an IKE response. This is usually caused by network reachability issues or incorrect peer settings.

73
Multi-Selecthard

Which TWO of the following are required to enable full visibility into threats inside SSL traffic?

Select 2 answers
A.GlobalProtect Portal
B.Security Profile (e.g., Anti-Virus)
C.Device Certificate
D.SSL Decryption Policy
E.External Logging server
AnswersB, D

Required to scan the content.

Why this answer

To see inside SSL, you need to decrypt it and apply a security profile to scan the decrypted content.

74
MCQmedium

You want to block a specific URL category for all users except for the 'HR' department. How should the security policy be structured?

A.Create an allow rule for 'HR' above a block rule for the category.
B.Create a block rule for the category, then place an allow rule for 'HR' below it.
C.Use an Object Group to exclude HR from the block rule.
D.Configure a NAT rule to redirect HR traffic.
AnswerA

Security policies are evaluated top-down; the first match wins.

Why this answer

You should create a rule that allows 'HR' access to the category, and a subsequent rule that blocks everyone else.

75
MCQmedium

What is the purpose of the 'Pre-Rule' and 'Post-Rule' sections in a Panorama-managed firewall?

A.To speed up the policy lookup.
B.To provide backup for failed rules.
C.To organize rules by date.
D.To ensure global policies are enforced before local policies.
AnswerD

Pre-rules provide a hierarchy for global enforcement.

Why this answer

Pre-rules are evaluated before local rules, ensuring that global corporate policies override local branch configurations.

Page 1 of 3

Page 2

All pages