Courseiva

Certified Network Security Professional (NetSec-Pro) (NetSec-Pro) — Questions 151191

191 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
MCQmedium

What is the effect of setting a Security Policy rule action to 'Drop' versus 'Reset-Both'?

A.Reset-Both is only for TCP, while Drop is only for UDP.
B.Drop is only available for inter-zone traffic.
C.Drop consumes more firewall CPU cycles.
D.Reset-Both informs the client and server that the connection is closed.
AnswerD

Resetting allows the endpoints to clean up their state immediately.

Why this answer

'Drop' silently discards the packet, while 'Reset-Both' actively informs the sender and receiver that the connection is terminated.

152
MCQhard

An administrator wants to block a specific file type from being uploaded. Which profile is required?

A.URL Filtering
B.File Blocking
C.Vulnerability Protection
D.Anti-Virus
AnswerB

File blocking is used to restrict uploads/downloads.

Why this answer

File Blocking profiles are designed to block specific file types based on the file extension and type.

153
MCQhard

An administrator is implementing PBF (Policy Based Forwarding). What is a requirement for PBF to function correctly?

A.The PBF rule must be placed in the policy and reference a valid egress interface or next hop.
B.The destination must always be an IP address object.
C.PBF must be enabled at the global configuration level.
D.PBF can only be used on Layer 2 interfaces.
AnswerA

PBF acts as a policy-based override and requires specific egress parameters.

Why this answer

PBF requires a defined source zone, and the rule must be matched before the routing table determines the exit interface, otherwise the standard routing table takes precedence.

154
MCQmedium

Which of the following is an example of a Security Profile?

A.Vulnerability Protection
B.Policy Rule
C.Interface Configuration
D.Address Object
AnswerA

Vulnerability Protection is a standard security profile.

Why this answer

Anti-Virus, Anti-Spyware, Vulnerability Protection, and URL Filtering are all Security Profiles.

155
Multi-Selecthard

Which THREE features are provided by the Strata Cloud Manager 'Subscription Management' interface?

Select 3 answers
A.View expiration dates for security subscriptions.
B.Automate the deployment of licenses to firewalls.
C.Generate license renewal quotes.
D.Configure threat signature update frequency.
E.View current subscription status for all managed devices.
AnswersA, B, E

SCM tracks expiration dates across the global deployment.

Why this answer

SCM provides centralized visibility into license status, expiration, and automated renewal/deployment workflows.

156
MCQmedium

What is the benefit of using an 'Aggregate Interface'?

A.It allows the firewall to act as a layer 2 switch.
B.It provides higher bandwidth and link redundancy.
C.It enables hardware-level encryption.
D.It increases the number of available sub-interfaces.
AnswerB

Aggregation combines multiple links for throughput and failover.

Why this answer

Aggregate interfaces provide both increased bandwidth and link redundancy using LACP.

157
MCQmedium

When managing WildFire, how can you ensure that you are receiving the latest threat signatures as soon as they are generated?

A.Enable 'Push Notifications' in the Device > Setup menu.
B.Use a local WildFire appliance in 'Synchronous' mode.
C.Set the 'WildFire Update Schedule' to 'Every 1 minute'.
D.Force a manual 'Check Now' every hour.
AnswerC

The 1-minute interval is the fastest available setting.

Why this answer

Setting the 'WildFire Update Schedule' to the most frequent interval (every minute) ensures near-instant signature delivery.

158
MCQmedium

You are deploying Advanced URL Filtering. How does the 'Credential Phishing' prevention feature operate?

A.It analyzes the URL to determine if it is a known malicious site.
B.It detects and blocks the submission of enterprise credentials to untrusted or newly registered websites.
C.It requires an agent installed on the endpoint to monitor browser activity.
D.It monitors all inbound traffic for known phishing signatures.
AnswerB

This describes the core mechanism of Credential Phishing prevention.

Why this answer

Advanced URL Filtering inspects HTTP POST requests and uses URL categorization to detect and block credential theft.

159
Multi-Selecteasy

Which TWO locations in the PAN-OS web interface are used to check the status of CDSS subscriptions?

Select 2 answers
A.Network > Interfaces.
B.Dashboard > Widgets > General Information.
C.Device > Licenses.
D.Monitor > Logs.
E.Policies > Security.
AnswersB, C

The General Information widget summarizes license status.

Why this answer

Subscription status is typically found in the Dashboard or the Device licensing page.

160
Multi-Selecteasy

Which TWO of the following are valid components of a PAN-OS Security Policy?

Select 2 answers
A.Source Zone
B.Destination Zone
C.Fan speed
D.Management IP
E.System BIOS version
AnswersA, B

Required for policy matching.

Why this answer

A security policy requires matching criteria like Source/Destination zones, addresses, and applications.

161
Multi-Selecthard

Which THREE items must be verified when troubleshooting traffic that is not being correctly identified as the intended application?

Select 3 answers
A.Verify the MAC address table.
B.Ensure the App-ID override policy is correctly configured for the traffic.
C.Check the system clock synchronization.
D.Check if SSL decryption is required to inspect the application traffic.
E.Verify the application is not being misidentified due to non-standard ports.
AnswersB, D, E

Overrides force the identification if the engine cannot determine the app.

Why this answer

Correct App-ID matching depends on having correct port mappings, proper decryption, and the use of the most specific policy.

162
MCQeasy

Where do you configure a URL Filtering profile?

A.Policies > Security
B.Network > Profiles
C.Objects > Security Profiles
D.Device > Setup
AnswerC

Correct path for security profiles.

Why this answer

URL Filtering profiles are configured under the Objects tab in the Security Profiles section.

163
MCQmedium

When using Panorama, an administrator wants to push policies to specific firewalls based on their geographical location. Which feature should be used?

A.Device Groups
B.Panorama Templates
C.Address Groups
D.Policy Groups
AnswerA

Device Groups are the primary mechanism for grouping firewalls for shared configuration.

Why this answer

Device Groups allow for hierarchical organization of firewalls, enabling targeted policy application.

164
MCQeasy

Which type of VPN tunnel configuration is required for a Palo Alto Networks firewall to act as a client connecting to a third-party VPN gateway?

A.Policy-based VPN
B.SSL VPN
C.L2TP VPN
D.Route-based VPN
AnswerD

Route-based VPNs use tunnel interfaces, making them the standard choice for PAN-OS.

Why this answer

A Route-based VPN is the standard for Palo Alto Networks, as it creates a virtual tunnel interface, which is required for routing traffic through the VPN.

165
MCQeasy

Which type of interface is used to connect to a switch in a Layer 2 configuration where the firewall acts as a transparent bridge?

A.Layer 2 interface
B.Virtual Wire interface
C.Aggregate interface
D.Layer 3 interface
AnswerA

Layer 2 interfaces are used for transparent bridging.

Why this answer

Layer 2 interfaces are designed for transparent switching and do not require IP addresses for traffic processing.

166
MCQmedium

An administrator needs to restrict access to a specific internal server to only one remote VPN user. What is the most secure method?

A.Set the user to 'Any' in the security policy.
B.Create a NAT policy to map the user's IP to the server.
C.Create a security policy with a Source User-ID for the VPN user and a Destination Object for the server.
D.Assign the VPN user a unique IP pool.
AnswerC

This leverages user identity and object-based filtering for precise access control.

Why this answer

Using a combination of a dedicated security policy with a specific User-ID/Group-ID source and a specific destination address object is the standard practice for least privilege access.

167
MCQhard

You are troubleshooting a connection that is being blocked despite a matching policy. Which tool is best for determining which specific rule is hitting the traffic?

A.Packet Capture (pcap)
B.GlobalProtect logs
C.Policy Test Tool (test security-policy-match)
D.Traffic Monitor
AnswerC

This command simulates traffic and returns the matching rule.

Why this answer

The Policy Optimizer and the Test Policy match tool are essential for identifying why traffic is being dropped or allowed.

168
MCQhard

Which feature allows an administrator to prevent unauthorized users from using a stolen credential by requiring a second form of authentication?

A.Authentication Portal
B.MFA Profile
C.Credential Protection Profile
D.GlobalProtect Authentication Override
AnswerB

The MFA Profile is the configuration object that links the firewall to an external MFA provider.

Why this answer

Multi-Factor Authentication (MFA) profiles are integrated into the Authentication Policy to enforce secondary verification.

169
Multi-Selecteasy

Which THREE are types of security policies that can be configured on a Palo Alto Networks firewall?

Select 3 answers
A.Firmware update policy
B.User mapping policy
C.Decryption Policy
D.NAT Policy
E.Security Policy
AnswersC, D, E

Fundamental policy type.

Why this answer

Palo Alto firewalls support Security, NAT, and Decryption policies.

170
Multi-Selectmedium

Which TWO logs are essential when troubleshooting a user who cannot connect to the internet?

Select 2 answers
A.System Logs.
B.Decryption Logs.
C.Traffic Logs.
D.Config Logs.
E.Threat Logs.
AnswersA, C

System logs show interface or route events.

Why this answer

Traffic logs verify if the traffic is being hit by a policy, and System logs can indicate if the interface itself is down or flapping.

171
MCQeasy

How does the 'Advanced URL Filtering' subscription improve upon standard URL Filtering?

A.It provides real-time, cloud-based analysis of unknown or newly registered domains.
B.It allows the firewall to bypass SSL decryption for certain categories.
C.It includes an integrated VPN client for remote workers.
D.It allows for more custom URL categories.
AnswerA

Real-time categorization is the primary benefit of the Advanced subscription.

Why this answer

Advanced URL Filtering uses real-time analysis rather than just static database lookups to identify malicious sites.

172
MCQmedium

You are configuring 'Log Forwarding' from Panorama to an external SIEM. Which object must you define in Panorama to facilitate this?

A.Log Collector Profile
B.Reporting Profile
C.External Service Profile
D.Log Forwarding Profile
AnswerD

This profile defines the destination server for external log forwarding.

Why this answer

A Log Forwarding Profile must be created and applied to policies to define where logs are sent.

173
Multi-Selecthard

Which THREE of the following are considered 'App-ID' identification techniques?

Select 3 answers
A.Signature-based identification
B.Protocol decoding
C.Source IP inspection
D.Heuristic/Behavioral analysis
E.MAC address filtering
AnswersA, B, D

The primary technique for most apps.

Why this answer

App-ID uses signatures, protocol decoding, and behavioral analysis to identify applications.

174
MCQmedium

You are using the 'Policy Optimizer' in Panorama to identify unused rules. After identifying a rule, what is the safest way to remove it?

A.Disable the rule and monitor for issues, then delete after a set period.
B.Export the policy to CSV and re-import.
C.Immediately delete the rule.
D.Rename the rule to 'Old_Rule' and leave it.
AnswerA

Disabling the rule allows for a quick rollback if production traffic is affected.

Why this answer

Policy Optimizer allows for safe rule removal by tracking 'hits' over time, ensuring the rule is truly redundant.

175
MCQmedium

An administrator observes that dynamic updates for App-ID and Threat signatures are failing. Which troubleshooting step should be performed first?

A.Restart the management plane process using the 'debug software restart process management-plane' command.
B.Rebuild the configuration database using 'request system reset-config'.
C.Increase the timeout value in the 'Device > Setup > Management' tab.
D.Check the 'Device > Licenses' page to ensure the 'Threat Prevention' or 'PAN-DB' subscription is active.
AnswerD

Without an active subscription, dynamic updates cannot be downloaded or installed.

Why this answer

The firewall requires a valid support license and connectivity to the Palo Alto Networks update servers (updates.paloaltonetworks.com).

176
Multi-Selectmedium

Which TWO methods can be used to ensure the firewall has the latest threat intelligence for blocking malicious traffic?

Select 2 answers
A.VLAN tagging.
B.Manual IP entry.
C.DHCP reservation.
D.Dynamic Updates.
E.External Dynamic Lists.
AnswersD, E

Dynamic updates download the latest threat signatures.

Why this answer

Dynamic updates and external dynamic lists (EDLs) are the two primary ways to keep security intelligence current.

177
MCQhard

An administrator notices that the 'Commit' progress on Panorama hangs at 99%. What is the most effective way to troubleshoot this?

A.Check the 'Tasks' menu in Panorama for detailed error logs on the specific job.
B.Reboot the Panorama appliance.
C.Clear the configuration cache on the firewall.
D.Increase the timeout value in Management Settings.
AnswerA

The Tasks menu provides granular logs for why a commit is failing or hanging.

Why this answer

The task manager in Panorama shows the status of ongoing jobs, and clicking on the job ID reveals detailed logs of the push process.

178
Multi-Selecthard

Which THREE items are included in a Panorama configuration 'Export'?

Select 3 answers
A.Security policy rules
B.Template network configurations
C.Log data files
D.Historical threat reports
E.Address and Service objects
AnswersA, B, E

All policy rules are included in the configuration export.

Why this answer

A Panorama configuration export typically includes the full XML policy set, device group structure, and object definitions.

179
Multi-Selectmedium

Which TWO of the following are benefits of using Strata Cloud Manager over traditional on-premises Panorama?

Select 2 answers
A.Automatic updates and feature availability.
B.Direct root access to the management server.
C.Support for legacy PAN-OS versions 6.0 and below.
D.Ability to host custom local scripts.
E.Elimination of on-premises hardware maintenance for the management plane.
AnswersA, E

As a SaaS solution, SCM receives updates without manual appliance patching.

Why this answer

SCM provides cloud-native benefits such as reduced infrastructure overhead and automated updates.

180
MCQhard

Why should you use an App-ID 'Group' in a security policy?

A.To force traffic over specific ports.
B.To enable SSL decryption for those applications.
C.To reduce policy rule count and simplify management.
D.To increase security by blocking unknown traffic.
AnswerC

Grouping helps manage related applications in fewer rules.

Why this answer

App-ID groups simplify policy management by allowing you to update the group once rather than individual policies.

181
MCQmedium

What is the purpose of the 'Zone Protection Profile'?

A.To enforce SSL decryption on traffic within the zone.
B.To defend against reconnaissance and floods at the zone ingress.
C.To protect the management plane from web attacks.
D.To map IP addresses to user identities.
AnswerB

These profiles protect the zone from various network-layer attacks.

Why this answer

Zone Protection Profiles are used to defend against reconnaissance and DoS attacks at the zone ingress point.

182
MCQhard

An administrator needs to enable Threat Prevention to protect against a specific zero-day exploit. How are the signatures for these new threats delivered to the firewall?

A.By manually downloading the threat signature database from the Customer Support Portal.
B.Through the scheduled 'Threats' dynamic update package.
C.Through the daily WildFire update package.
D.By enabling the 'Automatic Update' feature in the Device > Software menu.
AnswerB

The 'Threats' dynamic update contains the latest vulnerability and exploit signatures.

Why this answer

Threat Prevention signatures are delivered via dynamic updates, specifically 'Threats' updates, which are pushed to the firewall.

183
MCQmedium

An administrator wants to use User-ID. What is the primary benefit of mapping IP addresses to usernames?

A.To increase firewall throughput.
B.To reduce the number of address objects.
C.To bypass the need for SSL decryption.
D.To enable policy enforcement based on user or group membership.
AnswerD

Identity-based policy is the primary driver for User-ID.

Why this answer

User-ID allows security policies to be based on identities rather than IP addresses.

184
MCQmedium

Which action is required to ensure that WildFire analysis results are applied to traffic as quickly as possible?

A.Configure the WildFire profile to use the 'Real-time' analysis mode.
B.Enable 'Packet Capture' for all security policies.
C.Increase the WildFire cloud region to the nearest geographic site.
D.Set the WildFire forwarding to 'Legacy' mode.
AnswerA

Real-time mode minimizes latency in file analysis and protection.

Why this answer

Enabling the 'Real-time' setting in the WildFire profile ensures files are sent and results are acted upon immediately.

185
MCQeasy

Which plane on a Palo Alto Networks firewall is responsible for the web interface and CLI?

A.Forwarding Plane
B.Management Plane
C.Security Plane
D.Data Plane
AnswerB

Management plane is for administrative tasks.

Why this answer

The Management Plane handles all management tasks, including the GUI and CLI.

186
MCQmedium

Which action should be taken if you want to log traffic matching a specific policy?

A.Enable logging in the Zone object.
B.Enable logging in the Device settings.
C.Enable logging in the Interface settings.
D.Enable logging in the 'Actions' tab of the Security Policy.
AnswerD

The Actions tab contains the logging controls.

Why this answer

Logging is enabled in the 'Actions' tab of the Security Policy rule.

187
MCQeasy

What does the 'Zone Protection Profile' protect against?

A.Denial of Service (DoS) and reconnaissance attacks.
B.Unauthorized user access.
C.Malware downloads.
D.Application-specific exploits.
AnswerA

This is the primary purpose of zone protection.

Why this answer

Zone Protection profiles guard against flood attacks and reconnaissance at the zone level.

188
Multi-Selecthard

Which THREE of the following items are required to successfully deploy a Prisma Access Service Connection?

Select 3 answers
A.User authentication list
B.Service connection name
C.Prisma Access Gateway IP
D.Destination IP range
E.BGP or Static Route configuration
AnswersB, D, E

Required identifier for the connection.

Why this answer

Service connections require an IP address, a destination network, and a associated interface/tunnel.

189
MCQmedium

An administrator is configuring a Site-to-Site VPN and needs to ensure that the tunnel interface is included in the routing table. What must be done to ensure traffic can be routed across the tunnel?

A.Configure the tunnel interface in a separate security zone.
B.Change the tunnel interface type to Layer 3.
C.Enable Proxy-ID settings on the tunnel interface.
D.Add a static route in the Virtual Router pointing to the remote subnet using the tunnel interface as the next hop.
AnswerD

A route is required to direct traffic towards the tunnel interface.

Why this answer

To route traffic into a VPN tunnel, the tunnel interface must be associated with a Virtual Router and have a static or dynamic route pointing to the remote subnet with the tunnel interface as the next hop.

190
MCQmedium

You have configured a custom application object for a proprietary internal tool. When you attempt to use this object in a Security Policy, traffic is still being denied. What is a common configuration error?

A.The application signature does not match the traffic's port or pattern.
B.The application must be assigned to the 'web' category.
C.The App-ID must be added to a service group.
D.The application requires an SSL decryption policy first.
AnswerA

If the traffic pattern doesn't match the signature criteria, the firewall will not identify it as the custom app.

Why this answer

For custom applications, you must ensure the 'Signature' tab has the correct port and protocol, and that the application is correctly referenced in the policy.

191
Multi-Selecthard

Which three types of logs can be generated by a PAN-OS firewall? (Choose THREE)

Select 3 answers
A.Threat logs
B.Traffic logs
C.Application logs
D.Interface logs
E.System logs
AnswersA, B, E

Generated when threats are detected.

Why this answer

The firewall generates various logs, including traffic, threat, and system logs.

Page 2

Page 3 of 3

All pages