NETSEC-ANALYST Exam Questions
421 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 2 of 9.
- Question #54
An internal host wants to connect to servers of the internet through using source NAT. Which policy is required to enable source NAT on the firewall?
- Question #55
Which security profile will provide the best protection against ICMP floods, based on individual combinations of a packet`s source and destination IP address?
- Question #56
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?
- Question #57
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)
- Question #58
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
- Question #59
Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that matches new application signatures?
- Question #60
How do you reset the hit count on a Security policy rule?
- Question #61
Given the topology, which zone type should you configure for firewall interface E1/1?
- Question #62
Which interface type is part of a Layer 3 zone with a Palo Alto Networks firewall?
- Question #65
Which firewall plane provides configuration, logging, and reporting functions on a separate processor?
- Question #66
A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_...
- Question #67
How many zones can an interface be assigned with a Palo Alto Networks firewall?
- Question #68
Which two configuration settings shown are not the default? (Choose two.)
- Question #69
Which data-plane processor layer of the graphic shown provides uniform matching for spyware and vulnerability exploits on a Palo Alto Networks Firewall?
- Question #70
Which option shows the attributes that are selectable when setting up application filters?
- Question #71
Four configuration choices are listed, and each could be used to block access to a specific URL. If you configured each choice to block the same URL then which choice would be the...
- Question #72
Which data flow direction is protected in a zero-trust firewall deployment that is not protected in a perimeter-only firewall deployment?
- Question #73
Which definition describes the guiding principle of the zero-trust architecture?
- Question #74
All users from the internal zone must be allowed only Telnet access to a server in the DMZ zone. Complete the two empty fields in the Security policy rules that permits only this t...
- Question #75
In which profile should you configure the DNS Security feature?
- Question #76
Which two statements are true for the DNS Security service introduced in PAN-OS version 10.0? (Choose two.)
- Question #77
Which two features can be used to tag a username so that it is included in a dynamic user group? (Choose two.)
- Question #78
The CFO found a malware infected USB drive in the parking lot, which when inserted infected their corporate laptop. The malware contacted a known command- and-control server, which...
- Question #79
You must configure which firewall feature to enable a data-plane interface to submit DNS queries on behalf of the control plane?
- Question #80
Which component provides network security for mobile endpoints by inspecting traffic routed through gateways?
- Question #81
For the firewall to use Active Directory to authenticate users, which Server Profile is required in the Authentication Profile?
- Question #82
Which operations are allowed when working with App-ID application tags?
- Question #83
Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilize...
- Question #84
Which type of administrative role must you assign to a firewall administrator account, if the account must include a custom set of firewall permissions?
- Question #85
Which statement is true regarding a Heatmap report?
- Question #86
Based on the screenshot presented, which column contains the link that when clicked, opens a window to display all applications matched to the policy rule?
- Question #87
Access to which feature requires the PAN-OS Filtering license?
- Question #88
Based on the screenshot, what is the purpose of the Included Groups?
- Question #89
Based on the graphic, which statement accurately describes the output shown in the Server Monitoring panel?
- Question #90
Which action results in the firewall blocking network traffic without notifying the sender?
- Question #91
What do Dynamic User Groups help you to do?
- Question #92
Which security policy rule would be needed to match traffic that passes between the Outside zone and Inside zone, but does not match traffic that passes within the zones?
- Question #93
You notice that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would you need to monitor an...
- Question #94
Based on the shown security policy, which Security policy rule would match all FTP traffic from the inside zone to the outside zone?
- Question #95
Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor?
- Question #96
Which Palo Alto network security operating platform component provides consolidated policy creation and centralized management?
- Question #97
Which type of firewall configuration contains in-progress configuration changes?
- Question #98
Which link in the web interface enables a security administrator to view the security policy rules that match new application signatures?
- Question #99
At which stage of the cyber-attack lifecycle would the attacker attach an infected PDF file to an email?
- Question #100
How frequently can wildfire updates be made available to firewalls?
- Question #101
Which data flow direction is protected in a zero trust firewall deployment that is not protected in a perimeter-only firewall deployment?
- Question #102
Which protocol is used to map usernames to user groups when User-ID is configured?
- Question #103
Which Palo Alto networks security operating platform service protects cloud-based application such as Dropbox and salesforce by monitoring permissions and shared and scanning files...
- Question #104
Which three interface deployment methods can be used to block traffic flowing through the Palo Alto Networks firewall? (Choose three.)
- Question #105
Which three statements describe the operation of Security policy rules and Security Profiles? (Choose three.)