NETSEC-ANALYST Exam Questions
435 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 4 of 9.
- Question #151Firewall Configuration and Management
Which tab would an administrator click to create an address object?
address objectObjects tabfirewall GUIobject management - Question #152Logging and Reporting
An administrator wishes to follow best practices for logging traffic that traverses the firewall. Which log setting is correct?
session logginglog at session endbest practicestraffic monitoring - Question #153DoS and Zone Protection
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two.)
SYN floodDoS protection profilezone protection profileflood protection - Question #154Security Policy Management
An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs. What is the correct process to enable this logging?
interzone-default rulerule overridedefault security ruleslogging - Question #155Network Routing Configuration
The Palo Alto Networks NGFW was configured with a single virtual router named VR-1. What changes are required on VR-1 to route traffic between two interfaces on the NGFW?
virtual routerinterface assignmentLayer 3 routingconnected routes - Question #156Security Policy Management
Which two rule types allow the administrator to modify the destination zone? (Choose two.)
rule typesuniversal ruleinterzone ruledestination zone modification - Question #157Security Policy Management
What is the main function of Policy Optimizer?
Policy Optimizerapplication-based rulesport-based migrationrule conversion - Question #158User-Based Access Control
Based on the screenshot, what is the purpose of the group in User labelled "it"?
User-IDuser group policysource useraccess control - Question #159Security Policy and Profiles
Assume that traffic matches a Security policy rule but the attached Security Profiles is configured to block matching traffic. Which statement accurately describes how the firewall...
security profilesaction precedenceallow ruleprofile block action - Question #160Security Policy Management
Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications. Whi...
multi-zone policysource zone groupingapplication policytrusted and guest users - Question #161Threat Prevention and Licensing
Which license is required to use the Palo Alto Networks built-in IP address EDLs?
External Dynamic ListsThreat Prevention licenseIP address EDLlicensing - Question #162Panorama Management
Which statement is true about Panorama managed devices?
Panoramaconfiguration locksmanaged devicespolicy management - Question #163Security Policy Configuration
Which component is a building block in a Security policy rule?
Security policypolicy rule componentsapplicationrule building blocks - Question #164Network Configuration and Routing
You have been tasked to configure access to a new web server located in the DMZ. Based on the diagram what configuration changes are required in the NGFW virtual router to route tr...
virtual routerstatic routesDMZ routingnext-hop configuration - Question #165Application Identification (App-ID)
An administrator would like to use App-ID's deny action for an application and would like that action updated with dynamic updates as new content becomes available. Which security...
App-IDdeny actiondynamic content updatesapplication default action - Question #166Device Management and Configuration
Selecting the option to revert firewall changes will replace what settings?
candidate configurationrunning configurationrevert changesconfiguration management - Question #167Security Policy Configuration
An administrator has configured a Security policy where the matching condition includes a single application, and the action is deny. If the application's default deny action is re...
deny actionreset-bothapplication default denySecurity policy actions - Question #168User Identification and Authentication
Which three types of authentication services can be used to authenticate user traffic flowing through the firewall's data plane? (Choose three.)
SAML 2.0KerberosTACACS+data plane authentication - Question #169Network Configuration and Routing
Given the screenshot, what two types of route is the administrator configuring? (Choose two.)
static routedefault routevirtual routerrouting types - Question #170Security Policy Configuration
Which rule type is appropriate for matching traffic both within and between the source and destination zones?
universal rule typeinterzoneintrazoneSecurity policy rules - Question #171Security Policy Configuration
An administrator would like to override the default deny action for a given application, and instead would like to block the traffic and send the ICMP code "communication with the...
Drop actionICMP unreachableadministratively prohibitedSecurity policy actions - Question #172Threat Prevention
You receive notification about new malware that infects hosts through malicious files transferred by FTP. Which Security profile detects and protects your internal networks from th...
Antivirus profileSecurity profilesmalware via FTPinbound threat protection - Question #173URL Filtering
An administrator wants to prevent access to media content websites that are risky. Which two URL categories should be combined in a custom URL category to accomplish this goal? (Ch...
URL Filteringcustom URL categorystreaming-mediahigh-risk category - Question #174Content and Threat Updates
Which dynamic update type includes updated anti-spyware signatures?
dynamic updatesanti-spyware signaturesApplications and Threatscontent updates - Question #175Application Identification (App-ID)
Which object would an administrator create to block access to all high-risk applications?
application filterhigh-risk applicationsapplication objectsSecurity policy - Question #176Decryption and SSL Inspection
Which option is part of the content inspection process?
content inspectionSSL proxy re-encryptSSL decryptionpacket processing - Question #177Threat Prevention
Drag and Drop Question Match each feature to the DoS Protection Policy or the DoS Protection Profile. Answer:
DoS protectionthreat intelligence cloudNGFWendpoint protection - Question #178Network Packet Processing
Drag and Drop Question Place the following steps in the packet processing order of operations from first to last. Answer:
packet processing orderDoS protectionSecurity policy lookupcontent inspection - Question #179Panorama Management
What must be considered with regards to content updates deployed from Panorama?
Panoramacontent updatesdynamic update distributioncontent management - Question #180Application Identification (App-ID)
During the packet flow process, which two processes are performed in application identification? (Choose two.)
App-IDapplication identificationpattern-based identificationapplication override - Question #181Security Policy and NAT
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
DNATSecurity policyzone-based firewallpre-NAT IP matching - Question #182Monitoring and Troubleshooting
What does an administrator use to validate whether a session is matching an expected NAT policy?
NAT policyCLI test commandsession matchingtroubleshooting - Question #183Panorama Management
What is the purpose of the automated commit recovery feature?
Panoramaautomated commit recoveryconnectivity lossconfiguration management - Question #184Threat Prevention
According to the best practices for mission critical devices, what is the recommended interval for antivirus updates?
antivirus updatescontent updatesmission criticalbest practices - Question #185Core Concepts and Packet Processing
Drag and Drop Question Place the steps in the correct packet-processing order of operations. Answer:
packet processing orderzone protectiondecryptionApp-ID - Question #186Security Policy and NAT
Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?
EDLSecurity policysource address matchmalicious IP blocking - Question #187URL Filtering
URL categories can be used as match criteria on which two policy types? (Choose two.)
URL categoriesdecryption policyauthentication policypolicy match criteria - Question #188Monitoring and Troubleshooting
Given the screenshot, what are two correct statements about the logged traffic? (Choose two.)
traffic logsSSL decryptionsecurity profileslog analysis - Question #189Security Policy and NAT
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, wher...
DNATmulti-server NATSecurity policyzone-based firewall - Question #190Threat Prevention
Which type of profile must be applied to the Security policy rule to protect against buffer overflows, illegal code execution, and other attempts to exploit system flaws?
vulnerability protectionsecurity profilesbuffer overflowexploit prevention - Question #191App-ID
Starting with PAN-OS version 9.1, application dependency information is now reported in which two locations? (Choose two.)
App-IDapplication dependenciesPAN-OS 9.1policy optimizer - Question #192URL Filtering
What action will inform end users when their access to Internet content is being restricted?
response pagesURL filteringuser notificationcontent restriction - Question #193Panorama Management
What is a recommended consideration when deploying content updates to the firewall from Panorama?
content updatesPanoramaversion compatibilitydeployment best practices - Question #194Panorama Management
Which information is included in device state other than the local configuration?
device statePanoramatemplate settingsconfiguration backup - Question #195Management and Administration
Based on the graphic, what is the purpose of the SSL/TLS Service profile configuration option?
SSL/TLS service profilecertificate managementmanagement interfaceHTTPS - Question #196Monitoring and Troubleshooting
An administrator is troubleshooting an issue with traffic that matches the intrazone-default rule, which is set to default configuration. What should the administrator do?
intrazone-default ruleSecurity policyloggingtroubleshooting - Question #197Core Concepts and Packet Processing
When is the content inspection performed in the packet flow process?
packet flowcontent inspectionApp-IDsession processing - Question #198App-ID
During the App-ID update process, what should you click on to confirm whether an existing policy rule is affected by an App-ID update?
App-ID updatespolicy reviewcontent updatespolicy impact - Question #199URL Filtering
When creating a custom URL category object, which is a valid type?
custom URL categoryURL filteringcategory matchURL objects - Question #200Management and Administration
When HTTPS for management and GlobalProtect are enabled on the same interface, which TCP port is used for management access?
management interfaceTCP port 4443GlobalProtectHTTPS