NETSEC-ANALYST Exam Questions
435 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 5 of 9.
- Question #201Authentication and Authorization
What two authentication methods on the Palo Alto Networks firewalls support authentication and authorization for role-based access control? (Choose two.)
SAMLTACACS+RBACauthentication methods - Question #202Threat Prevention
Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?
DNS securitysinkholeContent DNS SignaturesSecurity policy - Question #203Cybersecurity Fundamentals and Attack Lifecycle
Which stage of the cyber-attack lifecycle makes it important to provide ongoing education to users on spear phishing links, unknown emails, and risky websites?
cyber-attack lifecycledelivery stagespear phishingsecurity awareness - Question #204Threat Prevention
What are three factors that can be used in domain generation algorithms? (Choose three.)
domain generation algorithmsDGAC2 detectioncryptographic entropy - Question #205Policy and Object Management
Which action would an administrator take to ensure that a service object will be available only to the selected device group?
service objectsdevice groupsPanoramashared objects - Question #206User-ID
If using group mapping with Active Directory Universal Groups, what must you do when configuring the User-ID?
User-IDgroup mappingActive Directory Universal GroupsLDAP Global Catalog - Question #207Device Management
Which administrative management services can be configured to access a management interface?
management interfaceSSHHTTPStelnet - Question #208Threat Prevention
Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content, whose services are frequently used by attackers to distribute il...
Bulletproof IP AddressesEDLIP reputationthreat intelligence feeds - Question #209Policy and Object Management
Which attribute can a dynamic address group use as a filtering condition to determine its membership?
dynamic address groupstagsaddress objectspolicy objects - Question #210Security Policy Configuration
View the diagram. What is the most restrictive yet fully functional rule to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT...
Security policy ruleszone-based firewallDMZapplication-based policy - Question #211Content-ID
An administrator needs to add capability to perform real-time signature lookups to block or sinkhole all known malware domains. Which type of single unified engine will get this re...
Content-IDDNS securitymalware domain blockingunified engine - Question #212User-ID
Which solution is a viable option to capture user identification when Active Directory is not in use?
User-IDAuthentication Portalnon-AD identityuser mapping - Question #213Threat Prevention
You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact a command-and-control server. Which Security Profil...
Anti-Spyware ProfileC2 detectionmalware preventionSecurity profiles - Question #214Threat Prevention
Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis Unit 42 research and data gathered fro...
EDLWildFireKnown Malicious IP AddressesUnit 42 threat intel - Question #215App-ID
The compliance officer requests that all evasive applications need to be blocked on all perimeter firewalls out to the internet. The firewall is configured with two zones: 1. trust...
App-IDevasive applicationsSecurity policyapplication-default service - Question #216Threat Prevention
What must be configured before setting up Credential Phishing Prevention?
Credential Phishing PreventionUser-ID prerequisitephishing protectionURL filtering - Question #217Policy and Object Management
What allows a security administrator to preview the Security policy rules that match new application signatures?
Dynamic Updatesapplication signaturespolicy reviewApp-ID updates - Question #218Policy Management
Which statement best describes a common use of Policy Optimizer?
Policy Optimizerunused Security policiesApp-ID migrationpolicy hygiene - Question #219Policy and Object Management
An address object of type IP Wildcard Mask can be referenced in which part of the configuration?
IP Wildcard Maskaddress objectsSecurity policy referenceobject types - Question #220App-ID
An administrator would like to determine the default deny action for the application dns-over- https. Which action would yield the information?
App-IDapplication detailsdefault deny actiondns-over-https - Question #221Security Policy Management
An administrator needs to create a Security policy rule that matches DNS traffic within the LAN zone, and also needs to match DNS traffic within the DMZ zone. The administrator doe...
intrazone policySecurity policy rule typeszone-based trafficDMZ/LAN zones - Question #222User-ID and Authentication
What are three valid ways to map an IP address to a username? (Choose three.)
User-IDIP-to-username mappingGlobalProtect agentXML API - Question #223Application Identification and Control
Which object would an administrator create to enable access to all applications in the office- programs subcategory?
application filterApp-IDapplication subcategorysecurity objects - Question #224URL Filtering and Threat Prevention
An administrator would like to create a URL Filtering log entry when users browse to any gambling website. What combination of Security policy and Security profile actions is corre...
URL Filtering profileSecurity policy actionalert actionlogging configuration - Question #225Network Address Translation (NAT)
Which statement is true regarding NAT rules?
NAT rulesrule processing orderNAT policynetwork address translation - Question #226Firewall Configuration Management
After making multiple changes to the candidate configuration of a firewall, the administrator would like to start over with a candidate configuration that matches the running confi...
candidate configurationrunning configurationrevert configurationoperations - Question #227Security Policy Management
An administrator is reviewing the Security policy rules shown in the screenshot below. Which statement is correct about the information displayed?
rulebase groupsSecurity policy UIpolicy tagsrule display - Question #228Security Policy Management
What are the two default behaviors for the intrazone-default policy? (Choose two.)
intrazone-default policydefault logging behaviorallow actionzone-based default rules - Question #229Threat Prevention
What are two valid selections within an Antivirus profile? (Choose two.)
Antivirus profilethreat prevention actionsdrop actionsecurity profile options - Question #230Network Address Translation (NAT)
An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address. What is the most appropriate NAT policy to achie...
Dynamic IP and Port NATPATmany-to-one source NATNAT policy types - Question #231URL Filtering and Threat Prevention
Which action can be set in a URL Filtering Security profile to provide users temporary access to all websites in a given category using a provided password?
URL Filtering overridecategory access controlpassword-based accesssecurity profiles - Question #232Application Identification and Control
What is a function of application tags?
application tagsApp-IDpolicy automationreferenced applications - Question #233Threat Prevention
What are three Palo Alto Networks best practices when implementing the DNS Security Service? (Choose three.)
DNS Security Servicebest practicesthreat preventionURL Filtering integration - Question #234Monitoring and Troubleshooting
An administrator is investigating a log entry for a session that is allowed and has the end reason of aged-out. Which two fields could help in determining if this is normal? (Choos...
traffic logsaged-out sessionlog analysistroubleshooting sessions - Question #235Application Identification and Control
What does an application filter help you to do?
application filterdynamic groupingapplication attributesApp-ID - Question #236Firewall Configuration Management
Prior to a maintenance-window activity, the administrator would like to make a backup of only the running configuration to an external location. What command in Device > Setup > Op...
configuration backupexport running confignamed configuration snapshotoperations - Question #237Threat Prevention
Your company is highly concerned with their Intellectual property being accessed by unauthorized resources. There is a mature process to store and include metadata tags for all con...
Data FilteringDLPintellectual property protectionmetadata tags - Question #238Network Address Translation (NAT)
An administrator wants to create a No-NAT rule to exempt a flow from the default NAT rule. What is the best way to do this?
No-NAT ruleNAT exemptiontranslation type NoneNAT policy - Question #239Panorama Management
When creating a Panorama administrator type of Device Group and Template Admin, which two things must you create first? (Choose two.)
Panorama administrationDevice Group adminaccess domainadmin role - Question #240Monitoring and Troubleshooting
An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. T...
interzone-default policydefault logging disabledtraffic log troubleshootingdefault policy behavior - Question #241Configure and Manage NAT Policies
An administrator is configuring a NAT rule. At a minimum, which three forms of information are required? (Choose three.)
NAT ruleszone configurationrule requirementsfirewall policy - Question #243Threat Prevention and DNS Security
What are three characteristics of the Palo Alto Networks DNS Security service? (Choose three.)
DNS SecurityDGA detectionDNS tunnelingThreat Prevention license - Question #244Security Policy Objects and External Dynamic Lists
What are the requirements for using Palo Alto Networks EDL Hosting Sen/ice?
EDL Hosting Serviceexternal dynamic listssubscription requirementsPAN-OS compatibility - Question #245Configure and Manage Security Policies
An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets. What are two security policy actions the administrato...
security policy actionsTCP resethalf-open socketstraffic blocking - Question #246Application Identification and Control
An administrator would like to apply a more restrictive Security profile to traffic for file sharing applications. The administrator does not want to update the Security policy or...
application filterApp-IDfile-sharing subcategorydynamic policy matching - Question #247Configure Virtual Routers and Routing Protocols
A network administrator is required to use a dynamic routing protocol for network connectivity. Which three dynamic routing protocols are supported by the NGFW Virtual Router for t...
dynamic routingvirtual routerBGPOSPFRIP - Question #248Logging and Monitoring
Which log type would be used to find commit entries for a firewall?
config logscommit historylog typesfirewall administration - Question #249Configure and Manage Security Policies
Drag and Drop Question Match each rule type with its example. Answer:
intrazone rulesinterzone rulesuniversal ruleszone-based policy - Question #250Authentication and Authorization
To use Active Directory to authenticate administrators, which server profile is required in the authentication profile?
Active DirectoryLDAP server profileauthentication profileadmin authentication - Question #251Application Identification and Control
Which three filter columns are available when setting up an Application Filter? (Choose three.)
application filtercategorysubcategoryrisk rating