NETSEC-ANALYST Exam Questions
435 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 6 of 9.
- Question #252Threat Prevention Profiles
A coworker found a USB labeled "confidential in the parking lot. They inserted the drive and it infected their corporate laptop with unknown malware The malware caused the laptop t...
antivirus profilemalware detectionsecurity profilesunknown malware - Question #253WildFire Analysis and Configuration
According to best practices, how frequently should WildFire updates he made to perimeter firewalls?
WildFiresignature updatesbest practicesreal-time updates - Question #254Threat Prevention and DNS Security
What are the three DNS Security categories available to control DNS traffic? (Choose three.)
DNS Securitymalware domainsphishing domainsparked domains - Question #255User Identification and Group-Based Policy
What are three valid information sources that can be used when tagging users to dynamic user groups? (Choose three.)
dynamic user groupsuser taggingUser-IDSIEM integration - Question #256Configure Network Interfaces and Zones
When an ethernet interface is configured with an IPv4 address, which type of zone is it a member of?
Layer 3 interfacezone typesIPv4 addressingnetwork configuration - Question #257Security Policy Objects and External Dynamic Lists
How is an address object of type IP range correctly defined?
address objectsIP range formatpolicy objectsfirewall configuration - Question #258Security Policy Objects and External Dynamic Lists
What do you configure if you want to set up a group of objects based on their ports alone?
service groupsport-based policypolicy objectsfirewall configuration - Question #259Threat Prevention Profiles
What are two valid selections within a Vulnerability Protection profile? (Choose two.)
vulnerability protectionsecurity profile actionsdrop actiondefault action - Question #260Device Administration and Role-Based Access Control
When creating an Admin Role profile, if no changes are made, which two administrative methods will you have full access to? (Choose two.)
admin role profileweb UI accessREST APIadministrative methods - Question #261Device Administration and Role-Based Access Control
Which list of actions properly defines the order of steps needed to add a local database user account and create a new group to which this user will be assigned?
local user databaseuser account creationgroup assignmentdevice administration - Question #262Threat Prevention
An administrator wants to prevent hacking attacks through DNS queries to malicious domains. Which two DNS policy actions can the administrator choose in the Anti-Spyware Security P...
Anti-Spyware profileDNS securityDNS sinkholesecurity policy actions - Question #263Network Configuration
An administrator is creating a NAT policy. Which combination of address and zone are used as match conditions? (Choose two.)
NAT policypre-NAT addresssource zonematch conditions - Question #264Security Policy Configuration
Given the network diagram, traffic must be permitted for SSH and MYSQL from the DMZ to the SERVER zones, crossing two firewalls. In addition, traffic should be permitted from the S...
Security policy ruleszone-based policyDMZmulti-firewall topology - Question #265Device Management
Which firewall feature do you need to configure to query Palo Alto Networks service updates over a data-plane interface instead of the management interface?
service routedata-plane interfacemanagement interfacedevice services - Question #266Device Management
In order to fulfill the corporate requirement to backup the configuration of Panorama and the Panorama-managed firewalls securely, which protocol should you select when adding a ne...
SCPconfiguration backupPanoramasecure export protocol - Question #267Security Policy Configuration
All users from the internal zone must be allowed only HTTP access to a server in the DMZ zone. Complete the empty field in the Security policy using an application object to permit...
App-IDweb-browsing applicationsecurity policyapplication-default - Question #268Threat Prevention
An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems. From the P...
URL filteringCommand and Controldata exfiltrationpredefined categories - Question #269Monitoring and Logging
An administrator would like to follow the best-practice approach to log the traffic that traverses the firewall. What action should they take?
session loggingLog at Session Endtraffic loggingbest practices - Question #270Device Management
Which two protocols are available on a Palo Alto Networks Firewall Interface Management Profile? (Choose two.)
Interface Management ProfileHTTPSSSHmanagement protocols - Question #271Security Policy Configuration
A network administrator created an intrazone Security policy rule on the firewall. The source zones were set to IT. Finance, and HR. Which two types of traffic will the rule apply...
intrazone policysecurity zoneszone-based trafficfirewall rules - Question #272Security Policy Configuration
An administrator would like to override the default deny action for a given application, and instead would like to block the traffic. Which security policy action causes this?
security policy actionsdrop actiondeny overrideblock vs deny - Question #273Security Policy Configuration
Which syntax would match this?
URL filteringwildcard syntaxURL pattern matchingcustom categories - Question #274Threat Prevention
What are two valid selections within an Anti-Spyware profile? (Choose two.)
Anti-Spyware profilethreat actionsdrop actiondefault action - Question #275Panorama Management
Which Security policy set should be used to ensure that a policy is applied first?
Panoramapolicy hierarchypre-rulebaseshared device group - Question #276Policy Objects
An administrator is trying to implement an exception to an external dynamic list manually. Some entries are shown underlined in red. What would cause this error?
external dynamic listEDL exceptionsduplicate entriesconfiguration errors - Question #277Panorama Management
What can be achieved by disabling the Share Unused Address and Service Objects with Devices setting on Panorama?
Panoramaobject sharingaddress objectsfirewall capacity optimization - Question #278Threat Prevention
Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?
Anti-Spyware profileC2 communicationcompromised hoststhreat prevention - Question #279Policy Objects
An administrator is trying to enforce policy on some (but not all) of the entries in an external dynamic list. What is the maximum number of entries that they can be excluded?
external dynamic listEDL exceptionsexclusion limitpolicy enforcement - Question #280Threat Prevention
A website is unexpectedly allowed due to miscategorization. What are two ways to resolve this issue for a proper response? (Choose two.)
URL filteringURL miscategorizationcustom URL categoryURL category override - Question #281Network Configuration
If the firewall interface E1/1 is connected to a SPAN or mirror port, which interface type should E1/1 be configured as?
Tap interfaceSPAN portinterface typespassive monitoring - Question #282Network Address Translation
An administrator manages a network with 300 addresses that require translation. The administrator configured NAT with an address pool of 240 addresses and found that connections fr...
Dynamic NATNAT address poolIP translationNAT oversubscription - Question #283Panorama Administration and Management
The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should...
Panorama administrationDevice Group and Template Adminrole-based access controladmin profiles - Question #284Panorama Administration and Management
An administrator would like to reference the same address object in Security policies on 100 Panorama managed firewalls, across 10 devices groups and five templates. Which configur...
Panorama shared objectsaddress objectsdevice groupsmulti-device management - Question #285Security Policy Management
Which type of policy allows an administrator to both enforce rules and take action?
Security policypolicy typesfirewall rulespolicy actions - Question #286Threat Prevention and Security Subscriptions
With the DNS Security subscription, when will the cloud-based signature database provide users access to newly added DNS signatures?
DNS Securitycloud-based signaturesreal-time protectionsignature updates - Question #287Threat Prevention and Security Profiles
Why should a company have a File Blocking profile that is attached to a Security policy?
File Blocking profilesecurity profilesfile type controlupload/download restriction - Question #288Security Policy and Objects
What can be used as match criteria for creating a dynamic address group?
dynamic address groupstagsaddress objectspolicy match criteria - Question #289Threat Prevention and Security Profiles
In which threat profile object would you configure the DNS Security service?
DNS SecurityAnti-Spyware profilethreat profilessecurity subscriptions - Question #290Threat Prevention and Security Profiles
An administrator would like to protect against inbound threats such as buffer overflows and illegal code execution. Which Security profile should be used?
Vulnerability Protectionbuffer overflowexploit preventionsecurity profiles - Question #291Security Policy and Objects
An organization has some applications that are restricted for access by the Human Resources Department only, and other applications that are available for any known user in the org...
Application Groupapplication objectsaccess controluser-based policies - Question #292Firewall Administration and Configuration
Which two configurations does an administrator need to compare in order to see differences between the active configuration and potential changes if committed? (Choose two.)
candidate configurationrunning configurationconfiguration managementcommit process - Question #293Security Policy Management
An administrator configured a Security policy rule where the matching condition includes a single application and the action is set to deny. What deny action will the firewall perf...
App-IDdeny actionapplication-defaultSecurity policy - Question #294Security Policy Management
If users from the Trusted zone need to allow traffic to an SFTP server in the DMZ zone, how should a Security policy with App-ID be configured?
App-IDzone-based policySFTPSecurity policy configuration - Question #295Threat Prevention and Security Profiles
An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how wi...
Antivirus profiledefault actionvirus signaturethreat prevention - Question #296Security Policy and Objects
An administrator needs to allow users to use only certain email applications. How should the administrator configure the firewall to restrict users to specific email applications?
Application Groupapplication filteremail applicationsapplication control - Question #297Threat Prevention and Security Profiles
DNS exceptions can be set under which Security profile?
DNS exceptionsAnti-Spyware profileDNS securitysecurity profiles - Question #298Monitoring and Logging
An administrator is troubleshooting an issue with an accounts payable application. Which log setting could be temporarily configured to improve visibility?
session logginglog settingstroubleshootingSecurity policy logging - Question #299Security Policy Management
By default, which action is assigned to the interzone-default rule?
interzone-default ruleimplicit denyzone-based policiesdefault Security policy - Question #300Firewall Administration and Configuration
What is the maximum volume of concurrent administrative account sessions?
administrative sessionsconcurrent accessfirewall managementadmin accounts - Question #301Security Policy Management
An administrator is updating Security policy to align with best practices. Which Policy Optimizer feature is shown in the screenshot below?
Policy OptimizerApp-ID migrationSecurity policy best practicesrule analysis