NETSEC-ANALYST Exam Questions
421 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 6 of 9.
- Question #263
An administrator is creating a NAT policy. Which combination of address and zone are used as match conditions? (Choose two.)
- Question #265
Which firewall feature do you need to configure to query Palo Alto Networks service updates over a data-plane interface instead of the management interface?
- Question #266
In order to fulfill the corporate requirement to backup the configuration of Panorama and the Panorama-managed firewalls securely, which protocol should you select when adding a ne...
- Question #267
All users from the internal zone must be allowed only HTTP access to a server in the DMZ zone. Complete the empty field in the Security policy using an application object to permit...
- Question #268
An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems. From the P...
- Question #269
An administrator would like to follow the best-practice approach to log the traffic that traverses the firewall. What action should they take?
- Question #270
Which two protocols are available on a Palo Alto Networks Firewall Interface Management Profile? (Choose two.)
- Question #271
A network administrator created an intrazone Security policy rule on the firewall. The source zones were set to IT. Finance, and HR. Which two types of traffic will the rule apply...
- Question #272
An administrator would like to override the default deny action for a given application, and instead would like to block the traffic. Which security policy action causes this?
- Question #273
Which syntax would match this?
- Question #274
What are two valid selections within an Anti-Spyware profile? (Choose two.)
- Question #275
Which Security policy set should be used to ensure that a policy is applied first?
- Question #276
An administrator is trying to implement an exception to an external dynamic list manually. Some entries are shown underlined in red. What would cause this error?
- Question #277
What can be achieved by disabling the Share Unused Address and Service Objects with Devices setting on Panorama?
- Question #278
Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?
- Question #279
An administrator is trying to enforce policy on some (but not all) of the entries in an external dynamic list. What is the maximum number of entries that they can be excluded?
- Question #280
A website is unexpectedly allowed due to miscategorization. What are two ways to resolve this issue for a proper response? (Choose two.)
- Question #281
If the firewall interface E1/1 is connected to a SPAN or mirror port, which interface type should E1/1 be configured as?
- Question #282
An administrator manages a network with 300 addresses that require translation. The administrator configured NAT with an address pool of 240 addresses and found that connections fr...
- Question #283
The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should...
- Question #284
An administrator would like to reference the same address object in Security policies on 100 Panorama managed firewalls, across 10 devices groups and five templates. Which configur...
- Question #285
Which type of policy allows an administrator to both enforce rules and take action?
- Question #286
With the DNS Security subscription, when will the cloud-based signature database provide users access to newly added DNS signatures?
- Question #287
Why should a company have a File Blocking profile that is attached to a Security policy?
- Question #288
What can be used as match criteria for creating a dynamic address group?
- Question #289
In which threat profile object would you configure the DNS Security service?
- Question #290
An administrator would like to protect against inbound threats such as buffer overflows and illegal code execution. Which Security profile should be used?
- Question #291
An organization has some applications that are restricted for access by the Human Resources Department only, and other applications that are available for any known user in the org...
- Question #292
Which two configurations does an administrator need to compare in order to see differences between the active configuration and potential changes if committed? (Choose two.)
- Question #293
An administrator configured a Security policy rule where the matching condition includes a single application and the action is set to deny. What deny action will the firewall perf...
- Question #294
If users from the Trusted zone need to allow traffic to an SFTP server in the DMZ zone, how should a Security policy with App-ID be configured?
- Question #295
An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how wi...
- Question #296
An administrator needs to allow users to use only certain email applications. How should the administrator configure the firewall to restrict users to specific email applications?
- Question #297
DNS exceptions can be set under which Security profile?
- Question #298
An administrator is troubleshooting an issue with an accounts payable application. Which log setting could be temporarily configured to improve visibility?
- Question #299
By default, which action is assigned to the interzone-default rule?
- Question #300
What is the maximum volume of concurrent administrative account sessions?
- Question #301
An administrator is updating Security policy to align with best practices. Which Policy Optimizer feature is shown in the screenshot below?
- Question #302
Where within the firewall GUI can all existing tags be viewed?
- Question #303
What is the Anti-Spyware Security profile default action?
- Question #304
To enable DNS sinkholing, which two addresses should be reserved? (Choose two.)
- Question #305
A NetSec manager was asked to create a new firewall administrator profile with customized privileges. The new firewall administrator must be able to download TSF File and Starts Du...
- Question #306
What must exist in order for the firewall to route traffic between Layer 3 interfaces?
- Question #307
Which path in PAN-OS 10.2 is used to schedule a content update to managed devices using Panorama?
- Question #308
In which threat profile object would you configure the DNS Security service?
- Question #309
Which rule type is appropriate for matching traffic occurring within a specified zone?
- Question #310
Which two matching criteria are used when creating a Security policy involving NAT? (Choose two.)
- Question #311
If a universal security rule was created for source zones A & B and destination zones A & B, to which traffic would the rule apply?
- Question #312
Which interface type requires no routing or switching but applies Security or NAT policy rules before passing allowed traffic?
- Question #313
What is a valid Security Zone type in PAN-OS?