NETSEC-ANALYST Exam Questions
421 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 7 of 9.
- Question #314
An administrator is creating a Security policy rule and sees that the destination zone is grayed out. While creating the rule, which option was selected to cause this?
- Question #315
How many levels can there be in a device-group hierarchy, below the shared level?
- Question #316
Where in Panorama would Zone Protection profiles be configured?
- Question #317
Which parameter is used to view the Security policy rulebase as groups?
- Question #318
When a security rule is configured as Intrazone, which field cannot be changed?
- Question #319
An administrator is trying to understand which NAT policy is being matched. In what order does the firewall evaluate NAT policies?
- Question #320
Which policy set should be used to ensure that a policy is applied just before the default security rules?
- Question #321
Which rule type is appropriate for matching traffic occurring within a specified zone? How should the administrator configure the firewall to restrict users to specific email appli...
- Question #322
Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?
- Question #323
An interface can belong to how many Security Zones?
- Question #324
What are the two types of Administrator accounts? (Choose two.)
- Question #325
The Net Sec Manager asked to create a new Firewall Operator profile with customized privileges. In particular, the new firewall operator should be able to: Check the configuration...
- Question #326
Within the WildFire Analysis profile, which three items are configurable? (Choose three.)
- Question #327
Which Security profile can be used to configure sinkhole IPs m the DNS Sinkhole settings?
- Question #328
Which three management interface settings must be configured for functional dynamic updates and administrative access on a Palo Alto Networks firewall? (Choose three.)
- Question #329
How does the Policy Optimizer policy view differ from the Security policy view?
- Question #330
An administrator creates a new Security policy rule to allow DNS traffic from the LAN to the DMZ zones. The administrator does not change the rule type from its default value. What...
- Question #331
What do application filters help provide access to?
- Question #332
What is the function of an application group object?
- Question #333
How would a Security policy need to be written to allow outbound traffic using Secure Shell (SSH) to destination ports tcp/22 and tcp/4422?
- Question #334
Which type of DNS signatures are used by the firewall to identify malicious and command-and- control domains?
- Question #335
Which Security policy action will message a user's browser that their web session has been terminated?
- Question #336
In order to protect users against exploit kits that exploit a vulnerability and then automatically download malicious payloads, which Security profile should be configured?
- Question #337
Which verdict may be assigned to a WildFire sample?
- Question #338
To protect against illegal code execution, which Security profile should be applied?
- Question #339
Which three types of entries can be excluded from an external dynamic list? (Choose three.)
- Question #340
The Administrator profile "PCNSA Admin" is configured with an Authentication profile "Authentication Sequence PCNSA". The Authentication Sequence PCNSA has a profile list with four...
- Question #341
By default, which action is assigned to the intrazone-default rule?
- Question #342
A Panorama administrator would like to create an address object for the DNS server located in the New York City office, but does not want this object added to the other Panorama ma...
- Question #343
An administrator is troubleshooting an issue with traffic that matches the interzone-default rule, which is set to default configuration. What should the administrator do?
- Question #344
What is the default action for the SYN Flood option within the DoS Protection profile?
- Question #345
Application groups enable access to what?
- Question #346
Where does a user assign a tag group to a policy rule in the policy creation window?
- Question #347
What is used to monitor Security policy applications and usage?
- Question #348
What is considered best practice with regards to committing configuration changes?
- Question #349
Which Security profile generates an alert based on a threshold when the action is set to Alert?
- Question #350
Given the network diagram, which two statements are true about traffic between the User and Server networks? (Choose two.)
- Question #351
Which setting is available to edit when a tag is created on the local firewall?
- Question #352
With the PAN-OS 11.0 Nova release, which two attack options can new inline deep learning analysis engines detect and prevent? (Choose two.)
- Question #353
Which profile must be applied to the Security policy rule to block spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers...
- Question #354
Which feature dynamically analyzes and detects malicious content by evaluating various web page details using a series of machine learning (ML) models?
- Question #355
An administrator is troubleshooting an issue with Office365 and expects that this traffic traverses the firewall. When reviewing Traffic Log entries, there are no logs matching tra...
- Question #356
When creating an address object, which option is available to select from the Type drop-down menu?
- Question #357
Ethernet 2/1 has an IP Address of 10.0.1.2 in Zone 'trust' (LAN). If both interfaces are connected to the same virtual router, which IP address information will an administrator ne...
- Question #358
Where within the URL Filtering security profile must a user configure the action to prevent credential submissions?
- Question #359
Which Security profile must be added to Security policies to enable DNS Signatures to be checked?
- Question #360
Which two Security profile actions can only be applied to DoS Protection profiles? (Choose two.)
- Question #361
Where can you apply URL Filtering policy in a Security policy rule?
- Question #362
Which interface types are assigned to IEEE 802.1Q VLANs?
- Question #363
Which three factors can be used to create malware based on domain generation algorithms? (Choose three.)