NETSEC-ANALYST Exam Questions
435 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 8 of 9.
- Question #352Threat Prevention
With the PAN-OS 11.0 Nova release, which two attack options can new inline deep learning analysis engines detect and prevent? (Choose two.)
inline deep learningPAN-OS 11.0 Novacommand injectionSQL injection - Question #353Threat Prevention
Which profile must be applied to the Security policy rule to block spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers...
anti-spywarecommand-and-controlC2 serverssecurity profiles - Question #354Threat Prevention
Which feature dynamically analyzes and detects malicious content by evaluating various web page details using a series of machine learning (ML) models?
URL Filtering Inline MLmachine learningweb page analysismalicious content detection - Question #355Monitoring and Troubleshooting
An administrator is troubleshooting an issue with Office365 and expects that this traffic traverses the firewall. When reviewing Traffic Log entries, there are no logs matching tra...
traffic logsinterzone-default rulelogging behaviortroubleshooting - Question #356Device Configuration and Management
When creating an address object, which option is available to select from the Type drop-down menu?
address objectsIP Netmaskobject typesnetwork objects - Question #357Network Configuration
Ethernet 2/1 has an IP Address of 10.0.1.2 in Zone 'trust' (LAN). If both interfaces are connected to the same virtual router, which IP address information will an administrator ne...
default routevirtual routerroutinginternet access - Question #358Threat Prevention
Where within the URL Filtering security profile must a user configure the action to prevent credential submissions?
URL filteringcredential submission preventionCategoriesuser credentials - Question #359Threat Prevention
Which Security profile must be added to Security policies to enable DNS Signatures to be checked?
DNS signaturesanti-spywaresecurity profilesDNS security - Question #360Threat Prevention
Which two Security profile actions can only be applied to DoS Protection profiles? (Choose two.)
DoS protectionSYN cookiesRandom Early Dropprofile-specific actions - Question #361Security Policy Management
Where can you apply URL Filtering policy in a Security policy rule?
URL filteringsecurity policyactions tabprofile attachment - Question #362Network Infrastructure and Configuration
Which interface types are assigned to IEEE 802.1Q VLANs?
IEEE 802.1QVLAN taggingLayer 2 interfacesnetwork interfaces - Question #363Threat Intelligence and Malware Analysis
Which three factors can be used to create malware based on domain generation algorithms? (Choose three.)
domain generation algorithmsDGA malwareC2 communicationmalware techniques - Question #364Threat Prevention and Security Profiles
Which action column is available to edit in the Action tab of an Antivirus security profile?
Antivirus security profileaction configurationsecurity profilesfirewall policy - Question #365Log Analysis and Monitoring
Given the detailed log information above, what was the result of the firewall traffic inspection?
Anti-Spyware profiletraffic log analysisfirewall inspectionlog interpretation - Question #366Identity and Access Management
When configuring a security policy, what is a best practice for User-ID?
User-IDWMI trafficsecurity policy best practiceszone segmentation - Question #367DNS Security
What are three DNS policy actions? (Choose three.)
DNS security policysinkhole actionDNS policy actionsthreat prevention - Question #368Log Analysis and Monitoring
Which System log severity level would be displayed as a result of a user password change?
system logslog severity levelsaudit loggingpassword management - Question #369Application Identification and Control
An administrator would like to block traffic to all high risk audio streaming applications, including new App-IDs introduced with content updates. Which filter should the administr...
App-IDapplication filterrisk levelcontent updates - Question #370Threat Prevention and Security Profiles
An administrator receives a notification about new malware that is being used to attack hosts. The malware exploits a software bug in a common application. Which Security Profile w...
Vulnerability Profilethreat signaturessecurity profilesinbound policy rules - Question #371Device Administration and Authentication
The NetSec Manager asked to create a new firewall Local Administrator profile with customized privileges named New_Admin. This new administrator has to authenticate without inserti...
client certificate authenticationadministrator profilesWebUI accesspasswordless auth - Question #372Threat Prevention and Security Profiles
Which Security profile prevents users from submitting valid corporate credentials online?
URL filteringcredential theft preventionphishing protectionsecurity profiles - Question #373Threat Prevention and Security Profiles
Which two statements apply to an Advanced Threat Prevention subscription? (Choose two.)
Advanced Threat PreventionC2 detectionthreat prevention subscriptionevasive threats - Question #374Threat Prevention and Security Profiles
With the PAN-OS 11.0 release, which tab becomes newly available within the Vulnerability security profile?
PAN-OS 11.0Vulnerability profileInline Cloud Analysisnew features - Question #375Security Policy and Object Management
What are the two ways to implement an exception to an external dynamic list? (Choose two.)
external dynamic listEDL exceptionsmanual exceptionsblock list management - Question #376Security Policy Configuration
An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones. The administrator...
interzone policysecurity policy rule typeszone-based firewalltraffic matching logic - Question #377Security Policy Configuration
An administrator is reviewing the Security policy rules shown in the screenshot. Why are the two fields in the Security policy EDL-Deny highlighted in red?
security policy tagsEDLpolicy visual indicatorstag color assignment - Question #378Application Identification and Control
What are two differences between an application group and an application filter? (Choose two.)
application groupsapplication filtersstatic vs dynamic groupingApp-ID - Question #379Application Identification and Control
An administrator reads through the following Applications and Threats Content Release Notes before an update: Which rule would continue to allow the file upload to confluence after...
App-ID content updatesapplication policy continuityconfluence App-IDcontent release notes - Question #380Network Infrastructure and Configuration
Drag and Drop Question Drag the steps into the correct order to create a static route. Answer:
static route configurationnext hoprouting setupvirtual router - Question #381Log Analysis and Monitoring
Which two events can be found in data-filtering logs? (Choose two.)
data filtering logsDLPfile type blockingsensitive data exfiltration - Question #382Security Policy Management
Which statement applies to the Intrazone Security policy rule?
intrazone policysecurity zonesfirewall ruleszone matching - Question #383Security Policy Management
Review the screenshot below. Which statement is correct about the information it contains?
security policy UIrulebase groupspolicy tagsunused rules - Question #384URL Filtering
An administrator wants to enable users to access retail websites that are considered minimum risk. Which two URL categories should be combined in a custom URL category to accomplis...
URL filteringcustom URL categoryURL categoriesweb access control - Question #385User Identification
What are three advantages of user-to-group mapping? (Choose three.)
user-to-group mappinguser identificationpolicy granularityuser administration - Question #386Logging and Monitoring
Which situation is recorded as a system log?
system logslog typesauthentication serverevent logging - Question #387Threat Prevention
Within an Anti-Spyware security profile, which tab is used to enable machine learning based engines?
Anti-Spyware profileinline cloud analysismachine learningsecurity profiles - Question #388Panorama Management
Which two statements correctly describe how pre-rules and local device rules are viewed and modified? (Choose two.)
Panoramapre-rulesdevice rulescentralized management - Question #389Authentication and Authorization
The administrator profile "SYS01 Admin" is configured with authentication profile "Authentication Sequence SYS01," and the authentication sequence SYS01 has a profile list with fou...
authentication sequenceLDAPlocal authenticationRADIUS fallback - Question #390Network Address Translation
Which three types of Source NAT are available to users inside a NGFW? (Choose three.)
source NATDynamic IP and PortStatic IPNAT types - Question #391Application Identification
What are the two main reasons a custom application is created? (Choose two.)
custom applicationApp-IDapplication identificationtraffic log - Question #392Panorama Management
By default, what is the maximum number of templates that can be added to a template stack?
template stackPanoramaconfiguration managementtemplates - Question #393Security Policy Management
What does rule shadowing in Security policies do?
rule shadowingsecurity policypolicy optimizationrule ordering - Question #394Authentication and Authorization
Which two types of profiles are needed to create an authentication sequence? (Choose two.)
authentication sequenceauthentication profileserver profileauthentication types - Question #395Network Routing
Which order of steps is the correct way to create a static route?
static routingnext hoproute configurationnetwork routing - Question #396Threat Prevention
Which two actions are needed for an administrator to get real-time WildFire signatures? (Choose two.)
WildFiredynamic updatesthreat prevention subscriptionreal-time signatures - Question #397Network Address Translation
Which two features implement one-to-one translation of a source IP address while allowing the source port to change? (Choose two.)
source NATDynamic IPDIPP fallbackone-to-one translation - Question #398Application Identification
What are three ways application characteristics are used? (Choose three.)
application characteristicsapplication filterACCapplication group - Question #399Threat Prevention
In which two Security Profiles can an action equal to the block IP feature be configured? (Choose two.)
vulnerability protectionanti-spywareblock IP actionsecurity profiles - Question #400Logging and Monitoring
When is an event displayed under threat logs?
threat logssecurity profileslog typessession logging - Question #401URL Filtering
In which section of the PAN-OS GUI does an administrator configure URL Filtering profiles?
URL filtering profilesPAN-OS GUIObjectssecurity profile configuration