NETSEC-ANALYST Exam Questions
435 real NETSEC-ANALYST exam questions with expert-verified answers and explanations. Page 9 of 9.
- Question #402Threat Prevention
Which profile should be used to obtain a verdict regarding analyzed files?
WildFire analysisfile verdictsthreat preventionsecurity profiles - Question #403Policy Management
In which three places on the PAN-OS interface can the application characteristics be found? (Choose three.)
App-IDapplication objectsPAN-OS GUIObjects tab - Question #404Device Administration
Where within the firewall GUI can an administrator create a local user database?
local user databasedevice administrationuser managementPAN-OS GUI - Question #405Network Configuration
How are service routes used in PAN-OS?
service routesmanagement planedata interfacesrouting - Question #406Logging and Monitoring
How can a complete overview of the logs be displayed to an administrator who has permission in the system to view them?
unified logslog managementmonitoringPAN-OS GUI - Question #407Threat Prevention
Which User Credential Detection method should be applied within a URL Filtering Security profile to check for the submission of a valid corporate username and the associated passwo...
User Credential DetectionURL Filteringcredential phishingsecurity profiles - Question #408Network Configuration
Which step is mandatory to create a static route in PAN-OS?
static routesvirtual routerroutingPAN-OS - Question #409Threat Prevention
Which security profile should be used to classify malicious web content?
URL Filteringmalicious web contentsecurity profilesweb security - Question #410Device Administration
A systems administrator momentarily loses track of which is the test environment firewall and which is the production firewall. The administrator makes changes to the candidate con...
candidate configurationrunning configurationrevertconfiguration management - Question #411Policy Management
An administrator is implementing an exception to an external dynamic list by adding an entry to the list manually. The administrator wants to save the changes, but the OK button is...
external dynamic listEDLconfiguration exceptionsIP blocking - Question #412Network Configuration
Which three Ethernet interface types are configurable on the Palo Alto Networks firewall? (Choose three.)
ethernet interfacestapLayer 3Virtual Wire - Question #413Device Administration
A network security manager is asked to save a configuration to be used after a firewall reboot. When the configuration is ready, how should it be saved so that the changes are not...
named configuration snapshotconfiguration backupconfiguration managementpost-reboot - Question #414Logging and Monitoring
Which action should be taken to identify threats that have been detected by using inline cloud analysis?
inline cloud analysisthreat logsthreat categoryAdvanced Threat Prevention - Question #415Policy Management
What are three valid source or D=destination conditions available as Security policy qualifiers? (Choose three.)
security policysource conditionsdestination conditionspolicy qualifiers - Question #416Policy Management
Which path in PAN-OS 11.x would you follow to see how new and modified App-IDs impact a Security policy?
App-IDdynamic updatespolicy reviewPAN-OS navigation - Question #417Network Configuration
What are three configurable interface types for a data-plane ethernet interface? (Choose three.)
data-plane interfaceVWireLayer 2Layer 3 - Question #418Policy Management
all other sites in the same category. Which object should the administrator create to use as a match condition for the security policy
URL categorysecurity policymatch conditionspolicy objects - Question #419Threat Prevention
Files are sent to the WildFire cloud service via the WildFire Analysis Profile. How are these files used?
WildFiremalware analysisfile submissioncloud security - Question #420Policy Management
Which feature enables an administrator to review the Security policy rule base for unused rules?
Policy Optimizerunused rulessecurity policyrule management - Question #421Network Configuration
What is a default setting for NAT Translated Packets when the destination NAT translation is selected as Dynamic IP (with session distribution)?
NATdestination NATDynamic IPsession distribution - Question #422Network Address Translation
Which table for NAT and NPTv6 (IPv6-to-IPv6 Network Prefix Translation) settings is available only on Panorama?
NATPanoramaNPTv6NAT policy tabs - Question #423Security Policy Management
Which action can be performed when grouping rules by group tags?
policy managementgroup tagsrule taggingsecurity policy - Question #424Threat Prevention
Which two DNS policy actions in the anti-spyware security profile can prevent hacking attacks through DNS queries to malicious domains? (Choose two.)
DNS securityanti-spywareDNS sinkholemalicious domains - Question #425Logging and Monitoring
What is the best-practice approach to logging traffic that traverses the firewall?
traffic loggingsession loggingbest practicesfirewall logging - Question #426Network Address Translation
In which two types of NAT can oversubscription be used? (Choose two.)
NAT oversubscriptionDIPPDynamic IP NATNAT types - Question #427Security Policy Management
Where in the PAN-OS GUI can an administrator monitor the rule usage for a specified period of time?
Policy Optimizerrule usage monitoringPAN-OS GUIpolicy management - Question #428Threat Prevention
In order to attach an Antivirus, Anti-Spyware and Vulnerability Protection security profile to your Security Policy rules, which setting must be selected?
security profilesantivirusvulnerability protectionprofile type - Question #429WildFire and Advanced Threat Prevention
Within a WildFire Analysis Profile, what match criteria can be defined to forward samples for analysis?
WildFirefile forwardingmalware analysismatch criteria - Question #430Authentication and Authorization
What must first be created on the firewall for SAML authentication to be configured?
SAML authenticationserver profileidentity providerauthentication configuration - Question #431Security Policy Management
Which two options does the firewall use to dynamically populate address group members? (Choose two.)
dynamic address groupstagstag-based filtersaddress objects - Question #432Security Policy Management
What two actions can be taken when implementing an exception to an External Dynamic List? (Choose two.)
External Dynamic ListEDL exceptionsIP exclusionURL exclusion - Question #433Security Policy Management
Which feature enables an administrator to review the Security policy rule base for unused rules?
Policy Optimizerunused rulesrule base reviewsecurity policy - Question #434Logging and Monitoring
An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?
traffic logssession type attributelog filteringNGFW monitoring - Question #435Security Policy Management
Which CLI command will help confirm if FQDN objects are resolved in the event there is a shadow rule?
FQDN objectsCLI commandsshadow rulesDNS resolution - Question #436Network Address Translation
In the PAN-OS Web Interface, which is a session distribution method offered under NAT Translated Packet Tab to choose how the firewall assigns sessions?
NATsession distributionIP moduloload balancing