Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks NetSec-Pro Palo Alto Networks Network Security Professional Exam Practice Test

Demo: 18 questions
Total 60 questions

Palo Alto Networks Network Security Professional Questions and Answers

Question 1

Which offering can be managed in both Panorama and Strata Cloud Manager (SCM)?

Options:

A.

Autonomous Digital Experience Manager (ADEM)

B.

VM-Series Next-Generation Firewall (NGFW)

C.

Prisma SD-WAN

D.

SaaS Security

Question 2

Which action allows an engineer to collectively update VM-Series firewalls with Strata Cloud Manager (SCM)?

Options:

A.

Creating an update grouping rule

B.

Scheduling software update

C.

Creating a device grouping rule

D.

Setting a target OS version

Question 3

Which firewall attribute can an engineer use to simplify rule creation and automatically adapt to changes in server roles or security posture based on log events?

Options:

A.

Address objects

B.

Dynamic Address Groups

C.

Dynamic User Groups

D.

Predefined IP addresses

Question 4

In which two applications can Prisma Access threat logs for mobile user traffic be reviewed? (Choose two.)

Options:

A.

Prisma Cloud dashboard

B.

Strata Cloud Manager (SCM)

C.

Strata Logging Service

D.

Service connection firewall

Question 5

Which procedure is most effective for maintaining continuity and security during a Prisma Access data plane software upgrade?

Options:

A.

Back up configurations, schedule upgrades during off-peak hours, and use a phased approach rather than attempting a network-wide rollout.

B.

Use Strata Cloud Manager (SCM) to perform dynamic upgrades automatically and simultaneously across all locations at once to ensure network-wide uniformity.

C.

Disable all security features during the upgrade to prevent conflicts and re-enable them after completion to ensure a smooth rollout process.

D.

Perform the upgrade during peak business hours, quickly address any user-reported issues, and ensure immediate troubleshooting post-rollout.

Question 6

What occurs when a security profile group named “default” is created on an NGFW?

Options:

A.

It only applies to traffic that has been dropped due to the reset client action.

B.

It allows traffic to bypass all security checks by default.

C.

It negates all existing security profiles rules on new policy.

D.

It is automatically applied to all new security rules.

Question 7

A company has an ongoing initiative to monitor and control IT-sanctioned SaaS applications. To be successful, it will require configuration of decryption policies, along with data filtering and URL Filtering Profiles used in Security policies. Based on the need to decrypt SaaS applications, which two steps are appropriate to ensure success? (Choose two.)

Options:

A.

Configure SSL Forward Proxy.

B.

Validate which certificates will be used to establish trust.

C.

Configure SSL Inbound Inspection.

D.

Create new self-signed certificates to use for decryption.

Question 8

A primary firewall in a high availability (HA) pair is experiencing a current failover issue with ICMP pings to a secondary device. Which metric should be reviewed for proper ICMP pings between the firewall pair?

Options:

A.

Link monitoring

B.

Non-functional state

C.

Heartbeat polling

D.

Bidirectional Forwarding Detection (BFD)

Question 9

An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a data center NGFW that already has one enabled. What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?

Options:

A.

It allows for traffic inspection at the application level.

B.

There will be no additional performance degradation.

C.

There will be only a minor reduction in performance.

D.

It allows additional security inspection devices to be added inline.

Question 10

A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs. Which two report types achieve this goal? (Choose two.)

Options:

A.

SNMP

B.

Custom

C.

PDF summary

D.

CSV export

Question 11

Which zone is available for use in Prisma Access?

Options:

A.

Clientless VPN

B.

Interzone

C.

Intrazone

D.

DMZ

Question 12

What is a necessary step for creation of a custom Prisma Access report on Strata Cloud Manager (SCM)?

Options:

A.

Open a support ticket.

B.

Set up Cloud Identity Engine.

C.

Generate a PDF summary report.

D.

Configure a dashboard.

Question 13

In a Prisma SD-WAN environment experiencing voice quality degradation, which initial action is recommended?

Options:

A.

Immediately modify path quality thresholds.

B.

Review real-time analytics of path performance.

C.

Switch all VoIP traffic to backup paths.

D.

Request an RMA of the ION devices.

Question 14

In a distributed enterprise implementing Prisma SD-WAN, which configuration element should be implemented first to ensure optimal traffic flow between remote sites and headquarters?

Options:

A.

Deploy redundant ION devices at each location.

B.

Implement dynamic path selection using real-time performance metrics.

C.

Configure static routes between all the branch offices.

D.

Enable split tunneling for all branch locations.

Question 15

After a firewall is associated with Strata Cloud Manager (SCM), which two additional actions are required to enable management of the firewall from SCM? (Choose two.)

Options:

A.

Deploy a service connection for each branch site and connect with SCM.

B.

Configure NTP and DNS servers for the firewall.

C.

Configure a Security policy allowing “stratacloudmanager.paloaltonetworks.com” for all users.

D.

Install a device certificate.

Question 16

When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?

Options:

A.

Configure port-based policies, check threat logs weekly, conduct software updates annually, and enable decryption.

B.

Configure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles to rules, and update regularly with dynamic updates.

C.

Configure all default policies provided by the firewall, use Policy Optimizer, and adjust security rules after an incident occurs.

D.

Configure a block policy for all malicious inbound traffic, configure an allow policy for all outbound traffic, and update regularly with dynamic updates.

Question 17

Which two features can a network administrator use to troubleshoot the issue of a Prisma Access mobile user who is unable to access SaaS applications? (Choose two.)

Options:

A.

SaaS Application Risk Portal

B.

Capacity Analyzer

C.

GlobalProtect logs

D.

Autonomous Digital Experience Manager (ADEM) console

Question 18

Which GlobalProtect configuration is recommended for granular security enforcement of remote user device posture?

Options:

A.

Configuring host information profile (HIP) checks for all mobile users

B.

Configuring a rule that blocks the ability of users to disable GlobalProtect while accessing internal applications

C.

Implementing multi-factor authentication (MFA) for all users attempting to access internal applications

D.

Applying log at session end to all GlobalProtect Security policies

Demo: 18 questions
Total 60 questions