Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks NetSec-Pro Palo Alto Networks Network Security Professional Exam Practice Test

Demo: 21 questions
Total 73 questions

Palo Alto Networks Network Security Professional Questions and Answers

Question 1

What is a necessary step for creation of a custom Prisma Access report on Strata Cloud Manager (SCM)?

Options:

A.

Open a support ticket.

B.

Set up Cloud Identity Engine.

C.

Generate a PDF summary report.

D.

Configure a dashboard.

Question 2

How often does the firewall retrieve signature database updates from Advanced WildFire?

Options:

A.

Real-time

B.

Within 5 to 10 minutes

C.

10 to 20 minutes

D.

Every 24 hours

Question 3

Which two components of a Security policy, when configured, allow third-party contractors access to internal applications outside business hours? (Choose two.)

Options:

A.

App-ID

B.

Service

C.

User-ID

D.

Schedule

Question 4

Which two features can a network administrator use to troubleshoot the issue of a Prisma Access mobile user who is unable to access SaaS applications? (Choose two.)

Options:

A.

SaaS Application Risk Portal

B.

Capacity Analyzer

C.

GlobalProtect logs

D.

Autonomous Digital Experience Manager (ADEM) console

Question 5

Which two tools can be used to configure Cloud NGFWs for AWS? (Choose two.)

Options:

A.

Cortex XSIAM

B.

Prisma Cloud management console

C.

Panorama

D.

Cloud service provider's management console

Question 6

In a service provider environment, what key advantage does implementing virtual systems provide for managing multiple customer environments?

Options:

A.

Shared threat prevention policies across all tenants

B.

Centralized authentication for all customer domains

C.

Unified logging across all virtual systems

D.

Logical separation of control and Security policy

Question 7

Which two configurations are required when creating deployment profiles to migrate a perpetual VM-Series firewall to a flexible VM? (Choose two.)

Options:

A.

Choose “Fixed vCPU Models” for configuration type.

B.

Allocate the same number of vCPUs as the perpetual VM.

C.

Allow only the same security services as the perpetual VM.

D.

Deploy virtual Panorama for management.

Question 8

Which two content updates can be pushed to next-generation firewalls from Panorama? (Choose two.)

Options:

A.

Advanced URL Filtering

B.

Applications and threats

C.

WildFire

D.

GlobalProtect data file

Question 9

A network security engineer needs to implement segmentation but is under strict compliance requirements to place security enforcement as close as possible to the private applications hosted in Azure. Which deployment style is valid and meets the requirements in this scenario?

Options:

A.

On a VM-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.

B.

On a PA-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.

C.

On a VM-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.

D.

On a PA-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.

Question 10

How does Strata Logging Service help resolve ever-increasing log retention needs for a company using Prisma Access?

Options:

A.

It increases resilience due to decentralized collection and storage of logs.

B.

Automatic selection of physical data storage regions decreases adoption time.

C.

It can scale to meet the capacity needs of new locations as business grows.

D.

Log traffic using the licensed bandwidth purchased for Prisma Access reduces overhead.

Question 11

An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a data center NGFW that already has one enabled. What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?

Options:

A.

It allows for traffic inspection at the application level.

B.

There will be no additional performance degradation.

C.

There will be only a minor reduction in performance.

D.

It allows additional security inspection devices to be added inline.

Question 12

Which action optimizes user experience across a segmented network architecture and implements the most effective method to maintain secure connectivity between branch and campus locations?

Options:

A.

Establish site-to-site tunnels on each branch and campus firewall and have individual VLANs for each department.

B.

Configure all branch and campus firewalls to use a single shared broadcast domain.

C.

Implement SD-WAN to route all traffic based on network performance metrics and use zone protection profiles.

D.

Configure a single campus firewall to handle the routing of all branch traffic.

Question 13

Which GlobalProtect configuration is recommended for granular security enforcement of remote user device posture?

Options:

A.

Configuring host information profile (HIP) checks for all mobile users

B.

Configuring a rule that blocks the ability of users to disable GlobalProtect while accessing internal applications

C.

Implementing multi-factor authentication (MFA) for all users attempting to access internal applications

D.

Applying log at session end to all GlobalProtect Security policies

Question 14

A cloud security architect is designing a certificate management strategy for Strata Cloud Manager (SCM) across hybrid environments. Which practice ensures optimal security with low management overhead?

Options:

A.

Deploy centralized certificate automation with standardized protocols and continuous monitoring.

B.

Implement separate certificate authorities with independent validation rules for each cloud environment.

C.

Configure manual certificate deployment with quarterly reviews and environment-specific security protocols.

D.

Use cloud provider default certificates with scheduled synchronization and localized renewal processes.

Question 15

Which component of NGFW is supported in active/passive design but not in active/active design?

Options:

A.

Single floating IP address

B.

Using a DHCP client

C.

Route-based redundancy

D.

Configuring ARP load-sharing on Layer 3

Question 16

How many places will a firewall administrator need to create and configure a custom data loss prevention (DLP) profile across Prisma Access and the NGFW?

Options:

A.

One

B.

Two

C.

Three

D.

Four

Question 17

An administrator wants to optimize the attack surface and check if configurations comply with CIS standards. Where in SCM can this function be accessed?

Options:

A.

BPA

B.

Command Center

C.

Policy Optimizer

D.

Executive Summary

Question 18

Which action allows an engineer to collectively update VM-Series firewalls with Strata Cloud Manager (SCM)?

Options:

A.

Creating an update grouping rule

B.

Scheduling software update

C.

Creating a device grouping rule

D.

Setting a target OS version

Question 19

In a Prisma SD-WAN environment experiencing voice quality degradation, which initial action is recommended?

Options:

A.

Immediately modify path quality thresholds.

B.

Review real-time analytics of path performance.

C.

Switch all VoIP traffic to backup paths.

D.

Request an RMA of the ION devices.

Question 20

Which method in the WildFire analysis report detonates unknown submissions to provide visibility into real-world effects and behavior?

Options:

A.

Dynamic analysis

B.

Static analysis

C.

Intelligent Run-time Memory Analysis

D.

Machine learning (ML)

Question 21

What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?

Options:

A.

9.1 → 11.0 → 11.2

B.

9.1 → 10.0 → 11.

C.

9.1 → 11.

D.

9.1 → 10.0 → 11.2

Demo: 21 questions
Total 73 questions