Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Palo Alto Networks Certified Network Security Professional NetSec-Pro Exam Questions

Page: 1 / 8 Total 73 questions

Want more questions? Get Premium Access.

Question 1

How does Strata Logging Service help resolve ever-increasing log retention needs for a company using Prisma Access?

Correct Answer: C. It can scale to meet the capacity needs of new locations as business grows.
Explanation:

The Strata Logging Service offers scalable log storage to accommodate data growth, which ensures organizations can retain logs for compliance and threat hunting as their environments expand.

''The Strata Logging Service is designed to scale dynamically to accommodate growing log retention needs, allowing enterprises to maintain comprehensive visibility as they expand their network footprint.''

(Source: Strata Logging Service Overview)


Question 2

Which functionality does an NGFW use to determine whether new session setups are legitimate or illegitimate?

Correct Answer: B. SYN cookies
Explanation:

To prevent SYN flood attacks, the NGFW uses SYN cookies to validate legitimate session establishment.

''SYN cookies allow the firewall to verify the legitimacy of new session requests without allocating resources until the handshake is completed. This prevents SYN flood attacks from exhausting system resources.''

(Source: Flood Protection Best Practices)

SYN cookies mitigate resource exhaustion by ensuring only legitimate connections are established.


Question 3

Which two content updates can be pushed to next-generation firewalls from Panorama? (Choose two.)

Correct Answer: B. Applications and threats; C. WildFire
Explanation:

Applications and threats

Panorama can push application and threat signature updates to managed firewalls, ensuring consistent application and threat visibility.

''Panorama uses dynamic updates to distribute the latest application and threat signature packs to all managed firewalls.''

(Source: Manage Content Updates in Panorama)

WildFire

Panorama also distributes WildFire signature updates to firewalls for real-time malware detection.

''WildFire updates provide the latest malware signatures to enhance detection and prevention, and can be deployed to all managed firewalls via Panorama.''

(Source: WildFire and Dynamic Updates)


Question 4

Which GlobalProtect configuration is recommended for granular security enforcement of remote user device posture?

Correct Answer: A. Configuring host information profile (HIP) checks for all mobile users
Explanation:

Host Information Profile (HIP) checks are used in GlobalProtect to collect and evaluate endpoint posture (OS, patch level, AV status) to enforce granular security policies for remote users.

''The HIP feature collects information about the host and can be used in security policies to enforce posture-based access control. This ensures only compliant endpoints can access sensitive resources.''

(Source: GlobalProtect HIP Checks)

This enables fine-grained, context-aware access decisions beyond user identity alone.


Question 5

Which action is only taken during slow path in the NGFW policy?

Correct Answer: C. SSL/TLS decryption
Explanation:

In Palo Alto Networks' Single-Pass Parallel Processing (SP3) architecture, SSL/TLS decryption occurs only during the slow path when the firewall first encounters a new session.

''SSL/TLS decryption, which requires CPU-intensive cryptographic operations, is performed during the slow path when establishing new sessions. Once decrypted, traffic is processed in the fast path for subsequent packets.''

(Source: Packet Flow and SP3 Architecture)

After the initial decryption in the slow path, decrypted traffic is handled by fast path for efficiency.


Question 6

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

Correct Answer: D. IPSec termination node
Explanation:

To connect a remote network to Prisma Access via Strata Cloud Manager (SCM), the remote network requires an IPSec termination node. This acts as the VPN endpoint, ensuring secure connectivity between branch locations and Prisma Access.

''To onboard a remote network, configure the IPSec termination node on the customer's premises. This VPN endpoint establishes the secure tunnel to Prisma Access for traffic backhauling.''

(Source: Onboard Remote Networks)

Key takeaway:

The IPSec termination node is fundamental for secure, encrypted connectivity.


Question 7

Which two security services are required for configuration of NGFW Security policies to protect against malicious and misconfigured domains? (Choose two.)

Correct Answer: A. Advanced Threat Prevention; D. Advanced DNS Security
Explanation:

Protecting against malicious and misconfigured domains requires two critical services:

Advanced Threat Prevention

Provides signature-based and advanced analysis to identify threats, including DNS-based attacks.

''Advanced Threat Prevention enables the NGFW to detect and prevent exploits and malware-based communications, including those leveraging DNS.''

(Source: Advanced Threat Prevention)

Advanced DNS Security

Specifically designed to detect and sinkhole malicious and misconfigured DNS queries.

''DNS Security uses real-time intelligence to block DNS-based threats, protect against data exfiltration, and automatically sinkhole suspicious domain lookups.''

(Source: DNS Security)

By combining these services in security policies, NGFWs ensure robust protection against domain-based threats and misconfigurations.


Question 8

In a distributed enterprise implementing Prisma SD-WAN, which configuration element should be implemented first to ensure optimal traffic flow between remote sites and headquarters?

Correct Answer: B. Implement dynamic path selection using real-time performance metrics.
Explanation:

Dynamic path selection is the foundation of SD-WAN, leveraging real-time performance data to dynamically route traffic over the best available path.

''Dynamic path selection continuously monitors performance metrics (loss, latency, jitter) and makes real-time routing decisions to ensure application SLAs are met across the WAN.''

(Source: Prisma SD-WAN Dynamic Path Selection)

Establishing dynamic path selection first ensures the rest of the SD-WAN optimizations (e.g., failover, QoS) work effectively.


Question 9

What occurs when a security profile group named ''default'' is created on an NGFW?

Correct Answer: D. It is automatically applied to all new security rules.
Explanation:

A security profile group named ''default'' is automatically applied to all new security rules unless a specific profile group is explicitly configured.

''If a security profile group named 'default' exists, it will be automatically applied to any newly created security policy rules to ensure consistent protection.''

(Source: Security Profile Groups)

This behavior ensures that newly created policies are always protected by default security profiles, minimizing human error.


Question 10

A company has an ongoing initiative to monitor and control IT-sanctioned SaaS applications. To be successful, it will require configuration of decryption policies, along with data filtering and URL Filtering Profiles used in Security policies. Based on the need to decrypt SaaS applications, which two steps are appropriate to ensure success? (Choose two.)

Correct Answer: A. Configure SSL Forward Proxy.; B. Validate which certificates will be used to establish trust.
Explanation:

To inspect SaaS app traffic (often encrypted), you must configure:

SSL Forward Proxy

''The SSL Forward Proxy decryption profile enables the firewall to decrypt outbound SSL traffic, essential for visibility into SaaS app usage.''

(Source: SSL Forward Proxy Overview)

Validate certificates

''Validating and deploying the appropriate root and intermediate CA certificates is critical for establishing trust and preventing SSL errors during decryption.''

(Source: Certificate Deployment and Validation)

Without these steps, SaaS decryption and policy enforcement would be incomplete.