Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Paloalto Networks NetSec-Pro Dumps Questions Answers

Page: 1 / 5
Total 73 questions

Palo Alto Networks Network Security Professional Questions and Answers

Question 1

Which two security services are required for configuration of NGFW Security policies to protect against malicious and misconfigured domains? (Choose two.)

Options:

A.

Advanced Threat Prevention

B.

SaaS Security

C.

Advanced WildFire

D.

Advanced DNS Security

Buy Now
Question 2

What are two recommendations to ensure secure and efficient connectivity across multiple locations in a distributed enterprise network? (Choose two.)

Options:

A.

Use Prisma Access to provide secure remote access for branch users.

B.

Employ centralized management and consistent policy enforcement across all locations.

C.

Create broad VPN policies for contractors working at branch locations.

D.

Implement a flat network design for simplified network management and reduced overhead.

Question 3

When a firewall acts as an application-level gateway (ALG), what does it require in order to establish a connection?

Options:

A.

Dynamic IP and Port (DIPP)

B.

Payload

C.

Session Initiation Protocol (SIP)

D.

Pinholes

Question 4

An NGFW administrator is updating PAN-OS on company data center firewalls managed by Panorama. Prior to installing the update, what must the administrator verify to ensure the devices will continue to be supported by Panorama?

Options:

A.

Device telemetry is enabled.

B.

Panorama is configured as the primary device in the log collecting group for the data center firewalls.

C.

All devices are in the same template stack.

D.

Panorama is running the same or newer PAN-OS release as the one being installed.

Question 5

When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?

Options:

A.

Configure port-based policies, check threat logs weekly, conduct software updates annually, and enable decryption.

B.

Configure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles to rules, and update regularly with dynamic updates.

C.

Configure all default policies provided by the firewall, use Policy Optimizer, and adjust security rules after an incident occurs.

D.

Configure a block policy for all malicious inbound traffic, configure an allow policy for all outbound traffic, and update regularly with dynamic updates.

Question 6

In a Prisma SD-WAN environment experiencing voice quality degradation, which initial action is recommended?

Options:

A.

Immediately modify path quality thresholds.

B.

Review real-time analytics of path performance.

C.

Switch all VoIP traffic to backup paths.

D.

Request an RMA of the ION devices.

Question 7

Which file type supports WildFire inline detection?

Options:

A.

APK files

B.

PE files

C.

PDF files

D.

ZIP files

Question 8

Which two tools can be used to configure Cloud NGFWs for AWS? (Choose two.)

Options:

A.

Cortex XSIAM

B.

Prisma Cloud management console

C.

Panorama

D.

Cloud service provider's management console

Question 9

Using Prisma Access, which solution provides the most security coverage of network protocols for the mobile workforce?

Options:

A.

Explicit proxy

B.

Client-based VPN

C.

Enterprise browser

D.

Clientless VPN

Question 10

Which two SSH Proxy decryption profile settings should be configured to enhance the company’s security posture? (Choose two.)

Options:

A.

Block sessions when certificate validation fails.

B.

Allow sessions with legacy SSH protocol versions.

C.

Block connections that use non-compliant SSH versions.

D.

Allow sessions when decryption resources are unavailable.

Question 11

Which two content updates can be pushed to next-generation firewalls from Panorama? (Choose two.)

Options:

A.

Advanced URL Filtering

B.

Applications and threats

C.

WildFire

D.

GlobalProtect data file

Question 12

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

Options:

A.

Cloud Identity Engine

B.

Autonomous Digital Experience Manager (ADEM)

C.

GlobalProtect agent

D.

IPSec termination node

Question 13

Which step is necessary to ensure an organization is using the inline cloud analysis features in its Advanced Threat Prevention subscription?

Options:

A.

Disable anti-spyware to avoid performance impacts and rely solely on external threat intelligence.

B.

Enable SSL decryption in Security policies to inspect and analyze encrypted traffic for threats.

C.

Update or create a new anti-spyware security profile and enable the appropriate local deep learning models.

D.

Configure Advanced Threat Prevention profiles with default settings and only focus on high-risk traffic to avoid affecting network performance.

Question 14

Which two prerequisites must be evaluated when decrypting internet-bound traffic? (Choose two.)

Options:

A.

RADIUS profile

B.

Incomplete certificate chains

C.

Certificate pinning

D.

SAML certificate

Question 15

Which action is only taken during slow path in the NGFW policy?

Options:

A.

Session lookup

B.

Layer 2—Layer 4 firewall processing

C.

SSL/TLS decryption

D.

Security policy lookup

Question 16

Which configurations on hosts are supported for detection by HIP?

Options:

A.

Anti-malware

B.

Disk Encryption

C.

VLAN ID

D.

BGP peer state

Question 17

Which CDSS service mitigates phishing threats?

Options:

A.

URL Filtering

B.

Enterprise DLP

C.

IoT Security

D.

SD-WAN

Question 18

Which subscription sends non-file format-based traffic that matches Data Filtering Profile criteria to a cloud service to render a verdict?

Options:

A.

Enterprise DLP

B.

Advanced URL Filtering

C.

SaaS Security Inline

D.

Advanced WildFire

Question 19

Which two GlobalProtect modes allow partial users to access internal apps via GlobalProtect while other users access internal apps through third-party VPN?

Options:

A.

Proxy

B.

Hybrid, Proxy + Tunnel

C.

Clientless VPN only

D.

Always-On Tunnel only

Question 20

In which two applications can Prisma Access threat logs for mobile user traffic be reviewed? (Choose two.)

Options:

A.

Prisma Cloud dashboard

B.

Strata Cloud Manager (SCM)

C.

Strata Logging Service

D.

Service connection firewall

Question 21

A network security engineer has created a Security policy in Prisma Access that includes a negated region in the source address. Which configuration will ensure there is no connectivity loss due to the negated region?

Options:

A.

Set the service to be application-default.

B.

Create a Security policy for the negated region with destination address “any”.

C.

Add a Dynamic Application Group to the Security policy.

D.

Add all regions that contain private IP addresses to the source address.

Page: 1 / 5
Total 73 questions