Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Network Security Administrator NetSec-Analyst Exam Questions and Answers PDF

Palo Alto Networks Network Security Analyst Questions and Answers

Question 13

An analyst notices that a security rule intended to block a specific application is being bypassed. Upon investigation, the analyst finds that the traffic is matching a rule higher in the list. Which tool provides a visual "Shadowing" check to identify rules that will never be hit?

Options:

A.

Config Audit

B.

Policy Optimizer

C.

Rule Usage Filter

D.

ACC (Application Command Center)

Question 14

A company requires that all encrypted traffic from the "Accounting" department be decrypted for inspection, while all other departments remain encrypted. How should the analyst configure the Decryption Policy?

Options:

A.

Create a single rule with "Source Zone" set to Accounting and "Action" to Decrypt.

B.

Create a "No Decrypt" rule for all zones except Accounting.

C.

Use "User-ID" in the Decryption Policy to target only members of the Accounting group.

D.

Apply a decryption profile to the Accounting Security Policy rule.

Question 15

What is the benefit of the Command Center’s centralized dashboard in Strata Cloud Manager (SCM)?

Options:

A.

Monitoring encryption for network performance optimization

B.

Using AI to predict and prevent potential security incidents

C.

Automatically patching security vulnerabilities

D.

Monitoring and managing threats and operational health

Question 16

An analyst is investigating why an App-ID for a custom application is showing as "unknown-tcp" in the Traffic logs. The application is running on port 8080. What is the most likely cause of this identification failure?

Options:

A.

The firewall does not have a signature for the proprietary application.

B.

The Security policy is set to "application-default."

C.

The traffic is being decrypted by an SSL Forward Proxy.

D.

The URL category is "private-ip-addresses."