Palo Alto Networks Certified Network Security Analyst Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 130 questions. Use the simulator for timed and flashcard mode. Or, view 299 more questions in the alternate version PCCNSA 299 Questions.

Try Simulator

NetSec-Analyst Sample Questions

  1. Question 1

    Q1

    A security analyst is configuring a new Security Profile Group in Strata Cloud Manager (SCM) to apply consistent protections across multiple rules. The goal is to block known malicious files, prevent command-and-control beacons, and filter access to gambling websites. Which combination of profiles must be added to this group to achieve these specific objectives?

    Show answer & explanation

    Correct answer: A

    The Antivirus profile handles blocking malicious files (malware). The Anti-Spyware profile is responsible for detecting and blocking command-and-control (C2) beacons. The URL Filtering profile controls access to web categories like gambling. Combining these creates the required protection stack.

  2. Question 2

    Q2

    An organization requires SSL decryption for all outbound user traffic to inspect for malware. However, privacy regulations mandate that banking and healthcare traffic must NOT be decrypted. How should the Decryption Policy and Profiles be configured to meet this requirement while minimizing administrative overhead?

    Show answer & explanation

    Correct answer: B

    The best practice is to handle exclusions via policy logic. By placing a 'No Decrypt' rule for sensitive categories higher in the policy list, the firewall processes these first and bypasses decryption. A subsequent rule then catches and decrypts remaining traffic. This is cleaner than managing profile-based exclusions for broad categories.

  3. Question 3

    Q3

    A network administrator is implementing an External Dynamic List (EDL) to block a rapidly changing list of malicious IP addresses provided by a threat intelligence feed. The feed is hosted on an internal HTTPS server. After configuring the EDL object, the administrator notices the firewall is failing to fetch the list. Which of the following is the most likely cause?

    Show answer & explanation

    Correct answer: B

    When an EDL is hosted on an HTTPS server, the firewall acts as a client. It must validate the server's certificate. If the server uses a private CA or a certificate not in the firewall's trusted root store, the connection will fail, preventing the list fetch.

  4. Question 4

    Q4

    You are configuring a custom URL category to control access to a partner portal. The requirement is to match partner.example.com and all its subdomains (e.g., portal.partner.example.com), but specifically EXCLUDE test.partner.example.com from this category. Which pattern configuration correctly achieves this?

    Show answer & explanation

    Correct answer: B

    Custom URL categories do not support 'exclude' logic directly within the object definition itself in a single line. The standard approach is to define the broad match (partner.example.com and *.partner.example.com) in the custom category. The exclusion is handled operationally by placing test.partner.example.com in a separate category (or relying on its default categorization) and ensuring the policy logic or category match preference handles it appropriately. However, strictly speaking about the object definition, you define what IS included. To 'exclude' effectively in policy, you often need a specific allow/block rule for the specific subdomain before the wildcard rule.

  5. Question 5

    Q5

    A retail company uses a centralized SIEM for security monitoring. They want to forward 'Threat' logs from their Palo Alto Networks firewalls to the SIEM but only if the severity is 'High' or 'Critical'. 'Informational' threat logs should be stored locally on the firewall only. How should the Log Forwarding Profile be configured?

    Show answer & explanation

    Correct answer: A

    Log Forwarding Profiles allow granular filtering using the filter builder. By creating a match list specifically for the 'Threat' log type and applying a filter for specific severities, only those matching logs are sent to the configured forwarding destination (Syslog).

  6. Question 6

    Q6Multiple answers

    Which TWO of the following are valid components when configuring an SD-WAN Path Quality Profile to define acceptable performance thresholds for business-critical applications? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    Path Quality Profiles use metrics like Latency, Jitter, and Packet Loss to determine if a path meets the SLA requirements for an application.

    Jitter is a key metric in SD-WAN Path Quality profiles.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the NetSec-Analyst sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 429 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon