Palo Alto Networks Certified Network Security Professional Free Sample Questions

20 free sample questions259 in the full practice test Other version: NetSec-Pro(120)

Try simulator

netsec-generalist Sample Questions

  1. Question 1

    A financial services company is deploying a Zero Trust architecture. A key requirement is to ensure that only authenticated and authorized users on compliant devices can access internal applications. A security architect has configured GlobalProtect with Host Information Profile (HIP) checks and User-ID. During testing, a user on a non-compliant device is still able to access a sensitive application. The Security policy rule for this application correctly specifies the user's group. What is the most likely misconfiguration causing this policy failure?

    Answer and explanation

    Correct answer: B

    In a Zero Trust model using GlobalProtect, enforcing device compliance requires both collecting HIP data and applying it in policy. While the Security policy rule correctly identifies the user group via User-ID, it is ineffective at checking device posture without a HIP Profile attached. The HIP Profile defines what constitutes a 'compliant' device, and adding this profile to the rule ensures that traffic will only match if both the user and the device posture criteria are met.

  2. Question 2

    Multiple answers

    A network engineer observes that traffic destined for a trusted internal web server, which is protected by a Palo Alto Networks firewall with SSL Inbound Inspection, is being dropped. The traffic logs show the session is ending with a 'decrypt-error' message. The server uses a certificate signed by an internal Certificate Authority (CA). Which two actions are most likely to resolve this issue? (Select TWO)

    Answer and explanation

    Correct answers: A, D

    For SSL Inbound Inspection to work, the firewall must be able to act as the destination web server. This requires importing the server's certificate and its corresponding private key. Additionally, because the server's certificate is signed by an internal CA, the firewall itself does not inherently trust this CA. You must import the internal root CA certificate onto the firewall and explicitly configure it as a Trusted Root CA to validate the server certificate's chain of trust.

  3. Question 3

    An administrator is configuring a new VM-Series firewall in Azure to inspect traffic between a 'spoke' Virtual Network (VNet) and a 'hub' VNet. The spoke VNet is peered with the hub VNet, which contains the firewall. The administrator has configured User-Defined Routes (UDRs) in the spoke VNet to direct all traffic (0.0.0.0/0) to the firewall's internal interface. However, systems in the spoke VNet cannot access the internet. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: C

    In a hub-and-spoke topology where traffic is forced through a firewall, the private IP addresses from the spoke VNet are not routable on the public internet. The firewall must translate the source IP addresses of the traffic from the spoke VNet to its own public-facing IP address before sending it to the internet. This requires a Source NAT (SNAT) policy. Without it, return traffic from the internet will not know how to get back to the originating private IP in the spoke VNet.

  4. Question 4

    A retail company uses Prisma SD-WAN to connect its stores to a central data center. To improve the performance of a custom point-of-sale (POS) application, an administrator has created a path policy to prioritize this traffic over an MPLS link. However, monitoring tools show that the POS application traffic is still being sent over the backup broadband internet link, causing slow transaction times. What is the most likely reason for the path policy not being applied as intended?

    Answer and explanation

    Correct answer: A

    Prisma SD-WAN continuously monitors the health of all available paths based on metrics like latency, jitter, and packet loss. If a path, such as the MPLS link, fails to meet the configured health thresholds, it will be marked as down or degraded. Even if a path policy explicitly directs traffic to that link, the SD-WAN controller will automatically reroute the traffic to the next-best available path (the broadband link) to maintain connectivity, bypassing the preferred path.

  5. Question 5

    Multiple answers

    A consultant is designing a Prisma Access deployment for a global enterprise. The enterprise has a significant presence in both North America and Asia, with users in both regions needing low-latency access to private applications hosted in an AWS VPC in the us-east-1 region. Which Prisma Access components are required to provide an optimal and secure solution? (Select THREE)

    Answer and explanation

    Correct answers: A, B, D

    A complete Prisma Access solution requires several components. A Service Connection is essential to connect the Prisma Access backbone to the private applications in the AWS VPC. Remote Network connections are needed to securely connect the physical office locations to Prisma Access. Finally, GlobalProtect must be deployed on user devices to provide secure access for mobile and remote users, ensuring they connect to the nearest Prisma Access node for low-latency performance.

  6. Question 6

    A large enterprise manages over 500 firewalls globally using Panorama. A junior administrator is tasked with creating a new Security policy rule to block a newly identified malicious application. To ensure the rule is applied globally and consistently, what is the best practice for deploying this rule using Panorama?

    Answer and explanation

    Correct answer: B

    Panorama uses a hierarchical structure for policies with Pre-rules, Local rules, and Post-rules. Pre-rules are evaluated first and are inherited by all lower-level device groups. To enforce a global blocking rule that cannot be overridden by local administrators, the best practice is to place it in the Pre-rules of the top-level device group. This ensures it is applied consistently across all 500 firewalls and takes precedence over any more specific, local rules.

  7. Question 7

    True or False: When configuring Enterprise DLP, a data pattern for 'Credit Card Numbers' is applied to a Security policy rule. This configuration, by itself, is sufficient to both detect and block the exfiltration of credit card numbers in web traffic.

    Answer and explanation

    Correct answer: B

    This statement is false. Enterprise DLP requires a multi-step configuration. First, you define a Data Pattern (e.g., for credit card numbers). Second, you add this pattern to a Data Filtering Profile and set the action to 'block'. Finally, this Data Filtering Profile must be attached to the relevant Security policy rule. Simply having the data pattern defined and attached to a rule without the profile and action is insufficient to block exfiltration.

  8. Question 8

    A hospital has implemented Palo Alto Networks IoT Security to protect its medical devices. The security team receives an alert for a device identified as an 'Infusion Pump' that is attempting to connect to an external IP address using SSH. This behavior violates the hospital's security policy. Based on IoT Security best practices, what is the most effective and least disruptive way to prevent this specific activity while allowing the pump to perform its normal functions?

    Answer and explanation

    Correct answer: B

    Palo Alto Networks IoT Security learns the normal behavior of devices and can automatically generate security policy recommendations based on this baseline. This feature creates highly specific rules using Device-ID, App-ID, and known destinations. By importing and applying this recommended policy, the administrator can create a rule that allows only the legitimate, expected traffic for the 'Infusion Pump' device profile and implicitly denies all other traffic, such as the anomalous SSH connection, without disrupting its core medical functions.

  9. Question 9

    A security analyst is reviewing the Threat logs and notices that a PDF file downloaded by a user was assigned a 'malicious' verdict by Advanced WildFire. The firewall configuration includes a Security policy rule with a WildFire Analysis profile set to 'alert' for all file types. The user's machine is now showing signs of compromise. To prevent this from happening in the future, what is the most critical configuration change?

    Answer and explanation

    Correct answer: B

    The WildFire Analysis profile determines which files get sent to the sandbox for analysis, but it does not block files based on verdicts. The blocking action is handled by other security profiles. When WildFire identifies a file as malicious, it generates a new signature and categorizes it under the 'wildfire-virus' subtype. To proactively block future downloads of this and other WildFire-identified malware, the Antivirus profile must be configured to block (e.g., 'reset-both') this specific subtype. This ensures that once a verdict is known, subsequent attempts to download the same file are immediately blocked.

  10. Question 10

    The Best Practice Assessment (BPA) tool has been run against a firewall configuration. The report indicates a 60% adoption rate for 'Content-ID Best Practices' and flags several Security policy rules that use service objects (e.g., 'service-http') instead of App-ID. What is the primary security risk associated with this configuration?

    Answer and explanation

    Correct answer: C

    The core advantage of App-ID over port-based rules is its ability to identify the true application regardless of the port it uses. When a rule is configured with a service object like 'service-http' (port 80), it allows any application to use that port. This creates a significant security gap, as malicious or unwanted applications (e.g., peer-to-peer file sharing, remote access tools) can tunnel their traffic over port 80 to bypass security controls. Using App-ID ensures that only the intended application (e.g., 'web-browsing') is allowed, effectively closing this gap.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 379 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon