netsec-generalist Network Security Professional Practice Questions
Prepare for netsec-generalist with more than an answer.
Unlock the full exam and previous versions
- v1Palo Alto Networks Certified Network Security Professional 120 questions Locked
- netsec-generalistLegacy Palo Alto Networks Certified Network Security Professional 259 questions Current
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 6
- Network Security Fundamentals16%
- NGFW and SASE Solution Functionality18%
- Platform Solutions, Services, and Tools18%
- NGFW and SASE Solution Maintenance and Configuration19%
- Infrastructure Management and CDSS15%
- Connectivity and Security14%
- 1
A security engineer is responsible for managing certificates for a fleet of remote user laptops that connect via GlobalProtect. To enhance security, the company wants to use client certificates for authentication in addition to SAML integration with an IdP. What is the most critical component that must be configured in the GlobalProtect Portal's authentication settings to achieve this?
Show answer details
Correct answer: C
While SAML handles the user identity part of authentication, the firewall needs a way to validate the client certificate presented by the GlobalProtect agent. This is accomplished using a Certificate Profile. The Certificate Profile is configured with the CA certificate that signed the client certificates. This allows the firewall to verify the authenticity and validity of the client certificate during the authentication process. It is a mandatory component for enabling client certificate-based authentication.
- 2
During a security policy review, an administrator is tuning rules for remote users connecting via Prisma Access. They notice that a broad 'allow' rule for the 'ssl' application is generating a high number of sessions and is making it difficult to apply granular threat prevention. What is the recommended approach to tune this policy for better security and visibility?
Show answer details
Correct answer: B
A rule allowing the generic 'ssl' application is a major visibility blind spot. The best practice is to implement SSL Forward Proxy decryption. Once the traffic is decrypted, App-ID can accurately identify the specific applications running inside the SSL tunnel (e.g., 'google-drive', 'salesforce', 'github'). The administrator can then create granular Security policy rules for these specific applications, allowing for tailored threat prevention profiles and much tighter security control.
- 3
A packet is processed by a Palo Alto Networks firewall. It matches an existing session in the firewall's session table that has already been offloaded to the hardware for accelerated processing. Which processing path will this packet take?
Show answer details
Correct answer: B
The firewall uses two main processing paths. The Slow Path (or session setup path) is used for the first packet of a new session, where policy lookups, App-ID, and Content-ID are performed. Once the session is established and deemed eligible for acceleration, it is offloaded to hardware. All subsequent packets for that session are processed entirely in the Fast Path for maximum performance, bypassing the more intensive Slow Path processing.
- 4
When implementing SSL Forward Proxy decryption, what is the primary purpose of deploying the firewall's forward trust certificate to all client browsers in the organization?
Show answer details
Correct answer: C
SSL Forward Proxy is a legitimate man-in-the-middle operation. The firewall intercepts the client's SSL/TLS session, establishes its own session to the destination server, and then creates a new session back to the client, signing the server's certificate with its own 'forward trust' certificate. Because clients' browsers do not inherently trust the firewall as a Certificate Authority, they will present a certificate warning. Deploying the forward trust certificate to the clients' trusted CA stores makes the browser trust the firewall, eliminating these warnings and allowing decryption to occur seamlessly.
- 5
A remote user reports intermittent connectivity issues to an internal application. A security administrator is analyzing the Prisma Access logs in Strata Logging Service to troubleshoot. The logs show that some packets from the user are being dropped with the message 'policy-deny'. The user is part of the 'Engineering' group, which should have access. Which of the following is the most logical next step in troubleshooting this issue based on the provided diagram?
sequenceDiagram participant User as Remote User (192.168.1.10) participant PA as Prisma Access participant App as Internal App (10.10.0.50) User->>PA: TCP SYN to 10.10.0.50 Note over PA: Rule #5: Eng-Access (Allow) Note over PA: Rule #20: Default-Deny (Deny) PA-->>User: TCP RST (Connection Reset)Show answer details
Correct answer: D
The log message 'policy-deny' explicitly indicates that the traffic is being dropped by a security policy. Since the diagram shows an intended 'allow' rule (Rule #5) and a final 'deny' rule (Rule #20), the most probable cause of an intermittent 'policy-deny' is that another, more specific deny rule exists between Rule #1 and Rule #4 that is sometimes matching the user's traffic. Palo Alto Networks firewalls process rules from top to bottom and stop at the first match. An intermittent issue could be caused by the application changing behavior or ports, causing it to match a different, higher-priority deny rule.
- 6
A financial services company is deploying a Zero Trust architecture. A key requirement is to ensure that only authenticated and authorized users on compliant devices can access internal applications. A security architect has configured GlobalProtect with Host Information Profile (HIP) checks and User-ID. During testing, a user on a non-compliant device is still able to access a sensitive application. The Security policy rule for this application correctly specifies the user's group. What is the most likely misconfiguration causing this policy failure?
Show answer details
Correct answer: B
In a Zero Trust model using GlobalProtect, enforcing device compliance requires both collecting HIP data and applying it in policy. While the Security policy rule correctly identifies the user group via User-ID, it is ineffective at checking device posture without a HIP Profile attached. The HIP Profile defines what constitutes a 'compliant' device, and adding this profile to the rule ensures that traffic will only match if both the user and the device posture criteria are met.
- 7
A network engineer observes that traffic destined for a trusted internal web server, which is protected by a Palo Alto Networks firewall with SSL Inbound Inspection, is being dropped. The traffic logs show the session is ending with a 'decrypt-error' message. The server uses a certificate signed by an internal Certificate Authority (CA). Which two actions are most likely to resolve this issue? (Select TWO)
Show answer details
Correct answer: C, E
For SSL Inbound Inspection to work, the firewall must be able to act as the destination web server. This requires importing the server's certificate and its corresponding private key. Additionally, because the server's certificate is signed by an internal CA, the firewall itself does not inherently trust this CA. You must import the internal root CA certificate onto the firewall and explicitly configure it as a Trusted Root CA to validate the server certificate's chain of trust.
- 8
An administrator is configuring a new VM-Series firewall in Azure to inspect traffic between a 'spoke' Virtual Network (VNet) and a 'hub' VNet. The spoke VNet is peered with the hub VNet, which contains the firewall. The administrator has configured User-Defined Routes (UDRs) in the spoke VNet to direct all traffic (0.0.0.0/0) to the firewall's internal interface. However, systems in the spoke VNet cannot access the internet. What is the most likely cause of this issue?
Show answer details
Correct answer: B
In a hub-and-spoke topology where traffic is forced through a firewall, the private IP addresses from the spoke VNet are not routable on the public internet. The firewall must translate the source IP addresses of the traffic from the spoke VNet to its own public-facing IP address before sending it to the internet. This requires a Source NAT (SNAT) policy. Without it, return traffic from the internet will not know how to get back to the originating private IP in the spoke VNet.
- 9
A retail company uses Prisma SD-WAN to connect its stores to a central data center. To improve the performance of a custom point-of-sale (POS) application, an administrator has created a path policy to prioritize this traffic over an MPLS link. However, monitoring tools show that the POS application traffic is still being sent over the backup broadband internet link, causing slow transaction times. What is the most likely reason for the path policy not being applied as intended?
Show answer details
Correct answer: C
Prisma SD-WAN continuously monitors the health of all available paths based on metrics like latency, jitter, and packet loss. If a path, such as the MPLS link, fails to meet the configured health thresholds, it will be marked as down or degraded. Even if a path policy explicitly directs traffic to that link, the SD-WAN controller will automatically reroute the traffic to the next-best available path (the broadband link) to maintain connectivity, bypassing the preferred path.
- 10
A consultant is designing a Prisma Access deployment for a global enterprise. The enterprise has a significant presence in both North America and Asia, with users in both regions needing low-latency access to private applications hosted in an AWS VPC in the
us-east-1region. Which Prisma Access components are required to provide an optimal and secure solution? (Select THREE)Show answer details
Correct answer: A, B, E
A complete Prisma Access solution requires several components. A Service Connection is essential to connect the Prisma Access backbone to the private applications in the AWS VPC. Remote Network connections are needed to securely connect the physical office locations to Prisma Access. Finally, GlobalProtect must be deployed on user devices to provide secure access for mobile and remote users, ensuring they connect to the nearest Prisma Access node for low-latency performance.
