NetSec-Pro Palo Alto Networks Certified Network Security Professional Practice Questions
Prepare for NetSec-Pro with more than an answer.
Unlock the full exam and previous versions
- v1Palo Alto Networks Certified Network Security Professional 120 questions Current
- netsec-generalistLegacy Palo Alto Networks Certified Network Security Professional 259 questions Locked
- Exam fee
- $200 USD
- Time limit
- 90 minutes
- Questions on the exam
- 75
- Passing score
- 860 (scale 300-1000)
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 6
- Network Security Fundamentals16%
- NGFW and SASE Solution Functionality18%
- Platform Solutions, Services, and Tools18%
- NGFW and SASE Solution Maintenance and Configuration19%
- Infrastructure Management and CDSS15%
- Connectivity and Security14%
- 1
A manufacturing company needs to secure 5,000 unmanaged IoT devices (sensors, cameras) on their network. They cannot install agents on these devices. Which CDSS solution should be enabled to automatically discover, classify, and recommend security policies for these devices?
Show answer details
Correct answer: B
Device Security, formerly IoT Security or Enterprise IoT Security, discovers and classifies agentless devices passively. It analyzes metadata from the traffic your NGFWs already see, which the firewalls send through the Strata Logging Service. It then generates Security policy rule recommendations for each device profile, which firewalls use through Device-ID, so policy is based on the type of device rather than its IP address. GlobalProtect needs an agent on the endpoint, SaaS Security Inline discovers SaaS applications, and Advanced Threat Prevention blocks threats; none of them classifies IoT devices.
- 2
What is the primary advantage of 'Advanced WildFire' over the standard WildFire subscription?
Show answer details
Correct answer: C
Advanced WildFire includes everything in the standard WildFire subscription and adds an advanced cloud-based detection system for highly evasive malware. It uses intelligent runtime memory analysis, runtime DLL emulation, automated unpacking, family classification and stealth observation. Intelligent Run-time Memory Analysis uses your existing WildFire Analysis profile settings and needs no extra configuration. Real-time signature updates and WildFire Inline ML come with the standard WildFire subscription, and so does analysis of PDF and Office files. Analysis happens in the cloud, not locally on the firewall.
- 3
An organization is using the Best Practice Assessment (BPA) tool. The report indicates a low adoption of 'Log Forwarding Profiles'. Why is this considered a risk?
Show answer details
Correct answer: D
A Log Forwarding profile attached to a Security policy rule sends that rule's logs to external receivers such as Panorama, the Strata Logging Service (formerly Cortex Data Lake), syslog or email. If few rules have one, their logs stay only on the firewall's local disk. They can be lost as local log storage fills, and you get no central visibility for threat hunting and correlation. The firewall still generates the logs.
- 4
A security architect is designing a decryption strategy for a high-security financial institution. The organization requires inspection of outbound SSL/TLS traffic to detect data exfiltration. However, strict privacy regulations mandate that personal banking and healthcare traffic must NEVER be decrypted. Which configuration strategy optimally balances security visibility with regulatory compliance?
Show answer details
Correct answer: D
Palo Alto Networks firewalls process decryption policy rules from top to bottom. To satisfy the requirement, specific traffic (sensitive categories) must be explicitly excluded from decryption using a 'No Decrypt' action before the general rule that decrypts remaining traffic is evaluated. Blocking the categories would prevent business continuity, not just stop decryption.
- 5
A network administrator is troubleshooting an issue where a specific custom application is being identified as 'ssl' instead of its unique App-ID 'custom-corp-app'. The application runs over HTTPS (port 443). The administrator has verified that the custom App-ID signature is correctly defined. What is the most likely cause of this identification failure?
flowchart LR Client -->|HTTPS/443| Firewall Firewall -->|HTTPS/443| Server subgraph Firewall_Logic A[Packet In] --> B{Decryption?} B -->|No| C[App-ID: ssl] B -->|Yes| D[App-ID: custom-corp-app] endShow answer details
Correct answer: B
App-ID uses application signatures to identify traffic. When a session is SSL/TLS and no Decryption policy rule matches it, the firewall sees only the TLS handshake, so it usually identifies the session as ssl and not as the application inside. When a Decryption policy rule decrypts the session (SSL Forward Proxy for outbound traffic, or SSL Inbound Inspection for your own server), App-ID runs the signatures again on the decrypted flow, and the custom-corp-app signature can match. Adding the application to the Security policy rule doesn't change how it is identified. Unencrypted HTTP that can't be identified more specifically appears as web-browsing, not as ssl.
- 6
Which TWO components are essential for implementing a Zero Trust architecture using Palo Alto Networks NGFWs to ensure user identity is verified before granting resource access? (Select TWO)
Show answer details
Correct answer: B, D
User-ID is the fundamental component that maps IP addresses to users, allowing policies to be written based on identity rather than IP.
To enforce Zero Trust, security policies must explicitly allow access only to specific users or groups (Least Privilege), rather than allowing 'Any' user.
