NetSec-Analyst Palo Alto Networks Certified Network Security Analyst Practice Questions
Prepare for NetSec-Analyst with more than an answer.
Unlock the full exam and previous versions
- v1Palo Alto Networks Certified Network Security Analyst 130 questions Current
- PCCNSALegacy Palo Alto Networks Certified Network Security Analyst 299 questions Locked
- Exam fee
- $250 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 4
- Object Configuration Creation and Application30%
- Policy Creation and Application30%
- Management and Operations26%
- Troubleshooting14%
- 1
A financial institution uses a Vulnerability Protection Profile to block known exploits. However, an internal legacy application triggers a specific threat signature (ID 30005) that results in a false positive, blocking legitimate business traffic. How should the administrator allow this traffic for ONLY this application while maintaining protection against this threat for all other traffic?
Show answer details
Correct answer: A
The most secure and granular approach is to create a specific profile for the exception. By cloning the standard profile and modifying the action for the specific threat ID to 'Allow', and then applying this profile ONLY to the rule for the legacy app, you maintain strict protection for the rest of the network.
- 2
Which Data Filtering Profile action should be selected if the goal is to prevent the upload of credit card numbers but also alert the security team and log the event, without resetting the connection immediately (to avoid breaking the user experience for non-malicious errors)?
Show answer details
Correct answer: D
In Data Filtering, the 'Block' action prevents the file transfer and generates a log. While the question mentions avoiding a reset, 'Block' in file/data blocking usually stops the transfer. However, if the intent is to strictly prevent the upload, 'Block' is the correct security action. If the question implies 'User Alert' (a specific action), that might be valid, but typically 'Block' is the standard for DLP enforcement. Wait - reading carefully: 'without resetting the connection immediately'. Often 'Block' sends a block page. Let's look at options. 'Alert' would log but not stop it. 'Block' stops it. The requirement is 'prevent the upload'. So 'Block' is required. A TCP Reset terminates the session abruptly. A 'Block' usually sends a 403 or replacement message, which is better UX than a hard reset.
- 3
You need to create a custom data pattern to detect a proprietary internal project code format:
PROJ-followed by exactly 6 digits (e.g.,PROJ-123456). Which Regular Expression (Regex) correctly defines this pattern for a Data Filtering object?Show answer details
Correct answer: C
In Regex,
\drepresents any digit (0-9).{6}specifies that the preceding element must appear exactly 6 times. Thus,PROJ-\d{6}matches 'PROJ-' followed by exactly 6 digits. - 4
A security analyst is configuring a new Security Profile Group in Strata Cloud Manager (SCM) to apply consistent protections across multiple rules. The goal is to block known malicious files, prevent command-and-control beacons, and filter access to gambling websites. Which combination of profiles must be added to this group to achieve these specific objectives?
Show answer details
Correct answer: D
The Antivirus profile handles blocking malicious files (malware). The Anti-Spyware profile is responsible for detecting and blocking command-and-control (C2) beacons. The URL Filtering profile controls access to web categories like gambling. Combining these creates the required protection stack.
- 5
An organization requires SSL decryption for all outbound user traffic to inspect for malware. However, privacy regulations mandate that banking and healthcare traffic must NOT be decrypted. How should the Decryption Policy and Profiles be configured to meet this requirement while minimizing administrative overhead?
Show answer details
Correct answer: D
The best practice is to handle exclusions via policy logic. By placing a 'No Decrypt' rule for sensitive categories higher in the policy list, the firewall processes these first and bypasses decryption. A subsequent rule then catches and decrypts remaining traffic. This is cleaner than managing profile-based exclusions for broad categories.
- 6
A network administrator is implementing an External Dynamic List (EDL) to block a rapidly changing list of malicious IP addresses provided by a threat intelligence feed. The feed is hosted on an internal HTTPS server. After configuring the EDL object, the administrator notices the firewall is failing to fetch the list. Which of the following is the most likely cause?
Show answer details
Correct answer: B
When an EDL is hosted on an HTTPS server, the firewall acts as a client. It must validate the server's certificate. If the server uses a private CA or a certificate not in the firewall's trusted root store, the connection will fail, preventing the list fetch.
