Pass the Paloalto Networks Network Security Administrator NetSec-Pro Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a data center NGFW that already has one enabled. What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?

Options:

A.

It allows for traffic inspection at the application level.


B.

There will be no additional performance degradation.


C.

There will be only a minor reduction in performance.


D.

It allows additional security inspection devices to be added inline.


Questions # 2:

Which feature of SaaS Security will allow a firewall administrator to identify unknown SaaS applications in an environment?

Options:

A.

App-ID Cloud Engine


B.

App-ID


C.

SaaS Data Security


D.

Cloud Identity Engine


Questions # 3:

Which two components of a Security policy, when configured, allow third-party contractors access to internal applications outside business hours? (Choose two.)

Options:

A.

App-ID


B.

Service


C.

User-ID


D.

Schedule


Questions # 4:

Which zone is available for use in Prisma Access?

Options:

A.

Clientless VPN


B.

Interzone


C.

Intrazone


D.

DMZ


Questions # 5:

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

Options:

A.

Cloud Identity Engine


B.

Autonomous Digital Experience Manager (ADEM)


C.

GlobalProtect agent


D.

IPSec termination node


Questions # 6:

Which GlobalProtect configuration is recommended for granular security enforcement of remote user device posture?

Options:

A.

Configuring host information profile (HIP) checks for all mobile users


B.

Configuring a rule that blocks the ability of users to disable GlobalProtect while accessing internal applications


C.

Implementing multi-factor authentication (MFA) for all users attempting to access internal applications


D.

Applying log at session end to all GlobalProtect Security policies


Questions # 7:

What occurs when a security profile group named “default” is created on an NGFW?

Options:

A.

It only applies to traffic that has been dropped due to the reset client action.


B.

It allows traffic to bypass all security checks by default.


C.

It negates all existing security profiles rules on new policy.


D.

It is automatically applied to all new security rules.


Questions # 8:

Which set of practices should be implemented with Cloud Access Security Broker (CASB) to ensure robust data encryption and protect sensitive information in SaaS applications?

Options:

A.

Do not enable encryption for data-at-rest to improve performance.


B.

Use default encryption keys provided by the SaaS provider.


C.

Perform annual encryption key rotations.


D.

Enable encryption for data-at-rest and in transit, regularly update encryption keys, and use strong encryption algorithms.


Questions # 9:

Which subscription sends non-file format-based traffic that matches Data Filtering Profile criteria to a cloud service to render a verdict?

Options:

A.

Enterprise DLP


B.

Advanced URL Filtering


C.

SaaS Security Inline


D.

Advanced WildFire


Questions # 10:

Which NGFW function can be used to enhance visibility, protect, block, and log the use of Post-quantum Cryptography (PQC)?

Options:

A.

DNS Security profile


B.

Decryption policy


C.

Security policy


D.

Decryption profile


Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions