Skip to main content

PAN-NSG Online Practice Questions

Palo Alto Networks Network Security Generalist

98 questions available · Page 1 of 10

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Infrastructure performance issues and resource constraints have prompted a firewall administrator to
monitor hardware NGFW resource statistics.

Which AlOps feature allows the administrator to review these statistics for each firewall in the environment?

  1. A

    Capacity Analyzer

  2. B

    Host information profile (HIP)

  3. C

    Policy Analyzer

  4. D

    Security Posture Insights

Show answer and explanation

Correct answer: A

Explanation

The Capacity Analyzerfeature in Palo Alto Networks' AIOps for NGFW (Next-Generation Firewall) provides administrators with insights into hardware resource statistics for each firewall in the environment. It helps identify infrastructure performance issues and resource constraints, such as CPU usage, session capacity, and throughput levels.
Capacity Monitoring: It enables real-time and historical monitoring of resource usage to ensure optimal performance.
Proactive Issue Detection: Administrators can proactively address resource constraints before they impact the network.
Unified Visibility: With AIOps, the Capacity Analyzer aggregates data from all managed firewalls, providing centralized visibility into resource utilization across the environment.

References:
Palo Alto Networks AIOps Documentation
Capacity Analyzer Overview

Question 2 Single choice

Which object would an administrator create to block access to all high-risk applications?

  1. A

    HIP profile

  2. B

    application filter

  3. C

    application group

  4. D

    Vulnerability Protection profile

Show answer and explanation

Correct answer: B

Explanation

References:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKECA0

Question 3 Multiple choice

Which five Zero Trust concepts does a Palo Alto Networks firewall apply to achieve an integrated approach to prevent threats? (Choose five.)

  1. A

    User identification

  2. B

    Filtration protection

  3. C

    Vulnerability protection

  4. D

    Antivirus

  5. E

    Application identification

  6. F

    Anti-spyware

Show answer and explanation

Correct answers: A, C, D, E, F

Question 4 Single choice

Which zone is available for use in Prisma Access?

  1. A

    DMZ

  2. B

    Interzone

  3. C

    Intrazone

  4. D

    Clientless VPN

Show answer and explanation

Correct answer: D

Explanation

Prisma Access, a cloud-delivered security platform by Palo Alto Networks, supports specific predefined zones to streamline policy creation and enforcement. The se zones are integral to how traffic is managed and secured within the service.
Available Zones in Prisma Access: Trust Zone:This zone encompasses all trusted and onboarded IP addresses, service connections, ormobile users within the corporate network. Traffic originating from these entities is considered trusted.
Untrust Zone:This zone includes all untrusted IP addresses, service connections, or mobile users outside the corporate network. By default, any IP address or mobile user that is not designated as trusted falls into this category. Clientless VPN Zone:Designed to provide secure remote access to common enterprise web applications that utilize HTML, HTML5, and JavaScript technologies. This feature allows users to securely access applications from SSL-enabled web browsers without the need to install client software, which is particularly useful for enabling partner or contractor access to applications and for safely accommodating unmanaged assets, including personal devices. Notably, the Clientless VPN zone is mapped to the trust zone by default, and this setting cannot be changed.
Analysis of Options:
A. DMZ:A Demilitarized Zone (DMZ) is a physical or logical subnetwork that separates an internal local

area network (LAN) from other untrusted networks, typically the internet. While traditional network architectures often employ a DMZ to add an extra layer of security, Prisma Access does not specifically define or utilize a DMZ zone within its predefined zone structure. B. Interzone:In the context of Prisma Access, "interzone" is not a predefined zone available for user configuration. However, it's worth noting that Prisma Access logs may display a zone labeled "inter-fw," which pertains to internal communication within the Prisma Access infrastructure and is not intended for user-defined policy application.
C. Intrazone:Intrazone typically refers to traffic within the same zone. While security policies can be
configured to allow or deny intrazone traffic, "Intrazone" itself is not a standalone zone available for configuration in Prisma Access. D. Clientless VPN:As detailed above, the Clientless VPN is a predefined zone in Prisma Access, designed to facilitate secure, clientless access to web applications.
Conclusion:
Among the options provided,D. Clientless VPNis the correct answer, as it is an available predefined zone in Prisma Access.

References:
Palo Alto Networks. "Prisma Access Zones." (https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/prisma-access-zones)

Question 5 Single choice

An organization wants to host multiple business units on a single firewall while keeping each unit's policies, objects, and logs logically separate.

Which capability provides this design?

  1. A

    DHCP relay

  2. B

    Virtual systems

  3. C

    SSL Inbound Inspection

  4. D

    WildFire forwarding

Show answer and explanation

Correct answer: B

Explanation

Virtual systems provide logical multitenancy on a single physical firewall by allowing separate business units or tenants to maintain independent configurations, policies, and logging. This approach supports isolation while still using shared hardware resources, making it well suited to environments that need separation without separate appliances. It is the standard design choice for logical segmentation of management and inspection contexts on the same device.
Option A is incorrect because DHCP relay is used to forward DHCP messages and does not create tenant separation.
Option C is incorrect because SSL Inbound Inspection is a decryption function, not a multitenancy mechanism.
Option D is incorrect because WildFire forwarding is related to threat analysis and does not separate tenants or policy domains.

Question 6 Single choice

A company uses Prisma Access for mobile users and needs those users to reach an internal application hosted in the data center. There is currently no path between Prisma Access and the internal network.

What must be deployed to provide that connectivity?

  1. A

    Service connection

  2. B

    Dynamic User Group

  3. C

    Security processing node

  4. D

    Clientless VPN zone

Show answer and explanation

Correct answer: A

Explanation

A service connection creates the secure path between Prisma Access and the internal network so that mobile-user traffic can be routed to internal resources. This enables users connected through Prisma Access to access applications hosted in the data center or other internal environments. It is the required feature when routing between Prisma Access and internal destinations does not already exist.
Option B is incorrect because Dynamic User Groups are used for user-based policy decisions, not network connectivity.
Option C is incorrect because a security processing node handles inspection functions rather than establishing routing to internal networks.
Option D is incorrect because a Clientless VPN zone is not the mechanism used to build general network connectivity from Prisma Access to internal applications.

Question 7 Single choice

In conjunction with Advanced URL Filtering, which feature can be enabled after usemame-to-IP mapping is set up?

  1. A

    Host information profile (HIP)

  2. B

    Credential phishing prevention

  3. C

    Client probing

  4. D

    Indexed data matching

Show answer and explanation

Correct answer: B

Explanation

WhenAdvanced URL Filteringis enabled,Credential Phishing Preventioncan be activated toprotect against phishing attacksby blocking unauthorized credential submissions.
Uses Username-to-IP Mapping - Identifies usersbased on their IP and login credentials.
Prevents Credential The ft - Blocks users from submitting corporate credentials tountrusted or malicious websites.
Works Alongside Advanced URL Filtering - Detects and categorizesphishing domains in real-time, stopping credential leaks.
Can Enforce Action-Based Policies - Configures policies toalert, block, or validate credential submissions.
A. Host Information Profile (HIP)#
Incorrect, becauseHIP checks device healthbut does notprevent credential phishing.
C. Client Probing#
Incorrect, becauseClient Probing is used for User-ID mapping, notphishing prevention.
D. Indexed Data Matching#
Incorrect, becauseIndexed Data Matching is used for DLP (Data Loss Prevention), not for credential protection.
Firewall Deployment - Protectsuser credentials from phishing attacks.
Security Policies - Ensuresusers do not submit credentials to malicious sites.

VPN Configurations - Protectsremote users connecting via GlobalProtectfrom credential theft.
Threat Prevention - Works withThreat Intelligenceto detect new phishing sites.
WildFire Integration - Scansunknown websites for phishing behaviors.
Panorama - Centralized enforcement ofCredential Phishing Prevention policies.
Zero Trust Architectures - Ensuresonly legitimate authentication events occur within trusted environments.
How Credential Phishing Prevention Works:Why Other Options Are Incorrect?References to Firewall Deployment and Security Features:Thus, the correct answer is:#B. Credential phishing prevention

Question 8 Single choice

A security team wants to use AIOps for NGFW to reduce configuration drift and detect risky changes across dozens of firewalls managed by Panorama.

Which AIOps feature directly helps identify and alert on deviations from best practices and policy misconfigurations?

  1. A

    Policy Analyzer

  2. B

    Capacity Analyzer

  3. C

    Host Information Profile analyzer

  4. D

    Decryption Broker

Show answer and explanation

Correct answer: A

Explanation

AIOps for NGFW providesanalytics and best-practice validationacross firewalls.
Policy Analyzer (A)
Inspects existingSecurity policies, objects, and configurationsagainstbest-practice checks.
Highlightsoverly permissive rules, unused objects, and misconfigurations that increase risk.
Can triggeralertswhen new changes introducepolicy driftfrom recommended baselines.

B. Capacity Analyzer
Monitors hardware resource utilization, notpolicy correctness.
C. Host Information Profile analyzer
HIP is anendpoint posture feature of GlobalProtect; it is not an AIOps analyzer.
D. Decryption Broker
Relates todecryption traffic distributionand does not evaluate configuration risk.

Firewall Deployment - Panorama-managed firewalls are continuously evaluated by AIOps.
Security Policies - Policy Analyzer supports ongoinghardeningandcleanup of rules.
Zero Trust Architectures - Helps enforce "never trust, always verify" throughleast-privilege policy designs.

Question 9 Single choice

An internal host wants to connect to servers of the internet through using source NAT.

Which policy is required to enable source NAT on the firewall?

  1. A

    NAT policy with source zone and destination zone specified

  2. B

    post-NAT policy with external source and any destination address

  3. C

    NAT policy with no source of destination zone selected

  4. D

    pre-NAT policy with external source and any destination address

Show answer and explanation

Correct answer: A

Question 10 Multiple choice

Which two security profiles must be updated to prevent data exfiltration in outbound traffic on NGFWs? (Choose two.)

  1. A

    Data Filtering

  2. B

    DoS Protection

  3. C

    File Blocking

  4. D

    Antivirus

Show answer and explanation

Correct answers: A, C

Explanation

To preventdata exfiltration in outbound traffic,Next-Generation Firewalls (NGFWs)must have the followingsecurity profiles configured and updated: Data Filtering (##Correct)
Detects and preventssensitive data leaksin outbound traffic.
Monitors forPersonally Identifiable Information (PII), financial data, and intellectual property.
Canalert, block, or quarantineattempts to send confidential information externally.

File Blocking (##Correct)
Preventsunauthorized file transfersover email, cloud storage, and web uploads.
Blocks file typescommonly used for exfiltration, such as.zip, .docx, .csv, and .txt.
Helps stopcovert data exfiltration through disguised files.
B. DoS Protection#
Incorrect, becauseDoS Protection prevents volumetric attacksbut does not stopdata exfiltration attempts.
D. Antivirus#
Incorrect, becauseAntivirus detects malware, notsensitive data transfers.
Firewall Deployment - Preventsunauthorized data leaksthrough outbound connections.
Security Policies - Enforcescontent-based and file-based exfiltration prevention.
VPN Configurations - Ensuresencrypted VPNs do not become data exfiltration channels.
Threat Prevention - Monitors forinsider threats and advanced persistent threats (APTs)attempting exfiltration.
WildFire Integration - Detectsmalware that might be exfiltrating data.
Zero Trust Architectures - Preventsunauthorized data movement across network zones.

Why Other Options Are Incorrect?References to Firewall Deployment and Security Features: Thus, the correct answers are:#A. Data Filtering#C. File Blocking