Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

NetSec-Pro Questions and Answers

Question # 6

What are two recommendations to ensure secure and efficient connectivity across multiple locations in a distributed enterprise network? (Choose two.)

A.

Use Prisma Access to provide secure remote access for branch users.

B.

Employ centralized management and consistent policy enforcement across all locations.

C.

Create broad VPN policies for contractors working at branch locations.

D.

Implement a flat network design for simplified network management and reduced overhead.

Full Access
Question # 7

Which action is only taken during slow path in the NGFW policy?

A.

Session lookup

B.

Layer 2—Layer 4 firewall processing

C.

SSL/TLS decryption

D.

Security policy lookup

Full Access
Question # 8

Which component of NGFW is supported in active/passive design but not in active/active design?

A.

Single floating IP address

B.

Using a DHCP client

C.

Route-based redundancy

D.

Configuring ARP load-sharing on Layer 3

Full Access
Question # 9

Which action allows an engineer to collectively update VM-Series firewalls with Strata Cloud Manager (SCM)?

A.

Creating an update grouping rule

B.

Scheduling software update

C.

Creating a device grouping rule

D.

Setting a target OS version

Full Access
Question # 10

Which offering can be managed in both Panorama and Strata Cloud Manager (SCM)?

A.

Autonomous Digital Experience Manager (ADEM)

B.

VM-Series Next-Generation Firewall (NGFW)

C.

Prisma SD-WAN

D.

SaaS Security

Full Access
Question # 11

Which step is necessary to ensure an organization is using the inline cloud analysis features in its Advanced Threat Prevention subscription?

A.

Disable anti-spyware to avoid performance impacts and rely solely on external threat intelligence.

B.

Enable SSL decryption in Security policies to inspect and analyze encrypted traffic for threats.

C.

Update or create a new anti-spyware security profile and enable the appropriate local deep learning models.

D.

Configure Advanced Threat Prevention profiles with default settings and only focus on high-risk traffic to avoid affecting network performance.

Full Access
Question # 12

A network administrator obtains Palo Alto Networks Advanced Threat Prevention and Advanced DNS Security subscriptions for edge NGFWs and is setting up security profiles. Which step should be included in the initial configuration of the Advanced DNS Security service?

A.

Create a decryption policy rule to decrypt DNS-over-TLS / port 853 traffic.

B.

Create overrides for all company owned FQDNs.

C.

Configure DNS Security signature policy settings to sinkhole malicious DNS queries.

D.

Enable Advanced Threat Prevention with default settings and only focus on high-risk traffic.

Full Access
Question # 13

A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs. Which two report types achieve this goal? (Choose two.)

A.

SNMP

B.

Custom

C.

PDF summary

D.

CSV export

Full Access
Question # 14

Which NGFW function can be used to enhance visibility, protect, block, and log the use of Post-quantum Cryptography (PQC)?

A.

DNS Security profile

B.

Decryption policy

C.

Security policy

D.

Decryption profile

Full Access
Question # 15

Which two compliance standards are supported by SCM compliance reports?

A.

PCI-DSS

B.

NIST

C.

CIS

D.

GDPR

Full Access
Question # 16

After a firewall is associated with Strata Cloud Manager (SCM), which two additional actions are required to enable management of the firewall from SCM? (Choose two.)

A.

Deploy a service connection for each branch site and connect with SCM.

B.

Configure NTP and DNS servers for the firewall.

C.

Configure a Security policy allowing “stratacloudmanager.paloaltonetworks.com” for all users.

D.

Install a device certificate.

Full Access
Question # 17

Which action optimizes user experience across a segmented network architecture and implements the most effective method to maintain secure connectivity between branch and campus locations?

A.

Establish site-to-site tunnels on each branch and campus firewall and have individual VLANs for each department.

B.

Configure all branch and campus firewalls to use a single shared broadcast domain.

C.

Implement SD-WAN to route all traffic based on network performance metrics and use zone protection profiles.

D.

Configure a single campus firewall to handle the routing of all branch traffic.

Full Access
Question # 18

An administrator wants to optimize the attack surface and check if configurations comply with CIS standards. Where in SCM can this function be accessed?

A.

BPA

B.

Command Center

C.

Policy Optimizer

D.

Executive Summary

Full Access
Question # 19

Where is the menu to configure quarantined devices in SCM?

A.

Quarantine Devices

B.

Quarantined Device List

C.

Security Events

D.

Device Groups

Full Access
Question # 20

A cloud security architect is designing a certificate management strategy for Strata Cloud Manager (SCM) across hybrid environments. Which practice ensures optimal security with low management overhead?

A.

Deploy centralized certificate automation with standardized protocols and continuous monitoring.

B.

Implement separate certificate authorities with independent validation rules for each cloud environment.

C.

Configure manual certificate deployment with quarterly reviews and environment-specific security protocols.

D.

Use cloud provider default certificates with scheduled synchronization and localized renewal processes.

Full Access
Question # 21

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

A.

Cloud Identity Engine

B.

Autonomous Digital Experience Manager (ADEM)

C.

GlobalProtect agent

D.

IPSec termination node

Full Access