Exit demo PAN-NSA Palo Alto Networks Network Security Analyst PDF format · free preview

Palo Alto Networks PAN-NSA - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pan-nsa.html

Question 1
Single choice

A security analyst is using the Strata Cloud Manager (SCM) Policy Optimizer to create specific and focused rules. The analyst accepts the new rules from Policy Optimizer and updates the rule base, but the traffic does not hit these new rules.

Which action needs to be taken to resolve this issue?

A.

Execute a push configuration

B.

Remove the original Security policy rule

C.

Enable the newly created Security policy rules

D.

Perform a commit

Question 2
Single choice

A company wants to ensure that all internal users are prevented from uploading sensitive documents to a
specific personal cloud storage site.

Which Security profile is specifically designed to inspect the content of file transfers for specific data patterns?

A.

File Blocking Profile

B.

Vulnerability Protection Profile

C.

Data Filtering Profile

D.

WildFire Analysis Profile

Question 3
Single choice

Which SCM feature allows an administrator to see a "Safety Score" for a proposed policy change before it is committed to the firewalls?

A.

Policy Optimizer

B.

Activity Insights

C.

Best Practice Assessment (BPA)

D.

Strata Cloud Manager (SCM) Copilot

Question 4
Single choice

There are intermittent connectivity issues between two internal zones on a PA-Series firewall. Although the Security policies appear correctly configured, traffic between the zones is experiencing unexpected drops.

Which troubleshooting step will isolate the root cause of this behavior?

A.

Use the CLI command tcpdump filter and set the source and destination zones in the filter to capture and analyze traffic flows between zones, checking for packet loss on the data plane.

B.

Use the CLI command show system info to monitor CPU and memory usage, ensuring that resource constraints are not causing interfaces to drop packets between zones.

C.

Use the PAN-OS GUI Troubleshooting tool to review interface status, verify zone assignments, and confirm that all links are operational.

D.

Use the CLI command show system state filter sys.sl.* | match Error to find interface errors across all
the interfaces.

Question 5
Single choice

A user reports that they are being blocked from a website with a "Certificate Error."

Which log will help the analyst determine if the firewall is blocking the session because the web server is using an expired certificate?

A.

Traffic Log

B.

Threat Log

C.

Decryption Log

D.

System Log

Question 6
Single choice

What is the most granular method for ensuring that traffic to a firewall's public IP address on the public interface is translated to the private IP address of the web server?

A.

Create one NAT policy, ensure the policy has original packet destination IP as the public IP address and translated packet destination IP as the private IP address, and mark Bi-directional as "Yes."

B.

Create one NAT policy, set the source address to the public IP address and destination address to the private IP address, and ensure Bi-directional is checked.

C.

Create two static NAT policies, ensure one policy has original packet destination IP as the public IP address and translated packet destination IP as the private IP address, ensure the other policy has original packet source IP as the private IP address and the translated packet source IP as the public IP address.

D.

Create one NAT policy, ensure the policy has original packet source IP as the private IP address and the translated packet source IP as the public IP address, and mark Bi-directional as "Yes."

Question 7
Single choice

An analyst notices an unusual amount of bandwidth being consumed by "web-browsing" traffic.

Which ACC tab provides a breakdown of which specific URLs and URL Categories are responsible for this bandwidth usage?

A.

Network Activity

B.

Threat Activity

C.

Blocked Activity

D.

SSL Activity

Question 8
Single choice

A user reports that a specific business application is dropping connection every few minutes. The analyst wants to see if the firewall's session table is reaching its limit for that specific user.

Which tool should the analyst use?

A.

ACC (Application Command Center)

B.

Session Browser

C.

Rule Usage Filter

D.

Policy Optimizer

Question 9
Single choice

DNS rewrite can only be configured on a NAT rule with which type of destination address translation?

A.

Dynamic IP and Port (DIPP)

B.

Dynamic IP (with session distribution)

C.

Static IP

D.

Dynamic IP

Question 10
Single choice

A user reports that they can reach a website, but the page elements are not loading correctly. The analyst suspects that a security profile is silently dropping some of the web content.

Which log, when filtered by the user's IP, will show the specific Content-ID match that is causing the partial page failure?

A.

Traffic Log

B.

Threat Log

C.

URL Filtering Log

D.

Data Filtering Log

Showing 10 of 96 questions · Unlock the full set