Exit demo PAN-NSP Palo Alto Networks Network Security Professional PDF format · free preview

Palo Alto Networks PAN-NSP - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pan-nsp.html

Question 1
Single choice

Which NGFW function can be used to enhance visibility, protect, block, and log the use of Post-quantum Cryptography (PQC)?

A.

DNS Security profile

B.

Decryption policy

C.

Security policy

D.

Decryption profile

Question 2
Single choice

When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?

A.

Configure port-based policies, check threat logs weekly, conduct software updates annually, and enable decryption.

B.

Configure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles to rules, and update regularly with dynamic updates.

C.

Configure all default policies provided by the firewall, use Policy Optimizer, and adjust security rules after an incident occurs.

D.

Configure a block policy for all malicious inbound traffic, configure an allow policy for all outbound traffic, and update regularly with dynamic updates.

Question 3
Single choice

How are policies evaluated in the AWS management console when creating a Security policy for a Cloud NGFW?

A.

The administrator sets a rule order to determine the order in which they are evaluated.

B.

They can be dragged up or down the stack as they are evaluated.

C.

The administrator sets a rule priority to determine the order in which they are evaluated.

D.

They must be created in the order they are intended to be evaluated.

Question 4
Single choice

Which procedure is most effective for maintaining continuity and security during a Prisma Access data plane software upgrade?

A.

Back up configurations, schedule upgrades during off-peak hours, and use a phased approach rather than attempting a network-wide rollout.

B.

Use Strata Cloud Manager (SCM) to perform dynamic upgrades automatically and simultaneously across all locations at once to ensure network-wide uniformity.

C.

Disable all security features during the upgrade to prevent conflicts and re-enable them after completion to ensure a smooth rollout process.

D.

Perform the upgrade during peak business hours, quickly address any user-reported issues, and
ensure immediate troubleshooting post-rollout.

Question 5
Single choice

Using Prisma Access, which solution provides the most security coverage of network protocols for the mobile workforce?

A.

Explicit proxy

B.

Client-based VPN

C.

Enterprise browser

D.

Clientless VPN

Question 6
Single choice

Which step is necessary to ensure an organization is using the inline cloud analysis features in its Advanced Threat Prevention subscription?

A.

Disable anti-spyware to avoid performance impacts and rely solely on external threat intelligence.

B.

Enable SSL decryption in Security policies to inspect and analyze encrypted traffic for threats.

C.

Update or create a new anti-spyware security profile and enable the appropriate local deep learning models.

D.

Configure Advanced Threat Prevention profiles with default settings and only focus on high-risk traffic to avoid affecting network performance.

Question 7
Single choice

Which method in the WildFire analysis report detonates unknown submissions to provide visibility into real-world effects and behavior?

A.

Dynamic analysis

B.

Static analysis

C.

Intelligent Run-time Memory Analysis

D.

Machine learning (ML)

Question 8
Single choice

Which set of practices should be implemented with Cloud Access Security Broker (CASB) to ensure robust data encryption and protect sensitive information in SaaS applications?

A.

Do not enable encryption for data-at-rest to improve performance.

B.

Use default encryption keys provided by the SaaS provider.

C.

Perform annual encryption key rotations.

D.

Enable encryption for data-at-rest and in transit, regularly update encryption keys, and use strong encryption algorithms.

Question 9
Single choice

Which zone is available for use in Prisma Access?

A.

Clientless VPN

B.

Interzone

C.

Intrazone

D.

DMZ

Question 10
Single choice

How can a firewall administrator block a list of 300 unique URLs in the most time-efficient manner?

A.

Use application filters to block the App-IDs.

B.

Use application groups to block the App-IDs.

C.

Import the list into a custom URL category.

D.

Block multiple predefined URL categories.

Showing 10 of 75 questions · Unlock the full set