Sign In
Home/Palo Alto/Palo Alto Networks Certified Network Security Analyst/Free questions

Palo Alto Networks Certified Network Security Analyst — Free Practice Questions

10 free sample questions from a bank of 61, with the correct answers and explanations. No signup required — start practising right now.

1A security administrator is creating an internet of things (IoT) Security policy and needs to select behaviors for the trafficю Which characteristic has the greatest impact to the risk level of applications?
Palo Alto Networks Certified Network Security Analyst question 1
  • Used by Malware
  • Pervasive
  • Tunnels Other Apps
  • Known Vulnerabilities
Answer: A

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:In the Palo Alto Networks ecosystem, App-ID utilizes specific characteristics to help administrators assess the risk profile of applications traversing the network. These characteristics—which include whether an application is evasive, prone to misuse, or capable of file transfer—are aggregated into a numerical Risk Score ranging from 1 (lowest risk) to 5 (highest risk).Among the listed characteristics, "Used by Malware" (A) typically has the greatest immediate impact on the assigned risk level. This characteristic indicates that the application is a known vector for Command and Control (C2) traffic, data exfiltration, or payload delivery, necessitating a high risk rating (often 4 or 5). While "Known Vulnerabilities" (D) and "Tunnels Other Apps" (C) certainly increase the risk level by providing an exploit surface or obscuring visibility, they represent potential risks. In contrast, an application being actively "Used by Malware" represents a direct and validated threat to the environment."Pervasive" (B) refers to how common an application is and generally does not drive a high-risk score on its own. For an analyst building an IoT Security policy, prioritizing applications with the "Used by Malware" characteristic is critical, as many IoT devices lack robust internal security and are frequently recruited into botnets via these specific communication channels.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks NetSec-Analyst View All Questions

Paloalto Networks NetSec-Analyst Summary

Vendor: Paloalto Networks

Product: NetSec-Analyst

Update on: Sep 3, 2026

Questions: 74

Price: $52.5  $149.99

A financial company is deploying NGFWs with the Advanced SD-WAN subscription to improve uptime and...

Previous

2DNS rewrite can only be configured on a NAT rule with which type of destination address translation?
  • Dynamic IP and Port (DIPP)
  • Dynamic IP (with session distribution)
  • Static IP
  • Dynamic IP
Answer: C

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:In Palo Alto Networks PAN-OS, the DNS rewrite feature (often referred to as DNS Doctoring) is specifically designed to solve the issue of split-horizon DNS in environments where internal users must access an internal server using its public IP address. This occurs when the DNS server returns the public IP address of a server to an internal client, but the client and server are on the same or related internal networks.The firewall can only perform a DNS rewrite when a Static IP destination NAT rule is in place. When this option is enabled, the firewall monitors DNS responses passing through it. If a DNS response contains an IP address that matches the "Original Destination" IP in a static NAT rule, the firewall rewrites the DNS payload to the "Translated Destination" IP (the private IP of the server).This functionality is restricted to Static IP translation because it requires a 1-to-1, predictable mapping between the public and private addresses. Dynamic translation types (A, B, and D) involve pools of addresses or port-overloading, which makes it impossible for the firewall to determine which specific internal IP address should be written into the DNS response at any given time. By ensuring a static mapping, the Network Security Analyst guarantees that internal clients receive the correct internal IP address to reach their destination without hair-pinning traffic unnecessarily through the public interface.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks NetSec-Analyst View All Questions

Paloalto Networks NetSec-Analyst Summary

Vendor: Paloalto Networks

Product: NetSec-Analyst

Update on: Sep 3, 2026

Questions: 74

Price: $52.5  $149.99

Next

An analyst determines that several sanctioned, predefined app

3Based on the image below, what is a risk associated with this configuration?
Palo Alto Networks Certified Network Security Analyst question 3
  • Min Version setting of TLSvl 3 can cause compatibility issues with legacy applications or clients.
  • Authentication algorithm selections can significantly increase resource consumption and cause performance degradation.
  • Encryption algorithms 3DES and RC4 being disabled decreases security posture.
  • Max Version setting of "Max" enables the use of Perfect Forward Secrecy (PFS) and cannot be decrypted.
Answer: A

The short version

A — Requiring TLSv1.3 minimum breaks legacy clients. Raising Min Version improves security but drops older applications that only negotiate TLS 1.0-1.2.

Key concepts in this question

  • Decryption / SSL-TLS profile: Min and Max Version controls bound the handshake versions the firewall will negotiate.
  • TLS 1.3 enforcement: modern-only ciphers and handshake, unsupported by many legacy stacks.
  • Compatibility risk: stronger minimums trade interoperability for posture.

Why A is correct

The referenced profile sets the minimum to TLSv1.3, so any client or server that cannot offer TLS 1.3 will fail the handshake and lose connectivity. In enterprise environments with legacy applications, embedded devices, or old libraries, this causes outages even though security improves. That compatibility impact is the principal risk of a TLSv1.3-minimum setting. Authentication and encryption selections affect CPU or strength, but they do not cause the broad version-negotiation failures described, so A best names the configuration risk from stem plus options alone.

Why the others are wrong

  • B. Authentication algorithm choice can affect load, but it is not the headline risk of a Min-Version change.
  • C. Disabling 3DES and RC4 strengthens posture by removing weak ciphers; it does not decrease security.
  • D. Max set to Max does not inherently enable undecryptable PFS; the firewall can still decrypt with proper keys and profiles.

NetSec Analyst exam tip

Min Version too high equals outage risk; Max too low equals weak crypto — read version questions for compatibility.

4Which action ensures that sensitive information such as medical records, financial transactions, and legal communications are not decrypted and that they maintain strong security?
  • Create a log forwarding filter to exclude sensitive information.
  • Disable decryption globally to avoid exposing sensitive data.
  • Create an SSL Inbound Inspection policy to identify users sending sensitive information.
  • Create a no-decrypt policy for traffic matching specific URL categories.
Answer: D

The short version

D — Use a no-decrypt rule for sensitive URL categories. Excluding finance, health, and legal traffic preserves privacy while keeping decryption elsewhere.

Key concepts in this question

  • SSL Forward Proxy: decrypts outbound traffic for inspection using a trusted CA.
  • No-decrypt policy: bypasses decryption for matched categories such as financial-services and health.
  • Selective decryption: balances visibility with regulatory and privacy obligations.

Why D is correct

Palo Alto Networks best practice is to keep broad decryption enabled but add Decryption policy rules with action No Decrypt for sensitive URL categories like financial-services, health-and-medicine, and legal. The firewall then passes medical, banking, and legal sessions without inspection while still decrypting general web traffic for threat prevention. This targeted exclusion maintains strong security overall and avoids globally disabling decryption, which would blind inspection. Log filters or inbound inspection do not control forward-proxy decryption, so D is the correct mechanism.

Why the others are wrong

  • A. Log forwarding filters only change reporting; they do not stop decryption of sensitive sessions.
  • B. Disabling decryption globally removes visibility everywhere and weakens security unacceptably.
  • C. SSL Inbound Inspection protects internal servers with their private keys, not outbound user privacy traffic.

NetSec Analyst exam tip

Privacy requirement plus decryption equals No Decrypt rule by URL category — never pick global disable.

5An alert indicates that multiple internal endpoints are communicating with a known malicious IP address, and the analyst needs to identify the scope of this activity by using Log Viewer. What is the first step in identifying which internal hosts have communicated with the malicious IP address and determining the extent of the communication?
  • Filter the traffic logs by the known endpoint IP addresses.
  • Filter the traffic logs by the DNS Server's IP address.
  • Filter the traffic logs by the NGFWs IP addresses.
  • Filter the traffic logs by the malicious IP address.
Answer: D

The short version

D — Start by filtering traffic logs on the malicious IP. That pivot immediately reveals every internal host that talked to the indicator.

Key concepts in this question

  • Traffic logs in Log Viewer: authoritative record of source, destination, application, and bytes per session.
  • Indicator pivot: starting from the known-bad IP scopes the incident fast.
  • SCM / NGFW investigation: filter first, then expand to timelines and affected hosts.

Why D is correct

The only known-good fact is the malicious destination IP, so filtering traffic logs by that destination instantly lists all internal sources, timestamps, ports, applications, and volumes. From that result set the analyst can enumerate scope, identify patient zero, and determine extent before drilling into threat, URL, or WildFire logs. Filtering by endpoint IPs assumes you already know the victims, while DNS or firewall IPs look at infrastructure rather than the adversary indicator. D is therefore the correct first scoping step.

Why the others are wrong

  • A. Filtering by endpoint IPs only works after victims are known; it cannot discover them initially.
  • B. DNS server IPs show resolver traffic, not which clients reached the malicious destination.
  • C. NGFW interface IPs show transit, not the external adversary address to scope.

NetSec Analyst exam tip

When given one bad IOC, filter logs by that IOC first, then enumerate internal sources.

6A security administrator wants to determine which action a URL Filtering profile will take on the URL "www.chatgpt.com." The firewall has a custom URL object with "www.chatgpt.com/" as a member called "Permitted-AI." The URL "www.chatgpt.com" is also categorized as "Artificial-Intelligence, " "Computer-and-Internet-Info," and "Low-Risk." The URL Filtering profile has the following in descending order: • Artificial-Intelligence set to continue • Computer-and-Internet-Info set to block • Low-Risk set to alert • Permitted-AI set to allow Which action will the URL Filtering profile take when traffic matches the "www.chatgpt.com" URL on a rule with this profile attached?
  • Continue
  • Alert
  • Allow
  • Block
Answer: C

The short version

C — Custom URL categories win, so action is Allow. Permitted-AI as a custom object outranks the listed predefined categories.

Key concepts in this question

  • Custom vs predefined URL categories: custom entries are evaluated before built-in PAN-DB categories.
  • URL Filtering profile order: within custom categories, top-down order matters, but custom still beats predefined.
  • Allow override: explicit custom Allow is designed for sanctioned exceptions.

Why C is correct

The firewall first checks custom URL objects, and www.chatgpt.com matches Permitted-AI set to Allow. Even though the same URL also carries predefined categories Artificial-Intelligence, Computer-and-Internet-Info, and Low-Risk with continue, block, and alert actions, those are only consulted if no custom match exists. Because a custom Allow match occurs, the profile takes Allow and permits the session subject to other policy. This precedence lets administrators carve out approved sites without reordering the entire predefined list.

Why the others are wrong

  • A. Continue would apply only if the top predefined match governed, but custom Allow preempts it.
  • B. Alert from Low-Risk is lower precedence than any custom match and is not reached here.
  • D. Block from Computer-and-Internet-Info is ignored once the custom category matches first.

NetSec Analyst exam tip

Custom URL Allow always beats predefined block or alert; check custom membership before reading category order.

7In an environment with SSL Forward Proxy decryption policies and applications that use certificate pinning, which configuration step is essential to prevent application failures due to strict certificate validation?
  • Increase the key length of the SSL Forward Proxy certificate to enhance security.
  • Enable SSL/TLS 1.3 to ensure compatibility with modern applications.
  • Use a wildcard certificate to bypass certificate validation issues.
  • Create SSL decryption exclusions for applications that use certificate pinning.
Answer: D

The short version

D — Exclude pinned apps from SSL Forward Proxy decryption. Certificate pinning breaks when the firewall substitutes its own certificate.

Key concepts in this question

  • SSL Forward Proxy: resigns server certificates to inspect outbound TLS.
  • Certificate pinning: app hard-codes the expected server certificate or public key.
  • Decryption exclusions: No Decrypt rules or exclusion lists preserve pinned sessions.

Why D is correct

Pinned applications validate the exact server certificate or key rather than trusting the local CA chain, so a firewall-generated certificate causes validation failure and the app breaks or refuses to connect. Increasing key length, enabling TLS 1.3, or using wildcards does not change that pin mismatch. The supported fix is to identify pinning applications and create SSL decryption exclusions or No Decrypt policy for their destinations, letting them pass with original certificates while other traffic remains inspected. D is therefore the essential preventive step.

Why the others are wrong

  • A. Longer proxy keys improve crypto strength but do not satisfy a pinned fingerprint.
  • B. TLS 1.3 support aids compatibility generally, but pinning still rejects the substituted certificate.
  • C. A wildcard firewall certificate is still not the pinned origin certificate, so validation still fails.

NetSec Analyst exam tip

If you see pinning plus decryption breakage, answer exclusions or No Decrypt — crypto upgrades never fix pins.

8When configuring SSL Inbound Inspection for a public-facing web server, what must be installed as a critical certificate management step to ensure decryption of the SSL connection?
  • Certificate generated by an internal CA server and session-specific certificates on the firewall.
  • Self-signed certificate on the firewall to protect the identity of the server.
  • Public key wildcard certificate on the firewall to decrypt all inbound traffic.
  • Web server certificate and corresponding private key on the firewall.
Answer: D

The short version

D — Import the web server certificate plus private key. Inbound inspection must terminate the original server TLS session.

Key concepts in this question

  • SSL Inbound Inspection: decrypts traffic destined to internal servers by owning their keys.
  • Private key requirement: needed to terminate and re-establish the server-side TLS session.
  • Forward vs inbound proxy: forward uses a CA; inbound uses the actual server identity.

Why D is correct

For a public-facing web server, the firewall sits in front and must present the server identity to clients and decrypt the inbound TLS. That is only possible if the true server certificate and its corresponding private key are installed on the firewall so it can complete the handshake, decrypt, inspect, and re-encrypt to the backend. An internal CA, self-signed firewall cert, or generic wildcard without the private key cannot impersonate that specific public service correctly and will cause trust or decryption failure. D states the documented critical step.

Why the others are wrong

  • A. Internal CA plus session certs describes outbound forward proxy, not inbound hosting inspection.
  • B. A self-signed firewall certificate breaks public trust and does not match the server private key.
  • C. A generic wildcard without the hosted server private key cannot decrypt that server traffic.

NetSec Analyst exam tip

Inbound equals server cert plus key on firewall; outbound equals trusted CA on firewall.

9A security administrator is building out Decryption policies and wants to decrypt according to Palo Alto Networks best practices. Which URL categories should the administrator add to the policies?
  • Proxy avoidance and anonymizers, ransomware unknown, web-based email, web advertisements, and not resolved.
  • Online storage and backup web-based email web hosting, personal sites and blogs, content delivery networks, and high-risk URL.
  • AI website generator, Command and Control, compromised website, encrypted DNS, and dynamic DNS.
  • Newly registered domains, internet communications and telephony, high-risk URL, insufficient content, hacking, and grayware.
Answer: B

The short version

B — Decrypt high-value business and high-risk web categories. Palo Alto Networks recommends decrypting exfiltration-prone storage, mail, hosting, and risky URLs.

Key concepts in this question

  • Decryption best practice: decrypt where malware and data loss hide, exclude privacy categories elsewhere.
  • URL categories for decrypt: storage, webmail, hosting, blogs, CDNs, and high-risk sites.
  • No-decrypt categories: finance, health, and government remain excluded for compliance.

Why B is correct

Option B lists the sanctioned decrypt set: online storage and backup, web-based email, web hosting, personal sites and blogs, content delivery networks, and high-risk URLs. These categories commonly tunnel file uploads, phishing payloads, and evasive content over TLS, so inspecting them yields the most security value. Palo Alto Networks guidance pairs this decrypt list with separate No Decrypt rules for sensitive categories. The other options mix block-oriented categories like C2, compromised sites, or proxy avoidance that are typically blocked rather than used as the core decrypt-include list.

Why the others are wrong

  • A. Proxy avoidance, ransomware, and not-resolved are enforcement or block candidates, not the standard decrypt-include set.
  • C. C2, compromised, encrypted-DNS, and dynamic-DNS are threat categories usually blocked, not the decrypt baseline.
  • D. Newly registered, hacking, and grayware skew toward blocking controls rather than the recommended decrypt list.

NetSec Analyst exam tip

Memorize decrypt includes as storage, mail, hosting, blogs, CDNs, high-risk; threats get blocked.

10A new firewall has been added to Panorama After entering the firewall serial number and configuring the Panorama IP address on the firewall the device still appears as "disconnected" under Panorama Managed Devices. Given that both Panorama and the firewall are on the same subnet, what are two causes for this behavior? (Choose two.)
  • Panorama policy and objects are disabled in the firewall under Panorama settings.
  • The firewall does not have a management profile to allow the Panorama IP address.
  • Panorama IP is not allowed in the firewall management interface permitted IP list.
  • Panorama is running on a PAN-OS version lower than the firewall.
Answer: C, D

The short version

C and D — Permitted IPs and PAN-OS version mismatch block onboarding. Management access control and version compatibility both prevent a connected state.

Key concepts in this question

  • Panorama device onboarding: firewall initiates SSL management connection to Panorama.
  • Permitted IP list: restricts which addresses can manage the firewall.
  • Version compatibility: Panorama must run the same or newer PAN-OS than managed firewalls.

Why C and D are correct

If the Panorama IP is missing from the firewall management interface permitted IP list, the firewall drops Panorama management sessions even on the same subnet, leaving status disconnected. Separately, Panorama cannot manage a firewall running newer PAN-OS than itself because templates, objects, and APIs differ, which also yields disconnected or incompatible status. Both conditions are independent common causes, so C and D together answer the choose-two prompt. Disabling policy deployment or missing interface profiles does not itself break the management-plane connection.

Why the others are wrong

  • A. Disabling Panorama policy and objects stops content pushes, not the initial management connection itself.
  • B. Interface management profiles control services like ping or SSH per interface, not Panorama permitted-IP onboarding access.

NetSec Analyst exam tip

Panorama stuck disconnected means check permitted IPs first, then confirm Panorama version is equal or newer.

Want the full bank of 61 questions for Palo Alto Networks Certified Network Security Analyst? See all practice exams.