netsec-generalist Sample Questions & Answers
Most of the questions target maintaining and configuring firewalls, Prisma SD-WAN and Prisma Access, the single biggest weight, plus how NGFW and SASE products function, AIOps and platform security services, application layer inspection, and remote connectivity.
Launch the full netsec-generalist simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
NGFW and SASE Solution Functionality · 2.4.1 Panorama
A large enterprise manages over 500 firewalls globally using Panorama. A junior administrator is tasked with creating a new Security policy rule to block a newly identified malicious application. To ensure the rule is applied globally and consistently, what is the best practice for deploying this rule using Panorama?
Show answer & explanation
Correct answer: C
Panorama uses a hierarchical structure for policies with Pre-rules, Local rules, and Post-rules. Pre-rules are evaluated first and are inherited by all lower-level device groups. To enforce a global blocking rule that cannot be overridden by local administrators, the best practice is to place it in the Pre-rules of the top-level device group. This ensures it is applied consistently across all 500 firewalls and takes precedence over any more specific, local rules.
- Question 2Intermediate
Platform Solutions, Services, and Tools · 3.2.2 Enterprise Data Loss Prevention (DLP)
True or False: When configuring Enterprise DLP, a data pattern for 'Credit Card Numbers' is applied to a Security policy rule. This configuration, by itself, is sufficient to both detect and block the exfiltration of credit card numbers in web traffic.
Show answer & explanation
Correct answer: B
This statement is false. Enterprise DLP requires a multi-step configuration. First, you define a Data Pattern (e.g., for credit card numbers). Second, you add this pattern to a Data Filtering Profile and set the action to 'block'. Finally, this Data Filtering Profile must be attached to the relevant Security policy rule. Simply having the data pattern defined and attached to a rule without the profile and action is insufficient to block exfiltration.
- Question 3Intermediate
Platform Solutions, Services, and Tools · 3.2.1 Internet of things (IoT) security
A hospital has implemented Palo Alto Networks IoT Security to protect its medical devices. The security team receives an alert for a device identified as an 'Infusion Pump' that is attempting to connect to an external IP address using SSH. This behavior violates the hospital's security policy. Based on IoT Security best practices, what is the most effective and least disruptive way to prevent this specific activity while allowing the pump to perform its normal functions?
Show answer & explanation
Correct answer: D
Palo Alto Networks IoT Security learns the normal behavior of devices and can automatically generate security policy recommendations based on this baseline. This feature creates highly specific rules using Device-ID, App-ID, and known destinations. By importing and applying this recommended policy, the administrator can create a rule that allows only the legitimate, expected traffic for the 'Infusion Pump' device profile and implicitly denies all other traffic, such as the anomalous SSH connection, without disrupting its core medical functions.
- Question 4Beginner
Platform Solutions, Services, and Tools · 3.2.6 Advanced WildFire
A security analyst is reviewing the Threat logs and notices that a PDF file downloaded by a user was assigned a 'malicious' verdict by Advanced WildFire. The firewall configuration includes a Security policy rule with a WildFire Analysis profile set to 'alert' for all file types. The user's machine is now showing signs of compromise. To prevent this from happening in the future, what is the most critical configuration change?
Show answer & explanation
Correct answer: B
The WildFire Analysis profile determines which files get sent to the sandbox for analysis, but it does not block files based on verdicts. The blocking action is handled by other security profiles. When WildFire identifies a file as malicious, it generates a new signature and categorizes it under the 'wildfire-virus' subtype. To proactively block future downloads of this and other WildFire-identified malware, the Antivirus profile must be configured to block (e.g., 'reset-both') this specific subtype. This ensures that once a verdict is known, subsequent attempts to download the same file are immediately blocked.
- Question 5Intermediate
Platform Solutions, Services, and Tools · 3.3.3 Best Practice Assessment (BPA)
The Best Practice Assessment (BPA) tool has been run against a firewall configuration. The report indicates a 60% adoption rate for 'Content-ID Best Practices' and flags several Security policy rules that use service objects (e.g., 'service-http') instead of App-ID. What is the primary security risk associated with this configuration?
Show answer & explanation
Correct answer: C
The core advantage of App-ID over port-based rules is its ability to identify the true application regardless of the port it uses. When a rule is configured with a service object like 'service-http' (port 80), it allows any application to use that port. This creates a significant security gap, as malicious or unwanted applications (e.g., peer-to-peer file sharing, remote access tools) can tunnel their traffic over port 80 to bypass security controls. Using App-ID ensures that only the intended application (e.g., 'web-browsing') is allowed, effectively closing this gap.
- Question 6Intermediate
NGFW and SASE Solution Maintenance and Configuration · 4.1.4 Upgrades
A network administrator needs to perform a PAN-OS upgrade on a standalone PA-820 firewall. According to Palo Alto Networks' recommended procedure, what is the correct sequence of steps to minimize downtime and risk?
Show answer & explanation
Correct answer: C
The correct and safest procedure is to first back up the current state by exporting the configuration. Then, the new PAN-OS version is downloaded and installed (this does not activate it). The firewall is then rebooted to load the new version. After the reboot, it is critical to verify that the firewall is operating as expected. Only after confirming operational status should the latest content versions (like Applications and Threats) be downloaded and installed to ensure compatibility with the new OS.
- Question 7IntermediateSelect 2
NGFW and SASE Solution Maintenance and Configuration · 4.2.1 Initial ION setup
A new branch office is being set up with a Prisma SD-WAN ION 3000 device. The network team wants to use Zero Touch Provisioning (ZTP) to bring the device online with minimal manual intervention at the site. What are the essential prerequisites for ZTP to function correctly? (Select TWO)
Show answer & explanation
Correct answers: C, D
Zero Touch Provisioning is designed to automate the initial setup. For it to work, the administrator must first 'claim' the device in the cloud-based Prisma SD-WAN portal using its serial number and assign it to a pre-configured site. At the physical site, the only requirements are to plug in power and connect a WAN port to an internet link that provides an IP address via DHCP. The device will then automatically connect to the portal, authenticate itself, and download its full configuration.
- Question 8Advanced
NGFW and SASE Solution Maintenance and Configuration · 4.3.1 Security policies
A company is using Prisma Access for its remote workforce. The security team wants to ensure that if the connection between a user's endpoint and Prisma Access is temporarily lost, the endpoint remains secure and cannot access unauthorized local network resources. Which GlobalProtect feature should be configured to enforce this?
Show answer & explanation
Correct answer: C
The 'Enforce GlobalProtect Connection for Network Access' feature is specifically designed for this purpose. When enabled in the GlobalProtect agent settings, it ensures that if the VPN tunnel to Prisma Access is disconnected for any reason, all network traffic on the endpoint is blocked (with exceptions for captive portal detection, etc.). This prevents the device from falling back to an unprotected state on a local network (e.g., at a coffee shop or hotel) and maintains the intended security posture.
- Question 9Intermediate
Infrastructure Management and CDSS · 5.4.4 Configuration management
An administrator is managing a firewall through Strata Cloud Manager (SCM). They need to add a new custom URL category to be used in a security policy. Where in the SCM interface should this object be created to ensure it can be used across multiple managed firewalls?
Show answer & explanation
Correct answer: D
Strata Cloud Manager (and Panorama) uses a hierarchical folder structure for managing configurations. To create an object like a custom URL category that can be reused and inherited by multiple devices, it should be created in the 'Objects' tab at the appropriate folder level (e.g., a shared or global folder). Objects created here are available to any security policy within that folder and its sub-folders, promoting consistency and reusability.
- Question 10Intermediate
Connectivity and Security · 6.1.1 Network segmentation
A university provides a public Wi-Fi network for students and a separate, secure network for faculty. The security team wants to prevent students from accessing faculty resources while allowing both groups to access the internet through a single Palo Alto Networks firewall. The student devices are on the 10.10.0.0/16 subnet, and faculty devices are on 10.20.0.0/16. What is the most effective design to achieve this segmentation?
Show answer & explanation
Correct answer: A
The fundamental method for network segmentation on a Palo Alto Networks firewall is the use of security zones. By assigning the student network interface to a 'Students' zone and the faculty network interface to a 'Faculty' zone, the firewall's default intra-zone allow and inter-zone deny posture can be leveraged. A security policy would be required to explicitly allow traffic from the 'Students' zone to the 'Faculty' zone. By not creating such a policy, traffic between them is implicitly denied, achieving the required segmentation. Separate policies can then be created to allow each zone to access the 'Internet' zone.
Ready for the real thing?
The full netsec-generalist simulator has every exam-style question, timed mode, and instant scoring.