
Palo Alto NetworksCertified Cybersecurity Apprentice
Domain 3Objective 2
3.2 Explain the Function of Stateful Firewalls and Next-Generation Firewalls (NGFWs) CYBERSECURITY-APPRENTICE Practice Questions (Page 5)
Part of the Network Security domain, which accounts for 14% of the CYBERSECURITY-APPRENTICE exam.
32questions here
7free pages
8concepts
14%of the exam
Questions 21–25
- 21
A company is using a stateless firewall to protect its network. An attacker is sending packets with spoofed source IP addresses to bypass the firewall's rules. Why is the stateless firewall vulnerable to this type of attack?
Select an answer first - 22
A user on an internal network initiates a web request to an external server. How does the state table enable the response to be allowed back into the network?
Select an answer first - 23
A security team wants to deploy a firewall that can not only filter traffic but also detect and block known malware and exploit attempts in real time. Which feature of an NGFW is most relevant to this requirement?
Select an answer first - 24
What is the primary purpose of signature-based intrusion prevention in an NGFW?
Select an answer first - 25
A company wants to enforce different internet access policies for different departments. For example, the marketing department should have access to social media, but the finance department should not. Employees use dynamic IP addresses from a DHCP server. How can an NGFW enforce these policies?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-APPRENTICE” is a trademark of its owner, used for identification only.