
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 2Objective 2
2.2 Explain the Function of Stateless Firewalls and Next-Generation Firewalls (NGFWs) CYBERSECURITY-PRACTITIONER Practice Questions (Page 4)
Part of the Network Security domain, which accounts for 19% of the CYBERSECURITY-PRACTITIONER exam.
22questions here
5free pages
4concepts
19%of the exam
Questions 16–20
- 16
Which characteristic best describes how a stateless firewall processes network traffic?
Select an answer first - 17
A network engineer is configuring a stateless firewall to allow inbound HTTPS traffic to a web server. The firewall has a rule to allow TCP port 443 from any source to the web server. However, the web server is not receiving the traffic. What is the most likely reason for this failure?
Select an answer first - 18
A company is deploying an NGFW and wants to block a specific exploit that targets a vulnerability in a web application. The exploit uses a unique string in the HTTP request. Which NGFW feature is specifically designed to detect and block this type of threat?
Select an answer first - 19
A company is using a stateless firewall to protect its internal network. The security team discovers that an attacker is using a technique where they send a packet with the RST flag set to close a legitimate TCP connection between two internal hosts. The attacker is spoofing the source IP address of one of the hosts. Why is the stateless firewall unable to prevent this attack?
Select an answer first - 20
A small ISP uses a stateless firewall to filter traffic between customers and the internet. A customer reports that their VoIP calls intermittently fail, while web browsing works fine. The firewall's rule base only contains static rules for IP addresses and port numbers. What is the most likely reason for the VoIP failures?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.