
Palo Alto NetworksCertified Network Security Analyst
Domain 2Objective 1
2.1 Create and Apply Security Policies (i.e., App-ID, User-ID, Content-ID) NETWORK-SECURITY-ANALYST Practice Questions (Page 1)
Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.
14questions here
3free pages
6concepts
30%of the exam
Questions 1–5
- 1
An organization wants to enforce different security policies for different employees based on their Active Directory usernames. Which Palo Alto Networks feature enables the firewall to map IP addresses to usernames?
Select an answer first - 2
Which Palo Alto Networks tool allows an administrator to test a security policy rule against a simulated traffic flow to see if it would match?
Select an answer first - 3
In a Palo Alto Networks security policy rule, which element is used to match traffic based on the application being used, such as 'facebook-base' or 'web-browsing'?
Select an answer first - 4
A company's security team wants to allow employees to use a specific business application that runs on TCP port 443, but they want to block all other web traffic. The application is not in the default App-ID database. What should the administrator do to ensure the policy correctly identifies and allows only this application?
Select an answer first - 5
A security administrator wants to create a policy that allows only web browsing traffic while blocking other traffic that may use the same port. Which technology identifies the application regardless of the port used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.