
Palo Alto NetworksCertified Network Security Analyst
Domain 2Objective 1
2.1 Create and Apply Security Policies (i.e., App-ID, User-ID, Content-ID) NETWORK-SECURITY-ANALYST Practice Questions (Page 3)
Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.
14questions here
3free pages
6concepts
30%of the exam
Questions 11–14
- 11
In a security policy rule, which match criterion would you use to restrict access to a specific application to only the members of the 'Engineering' group?
Select an answer first - 12
A company has a security policy rule that blocks all traffic to a specific IP address (rule 1). They want to allow a specific application to that IP address (rule 2). The administrator adds rule 2 after rule 1. The application traffic is still blocked. What should the administrator do?
Select an answer first - 13
Which security policy profile is used to enforce URL filtering based on categories such as 'social-networking' or 'malware'?
Select an answer first - 14
A company has a security policy that allows all users to access the internet, but they want to block access to a specific application for users in the 'HR' group. User-ID is integrated with Active Directory. The administrator creates a rule that blocks the application for the 'HR' group and places it above the allow rule. However, some HR users can still access the application. What is the most likely reason?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NETWORK-SECURITY-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.