
Palo Alto NetworksCertified Network Security Analyst
Domain 3Objective 3
3.3 Use Log Viewer and the Incidents and Alerts Page to Remediate Incidents and Alerts NETWORK-SECURITY-ANALYST Practice Questions (Page 3)
Part of the Management and Operations domain, which accounts for 26% of the NETWORK-SECURITY-ANALYST exam.
29questions here
6free pages
9concepts
26%of the exam
Questions 11–15
- 11
A security team receives multiple alerts: one for a critical server attempting to connect to a known command-and-control IP, one for a low-priority user visiting a phishing site, and one for a malware signature detected on a non-critical workstation. The team has limited resources and must prioritize. Which alert should be investigated first?
Select an answer first - 12
When navigating the Log Viewer, what is the purpose of the timeline histogram displayed at the top of the page?
Select an answer first - 13
On the Incidents and Alerts page, what is the primary function of the 'Incidents' tab?
Select an answer first - 14
After blocking a malicious IP in the firewall, an analyst wants to verify that the block is effective and that no further traffic from that IP is being allowed. Which action in Log Viewer best verifies the remediation?
Select an answer first - 15
An analyst is investigating an incident and needs to view all traffic logs for a specific user's IP address. The analyst is currently on the Incidents and Alerts page. What is the most efficient way to access the relevant traffic logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.