
Palo Alto NetworksCertified Network Security Professional
Domain 2Objective 1
2.1 Explain the Function of Cloud NGFWs, PA-Series, CN-Series, and VM-Series Firewalls (e.g., Perimeter and Core Security, Zone Security and Segmentation, High Availability [HA], Security and NAT Policy Implementation, Monitoring and Logging) NETWORK-SECURITY-PROFESSIONAL Practice Questions (Page 6)
Part of the NGFW and SASE Solution Functionality domain, which accounts for 13% of the NETWORK-SECURITY-PROFESSIONAL exam.
35questions here
7free pages
10concepts
13%of the exam
Questions 26–30
- 26
In an HA pair, what is the role of the passive firewall?
Select an answer first - 27
A DevOps team runs a microservices application on Amazon EKS. They need to enforce security policies between pods in different namespaces and inspect traffic between services. The solution must be managed as part of the Kubernetes infrastructure and support Kubernetes-native policy definitions. Which firewall type is most appropriate?
Select an answer first - 28
What is a best practice for creating security policies?
Select an answer first - 29
What is a common method for integrating firewall logs with a central management or SIEM system?
Select an answer first - 30
An organization wants to deploy a firewall at the edge of its network to protect against external threats. The firewall must be able to inspect all inbound and outbound traffic, block known malware, and prevent intrusion attempts. Which firewall type and feature set should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.