
Palo Alto NetworksCertified Network Security Professional
Domain 3Objective 1
3.1 Explain the Security Efficacy of Palo Alto Networks NGFW and Prisma SASE Products (e.g., Security and NAT Policy, User-ID, App-ID, Decryption, Monitoring and Logging) NETWORK-SECURITY-PROFESSIONAL Practice Questions (Page 4)
Part of the Platform Solutions, Services, and Tools domain, which accounts for 30% of the NETWORK-SECURITY-PROFESSIONAL exam.
23questions here
5free pages
5concepts
30%of the exam
Questions 16–20
- 16
An application uses port 443 (HTTPS) but is actually a peer-to-peer file-sharing tool. How can Palo Alto Networks NGFW identify this application?
Select an answer first - 17
A security team has enabled SSL decryption on their Palo Alto Networks NGFW to inspect all outbound HTTPS traffic. They are now experiencing performance degradation and some users report that certain websites are not loading. Which action is most appropriate to address these issues while maintaining security efficacy?
Select an answer first - 18
What is the primary purpose of decryption in Palo Alto Networks NGFW?
Select an answer first - 19
Which security policy match criterion is made possible by User-ID in Palo Alto Networks NGFW?
Select an answer first - 20
A company is deploying a Palo Alto Networks NGFW and wants to ensure that all outbound web traffic is inspected for threats. They have enabled SSL decryption and created a security policy that allows HTTP and HTTPS traffic. However, they notice that some HTTPS traffic is not being inspected. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.