NetSec-Analyst Sample Questions & Answers
Focuses equally on building security, decryption and NAT policies and on creating external dynamic lists alongside decryption and security profiles, then covers centralized management, remediating incidents and alerts, and troubleshooting commit and runtime errors.
Launch the full NetSec-Analyst simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Object Configuration Creation and Application · Custom objects
You are configuring a custom URL category to control access to a partner portal. The requirement is to match
partner.example.comand all its subdomains (e.g.,portal.partner.example.com), but specifically EXCLUDEtest.partner.example.comfrom this category. Which pattern configuration correctly achieves this?Show answer & explanation
Correct answer: D
Custom URL categories do not support 'exclude' logic directly within the object definition itself in a single line. The standard approach is to define the broad match (
partner.example.comand*.partner.example.com) in the custom category. The exclusion is handled operationally by placingtest.partner.example.comin a separate category (or relying on its default categorization) and ensuring the policy logic or category match preference handles it appropriately. However, strictly speaking about the object definition, you define what IS included. To 'exclude' effectively in policy, you often need a specific allow/block rule for the specific subdomain before the wildcard rule. - Question 2Intermediate
Object Configuration Creation and Application · Log Forwarding profile
A retail company uses a centralized SIEM for security monitoring. They want to forward 'Threat' logs from their Palo Alto Networks firewalls to the SIEM but only if the severity is 'High' or 'Critical'. 'Informational' threat logs should be stored locally on the firewall only. How should the Log Forwarding Profile be configured?
Show answer & explanation
Correct answer: D
Log Forwarding Profiles allow granular filtering using the filter builder. By creating a match list specifically for the 'Threat' log type and applying a filter for specific severities, only those matching logs are sent to the configured forwarding destination (Syslog).
- Question 3IntermediateSelect 2
Object Configuration Creation and Application · SD-WAN profiles and templates
Which TWO of the following are valid components when configuring an SD-WAN Path Quality Profile to define acceptable performance thresholds for business-critical applications? (Select TWO)
Show answer & explanation
Correct answers: C, D
Path Quality Profiles use metrics like Latency, Jitter, and Packet Loss to determine if a path meets the SLA requirements for an application.
Jitter is a key metric in SD-WAN Path Quality profiles.
- Question 4Beginner
Object Configuration Creation and Application · Security profiles and security profile groups
True or False: A WildFire Analysis Profile must be explicitly configured to block files. Without this configuration, the profile only submits files for analysis but does not prevent the transfer of known malware.
Show answer & explanation
Correct answer: B
False. The WildFire Analysis Profile is primarily for submission rules (what gets sent to the cloud). The actual blocking of known malware discovered by WildFire is handled by the Antivirus Profile. The Antivirus profile uses the signatures generated by WildFire to block content. The WildFire profile itself configures forwarding criteria.
- Question 5Intermediate
Object Configuration Creation and Application · IoT security profiles
A manufacturing plant uses unmanaged legacy devices that cannot run endpoint agents. The security team wants to apply strict policies to these devices based on their device type (e.g., 'MRI Machine' vs 'HVAC Controller'). Which object configuration enables this capability?
Show answer & explanation
Correct answer: B
Device-ID uses machine learning from the IoT Security subscription to classify devices by type, vendor, and model. These classifications can be used as source criteria in security policies, allowing granular control over unmanaged devices without agents.
- Question 6Advanced
Object Configuration Creation and Application · DoS protection profiles
You are creating a DoS Protection Profile. You want to protect a specific critical database server (10.10.10.50) from SYN flood attacks while ensuring that legitimate traffic peaks are not dropped. You need to apply limits specifically to this single IP address. Which DoS protection type should you choose?
Show answer & explanation
Correct answer: A
Classified DoS protection applies thresholds to each individual IP address matched by the policy (source or destination). This is ideal for protecting specific servers where you want to limit the rate directed at that specific host. Aggregate protection would apply the limit to the sum of all traffic matching the rule, which isn't precise enough for a single-host protection requirement.
Ready for the real thing?
The full NetSec-Analyst simulator has every exam-style question, timed mode, and instant scoring.