Palo Alto Networks NetSec-Analyst - Palo Alto Networks Certified Network Security Analyst Exam
Page: 3 / 12
Total 58 questions
Question #11 (Topic: Exam A)
A new firewall has been added to Panorama After entering the firewall serial number and configuring the Panorama IP address on the firewall the device still appears as "disconnected" under Panorama Managed Devices.
Given that both Panorama and the firewall are on the same subnet, what are two causes for this behavior? (Choose two.)
Given that both Panorama and the firewall are on the same subnet, what are two causes for this behavior? (Choose two.)
A. Panorama policy and objects are disabled in the firewall under Panorama settings.
B. The firewall does not have a management profile to allow the Panorama IP address.
C. Panorama IP is not allowed in the firewall management interface permitted IP list.
D. Panorama is running on a PAN-OS version lower than the firewall.
Answer: CD
Question #12 (Topic: Exam A)
Strata Logging Service is experiencing an issue with log retention because the quota has been filled. While the manager works with Palo Alto Networks to potentially increase the quota, an administrator is asked to ensure certain logs are given priority to meet compliance requirements, as the company has not approved increased budgets.
Which steps should the administrator take to meet compliance without incurring additional cost?
Which steps should the administrator take to meet compliance without incurring additional cost?
A. Make a custom report in Strata Cloud Manager (SCM) for the needed areas then clear the Strata Log Service logs used in the report after the report is made.
B. Download all logs to ensure they are retained then clear the Strata Logging Service tenant so new logs can flow again.
C. Create a new AWS account and S3 bucket, then create a Log Forwarding profile that sends all logs to the S3 bucket.
D. Gather the information on the log types used for compliance reporting, then reallocate appropriate quota percentages in the configure page.
Answer: D
Question #13 (Topic: Exam A)
A company uses a load balancer with a single public IP address to distribute inbound traffic to multiple internal servers running a custom application on the non-standard port 8443.
For example, traffic destined to the load balancer IP address 203.0.113.50:8443 needs to be forwarded to 10.20.30.40:9443. The load balancer directs traffic to internal hosts based on the destination port. The company requires the NAT policy to support precise port translation to ensure proper server load balancing and application availability.
Which Destination NAT configuration should be implemented?
For example, traffic destined to the load balancer IP address 203.0.113.50:8443 needs to be forwarded to 10.20.30.40:9443. The load balancer directs traffic to internal hosts based on the destination port. The company requires the NAT policy to support precise port translation to ensure proper server load balancing and application availability.
Which Destination NAT configuration should be implemented?
A. Configure a static NAT rule with source translation enabled to translate the public and private IP addresses, leaving port translation unchanged.
B. Configure a static NAT rule that maps the public IP address and port 8443 to the corresponding internal IP address and port 9443.
C. Configure a No NAT rule, because the load balancer dynamically handles the port 8443 to 9443 translation.
D. Configure Dynamic IP and Port (DIPP) NAT rule to automatically handle port translation, and translate the destination IP address.
Answer: B
Question #14 (Topic: Exam A)
Which set of actions will allow an administrator to handle traffic redirection most efficiently when degradation occurs on a specific SaaS application that has an on-premises backup?
A. Use Advanced Routing Engine to create a logical router with BGP, then set up a new AS routing environment. Peer the AS to the SaaS company's AS and redistribute routes from the SaaS company's AS with BGP Filtering profile for the application-specific traffic.
B. Use VPN tunneling to create tunnels between the branches and the SaaS application provider with a backup tunnel pointing to the on-premises backup. Use OSPF to determine the shortest path to reach the application which will reconverge when there is a failure.
C. Use Policy-Based Forwarding (PBF) to create a rule that sends sessions for the SaaS application to the on-premises backup, then create a path monitor with "wait-recover" selected. Ensure that "enforce symmetric return" is enabled for the rule so failures do not create routing loops.
D. Use Advanced SD-WAN to create SaaS Quality profiles and Path Quality profiles with appropriate SLA levels, then create a Traffic Distribution profile set for "top down" with a DIA interface first and the SD-WAN path that leads to on-premises backup second. Use these in an SD-WAN rule.
Answer: D
Question #15 (Topic: Exam A)
Which two actions can be taken by a Data Filtering profile when sensitive data is detected? (Choose two.)
A. Block
B. Encrypt
C. Alert
D. Captive Portal
Answer: AC