Palo Alto Networks NetSec-Pro Exam Actual Questions
Palo Alto Networks Certified Network Security Professional (Page 3 )

Updated On: 8-Aug-2026

Which two tools can be used to configure Cloud NGFWs for AWS? (Choose two.)

  1. Prisma Cloud management console
  2. Cortex XSIAM
  3. Cloud service provider (CSP) management console
  4. Panorama

Answer(s): C,D

Explanation:

Why CD is correct
Cloud Service Provider (CSP) management console – When deploying a Palo Alto Networks Cloud NGFW in AWS, the firewall is typically launched from the AWS Marketplace or the CSP’s native console (e.g., AWS Console). This console provides the initial configuration parameters (instance size, networking, licensing) required to instantiate the firewall in the cloud environment. Panorama – Once the Cloud NGFW instance is running, Panorama can be used to centrally provision, push policies, and manage the firewall alongside other Palo Alto devices. Panorama’s API and integration with the CSP allow automated configuration, rule distribution, and lifecycle management, making it the recommended second tool for ongoing management.
Why the other options are less suitable

A: Prisma Cloud management console – Prisma Cloud focuses on CSPM (Cloud Security Posture Management), CIEM, and container security. It does not provide the capability to provision or configure Palo Alto Cloud NGFWs; it only monitors workloads and can trigger alerts. B. Cortex XSIAM – XSIAM is a security orchestration, automation, and response (SOAR) platform that ingests and correlates security data. It is used for incident response and threat analytics, not for firewall deployment or policy management.
Thus, the only tools that can be used to configure Cloud NGFWs for AWS are the CSP’s management console (for initial deployment) and Panorama (for centralized policy management).


Reference:

Palo Alto Networks – Deploy Cloud NGFW on AWS: https://docs.paloaltonetworks.com/cloud-security/cloud-ngfw/cloud-ngfw-for-aws/ Palo Alto Networks – Panorama Management of Cloud NGFW: https://docs.paloaltonetworks.com/cloud-security/panorama/panorama-cloud-admin/
These documents detail the deployment workflow via the AWS Marketplace/CSP console and the integration with Panorama for policy management.



In which two applications can Prisma Access threat logs for mobile user traffic be reviewed? (Choose two.)

  1. Prisma Cloud dashboard
  2. Strata Cloud Manager (SCM)
  3. Strata Logging Service
  4. Service connection firewall

Answer(s): B,C

Explanation:

Answer justification
Strata Cloud Manager (SCM) (Option B) – SCM aggregates logs from all managed firewalls, including threat logs generated by Prisma Access for mobile-user sessions. Through its UI you can filter, search, and visualize these logs directly, making it a primary location for review.
Strata Logging Service (Option C) – Mobile-user traffic is logged by the PAN-OS data plane and persisted in the Strata Logging Service. This centralized repository stores the raw logs, and SCM queries it for display. Because the logs reside there, it is a required backend component for any log-review activity.
Why A (Prisma Cloud dashboard) is not suitable – Prisma Cloud focuses on posture management for cloud resources (IaaS, containers, etc.) and does not ingest or surface Prisma Access threat logs for mobile users. Its visualization layer is geared toward cloud-security findings, not network threat analytics.
Why D (Service connection firewall) is not suitable – The “service connection firewall” refers to a configuration that allows the firewall to reach external services; it is not a logging or analytics UI. Threat logs are not viewed through this mechanism.
Thus, the two correct applications are Strata Cloud Manager (SCM) and Strata Logging Service , as they together provide the storage and the interactive view of Prisma Access threat logs for mobile user traffic.


Reference:

Prisma Access – Logging and Monitoring : https://docs.paloaltonetworks.com/prisma/prisma-access/10-0/prisma-access-admin/monitoring/overview.html Strata Cloud Manager – View Threat Logs : https://docs.paloaltonetworks.com/strata-cloud-manager/5-6/strata-cloud-manager-admin/log-management/overview.html



A network security engineer needs to implement segmentation but is under strict compliance requirements to place security enforcement as close as possible to the private applications hosted in Azure.
Which deployment style is valid and meets the requirements in this scenario?

  1. On a PA-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.
  2. On a VM-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logically segment the network.
  3. On a VM-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.
  4. On a PA-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logically segment the network.

Answer(s): B

Explanation:

Why option B is the only valid deployment
VM-Series support in Azure – Palo Alto VM-Series firewalls can be instantiated as virtual machines within the Azure environment, preserving the same security-policy and zone capabilities that are used on hardware PA-Series devices. Layer-3 zone model – Azure networks are fundamentally routed; traffic between subnets traverses a virtual next-hop. By assigning each subnet to a separate Layer-3 zone on the VM-Series and binding L3 interfaces to those zones, the firewall can enforce policies at the zone boundary exactly where the private application workloads reside. This places the enforcement point as close as possible to the workloads, satisfying strict compliance that requires segmentation to be “as close as possible” to the applications. Scalability & HA – VM-Series supports Azure availability sets, scale sets, and placement groups, allowing the firewall to be deployed redundantly across availability zones, which is required for high-availability compliance mandates. Feature parity – All PAN-OS security functions (App-ID, Threat Prevention, SSL Forward Decryption, etc.) are available on the VM-Series, ensuring compliance-driven inspection is not limited by platform constraints.
Why the other options do not meet the requirements
Option A – PA-Series on-premises – PA-Series firewalls are physical appliances that cannot be deployed inside Azure. They would require a site-to-site VPN or Azure ExpressRoute back-haul, placing the enforcement point outside the Azure virtual network and farther from the private applications, violating the “as close as possible” rule. Option C – VM-Series with Layer-2 zones – Azure virtual networks operate on routed (L3) semantics; creating Layer-2 zones would necessitate broadcast domains that Azure does not natively support for inter-subnet traffic. This would force the use of non-standard, unsupported topologies and would not provide the required isolation of traffic between subnets that are logically separated in Azure. Option D – PA-Series with Layer-2 zones – Like option A, a PA-Series device cannot be hosted inside Azure, and its deployment limited to Layer-2 zones would conflict with Azure’s routed networking model, again preventing placement adjacent to the private workloads.
Therefore, only Option B —deploying a VM-Series NGFW and configuring multiple Layer-3 zones with Layer-3 interfaces —provides a compliant, Azure-native segmentation solution that enforces security as near as possible to the private applications.


Reference:

Palo Alto Networks VM-Series documentation for Microsoft Azure: https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-deployment/10-2/vm-series-zones-and-interfaces.html Azure networking guide on virtual network segmentation and zones: https://learn.microsoft.com/azure/virtual-network/virtual-networks-overview.md#network-segmentation



When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, when can the firewall be powered on?

  1. During license activation
  2. After activating registration and completing license deployment profile
  3. After all required installation and setup procedures are completed
  4. During installation

Answer(s): B

Explanation:

Answer(s): B – After activating registration and completing license deployment profile
Activating the firewall’s registration in Panorama creates a valid device object that Panorama can control. Only after this registration is activated and the license deployment profile is successfully applied does Panorama possess the necessary license credentials and device identity to safely power on the ZTP firewall. Powering the device at any earlier stage would result in an unregistered, licence-less unit, leading to provisioning failures.

A: During license activation – The license must first be deployed to the firewall; merely activating the license on Panorama does not grant the firewall permission to boot. C. After all required installation and setup procedures are completed – The “all required procedures” include registration and license deployment; this wording is vague and ignores the mandatory pre-boot steps that must precede power-on. D. During installation – Installing the firewall (e.g., mounting, connecting cables) does not fulfill the software registration and license profile requirements; the device must remain off until Panorama has finished provisioning.
Thus, the firewall can be powered on only after Panorama successfully registers the device and completes the associated license deployment profile.


Reference:

Palo Alto Networks, Panorama Administrator’s Guide – Zero-Touch Provisioning: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/panorama-admin.html#z-t-p Palo Alto Networks, ZTP Configuration Guide: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zero-touch-provisioning.html



Which profile can help prevent the transmission of sensitive information to internet applications?

  1. Antivirus
  2. Data Filtering
  3. Anti-spyware
  4. URL Filtering

Answer(s): B

Explanation:

Technical justification
The Data Filtering profile is specifically designed to inspect and control application traffic based on content signatures and policy rules. By enabling data-filtering signatures, the firewall can identify sensitive data patterns (e.g., credit-card numbers, social-security numbers, internal IP addresses) and block or quarantine sessions that attempt to transmit such data to unapproved internet destinations or applications.

A: Antivirus – Focuses on malware detection and removal, not on content-level data leakage.
C: Anti-spyware – Targets spyware components and behaviors, but does not provide granular data-exfiltration controls. D. URL Filtering – Blocks or allows URLs/category based on web reputation; it does not inspect the payload for sensitive information.
Therefore, only the Data Filtering profile directly addresses the prevention of sensitive information transmission to internet applications.


Reference:

Palo Alto Networks – Data Filtering Palo Alto Networks – Data Filtering Signatures



How do template stacks help manage firewall configurations in Panorama?

  1. By grouping templates across multiple firewalls
  2. By creating template variables for permanent configurations in firewalls
  3. By creating a diagram of the network for a view of all firewalls
  4. By handling firmware updates across multiple firewalls

Answer(s): A

Explanation:

Why option A is the correct and only appropriate answer
A template stack in Panorama is a logical container that aggregates multiple templates , each of which can be assigned to one or more firewalls. By defining several templates (e.g., per-zone, per-policy, per-rule) and grouping them into a stack, an administrator can push a coherent configuration set to many firewalls simultaneously. This capability directly supports the exam-level understanding that a template stack “groups templates across multiple firewalls,” allowing centralized, consistent distribution of configuration parameters without manually editing each device. The design of Panorama’s template hierarchy (device > template > template stack) reflects exactly this concept, making option A the textbook definition used in the Palo Alto Networks certification material.
Why the other options do not fit the definition
B: Creating template variables for permanent configurations in firewalls – Template variables are used to inject dynamic values (e.g., IP addresses) into templates, but they are not the mechanism by which stacks manage configurations across devices; they are a feature of individual templates. C. Creating a diagram of the network for a view of all firewalls – Panorama does provide network visualizations, yet these are separate from template stacks and serve only for monitoring/visualization, not for configuration management. D. Handling firmware updates across multiple firewalls – Firmware (PAN-OS) upgrades are managed via software distribution or software images in Panorama, not through template stacks; firmware updates operate independent of template hierarchies.
Therefore, option A precisely captures the functional purpose of template stacks: they let administrators bundle and apply multiple templates to many firewalls in a coordinated manner.


Reference:

Palo Alto Networks Panorama Administration Guide – Template Stacks (Section 3.2) – https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/panorama-admin/supported-features/panorama-admin-guide.html Official study guide excerpt, Palo Alto Networks Certified Network Security Professional (PCNSP) – Exam Blueprint – https://www.paloaltonetworks.com/services/training/pcnsp-study-guide



Which subscription sends non-file format-based traffic that matches Data Filtering profile criteria to a cloud service to render a verdict?

  1. SaaS Security Inline
  2. Enterprise DLP
  3. Advanced URL Filtering
  4. Advanced WildFire

Answer(s): B

Explanation:

Answer – B. Enterprise DLP
How it works:
The Enterprise DLP subscription extends Data Filtering profiles to non-file-format traffic (e.g., HTTP, FTP, SMTP, WebSocket, API calls).
When a session matches the configured DLP criteria (such as credit-card numbers, social-security patterns, or custom regex), the traffic is off-loaded to the Palo Alto DLP cloud service for a deep-content verdict. The verdict (permit, block, or quarantine) is returned and the session is handled according to the policy, enabling real-time data-loss prevention without needing attachments or explicit file types.
Why the other options are not correct:
SaaS Security Inline – Inspects traffic to/from SaaS applications for malware and policy violations, but its primary focus is on SaaS-specific app controls, not on generic non-file traffic that requires DLP classification. Advanced URL Filtering – Filters URLs based on categories, reputations, or custom URL-filtering signatures; it does not analyze content patterns to enforce DLP rules or send traffic to a cloud DLP service. Advanced WildFire – Provides sandbox analysis of file-based payloads (e.g., executables, documents) to detect unknown malware; it does not handle non-file-format streams for DLP verdicts.
Key distinction: Only Enterprise DLP is explicitly designed to send any matching non-file traffic through the Cloud DLP service to generate a data-loss prevention verdict.


Reference:

Enterprise DLP Overview: https://docs.paloaltonetworks.com/palo-alto-networks/r7-2/palo-alto-networks-endpoint-security/enterprise-dlp-admin/ Data Filtering Profiles with DLP Integration: https://docs.paloaltonetworks.com/palo-alto-networks/r7-2/palo-alto-networks-firewall/administration/filters-and-profiles/data-filtering-profile/



A cloud security architect is designing a certificate management strategy for Strata Cloud Manager (SCM) across hybrid environments.
Which practice ensures optimal security with low management overhead?

  1. Implement separate certificate authorities with independent validation rules for each cloud environment.
  2. Configure manual certificate deployment with quarterly reviews and environment-specific security protocols.
  3. Use cloud provider default certificates with scheduled synchronization and localized renewal processes.
  4. Deploy centralized certificate automation with standardized protocols and continuous monitoring.

Answer(s): D

Explanation:

Why option D is the best choice
Centralized automation – A single, unified workflow automates issuance, renewal, and revocation across all hybrid clouds, eliminating the need to manage separate processes for each environment. Standardized protocols – Uniform security policies and configuration baselines ensure consistent trust levels and simplify audit trails, which is critical for compliance-driven architectures. Continuous monitoring – Built-in health checks and real-time alerts detect expired or mis-configured certificates before they cause service disruption, reducing the risk of unplanned outages. Low management overhead – Automation removes manual steps, decreasing human error and freeing staff to focus on higher-value security tasks. Scalability – The approach scales easily as new workloads or regions are added, preserving the same operational model without proliferating rule sets.
Why the other options are less suitable
A – Separate CAs per environment – Introduces fragmented certificate lifecycles, duplicated validation logic, and inconsistent policy enforcement, increasing complexity and the chance of mis-alignment between environments. B – Manual deployment with quarterly reviews – Requires frequent manual intervention, is error-prone, and cannot keep pace with the rapid change cadence typical of hybrid cloud workloads, leading to higher operational overhead. C – Using provider default certificates with periodic sync – Default certificates often lack the organization-specific security controls (e.g., key lengths, naming conventions) and do not provide continuous monitoring or automated renewal, exposing the environment to potential trust-anchor weaknesses and unnoticed expiration.


Reference:

Strata Cloud Manager – Certificate Management Overview: https://docs.paloaltonetworks.com/strata-cloud-manager/scm/20.1/s cm-admin/s cm-admin-certificates.html Panorama Administrator’s Guide – Managing Certificates: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/pan-os-admin-certificates.html



Viewing page 3 of 13
Viewing questions 17 - 24 out of 108 questions


Post your Comments and Discuss Palo Alto Networks NetSec-Pro exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!