Skip to content

Network Security Questions

Practice questions for Network Security topic in Palo Alto Networks Certified Cybersecurity Practitioner. 38 questions covering this domain.

38 questions10 easy20 medium8 hard
Q1
easy

Which firewall type filters individual packets without tracking session state?

Q2
medium

A company wants users to reach only authorized private applications rather than joining the whole network. Which approach fits best?

Q3
medium

A data center team wants to limit east-west movement if one workload is compromised. Which design approach should they use?

Q4
easy

Which network security approach provides least-privileged application access without relying on implicit network trust?

Q5
medium

A device filters traffic by packet fields but does not know whether packets belong to an established session. Which firewall type is this?

Q6
hard

A legacy VPN gives remote users broad network reach, and leadership wants app-specific least-privileged access. Which approach should replace the broa...

Q7
hard

A rule based only on TCP port allows both approved and risky applications. Which control best addresses the application-identification gap?

Q8
medium

The security team needs an inline control that can block exploit attempts as traffic passes. Which technology applies?

Q9
medium

Traffic is using port 443, but the team must control the actual application and user. Which control fits best?

Q10
medium

The team cannot detect threats hidden in outbound HTTPS unless traffic can be inspected under policy. Which capability is needed?

Q11
hard

Malware is delivered over encrypted web sessions, and policy allows inspection for managed users. Which capability enables detection inside that traff...

Q12
medium

A protection method catches known patterns but misses a modified or unknown attack. Which limitation is being shown?

Q13
easy

Which technology inspects traffic inline and blocks malicious activity?

Q14
hard

A compromised workload can communicate freely with peer systems. Which design change best reduces the blast radius?

Q15
medium

Users need real-time protection against newly created phishing pages. Which Palo Alto Networks service is most aligned?

Q16
medium

A branch requires an encrypted tunnel to another site over an untrusted network. Which technology should be selected?

Q17
medium

A security team wants to identify malicious domains during DNS lookups before connections complete. Which service applies?

Q18
easy

Which approach divides an environment into smaller protected segments to restrict lateral movement?

Q19
easy

Which firewall type identifies applications, users, and content instead of relying only on ports?

Q20
medium

A campus edge requires a physical NGFW appliance in a bare-metal network design. Which deployment option fits?

Sign in to see all 38 questions

Create a free account to browse all questions — completely free during our launch phase.