TechNuggets Academy

Deploy and Configure Features and Subscriptions

Free Palo Alto Networks Certified Network Security Engineer practice — 6 questions on Deploy and Configure Features and Subscriptions, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
An analyst reviews WildFire submission logs and notices a PDF file was assigned a verdict of 'Phishing' rather than 'Malicious' or 'Grayware'. What does this specific WildFire verdict indicate about the file?
The Phishing verdict is a distinct WildFire classification used specifically for files or URLs identified as credential-phishing content, separate from the Malicious verdict used for malware behavior or exploits.
Question 2 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
Which DNS Security category is specifically designed to identify domain names produced by malware algorithms used to generate rotating, resilient command-and-control infrastructure?
The DGA category in DNS Security is built to detect algorithmically generated domain names that malware families use to create large numbers of rotating C2 domains, defeating static blocklists.
Question 3 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
An Anti-Spyware profile uses the DNS Sinkhole action with the default Palo Alto Networks sinkhole FQDN. When an internal host queries a malicious domain, the firewall returns the sinkhole IP address in the DNS response. To identify which internal host is actually infected and attempting to reach the malicious domain, which log should the administrator examine?
After the DNS response is sinkholed, the infected host attempts to connect to the sinkhole IP address. Filtering the Traffic log for sessions destined to that IP reveals the actual source IP of the infected internal host.
Question 4 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
A Vulnerability Protection profile's base rule uses the 'default' action for all critical-severity threats. The security team wants threat ID 39900 specifically to trigger a block-ip action with a 300-second duration, tracked by source, while every other critical threat continues using the default action. How should this be configured?
The Exceptions tab in a Vulnerability Protection profile allows per-signature-ID action overrides, including block-ip with configurable track-by (source/destination) and duration, without altering the base rule's behavior for other threats.
Question 5 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
A custom URL category named 'Finance-Block' contains a set of specific FQDNs and is set to action 'block' in a URL Filtering profile. Those same FQDNs also belong to the PAN-DB predefined category 'financial-services', which is set to action 'alert' in the same profile. When a user browses to one of these FQDNs, which action does the firewall enforce?
When a site matches both a custom URL category and a PAN-DB predefined category within the same URL Filtering profile, the custom URL category's action takes precedence, so the block action is enforced.
Question 6 of 6 · Domain 3: Deploy and Configure Features and Subscriptions
A traffic flow matches a security profile group containing Antivirus, Anti-Spyware, Vulnerability Protection, and URL Filtering profiles, each configured to block on a match. Regardless of the order in which the profiles are listed within the profile group, which threat engine evaluates the traffic FIRST?
PAN-OS Content-ID inspects traffic using a fixed internal engine order that begins with Vulnerability Protection (exploit/IPS signatures), independent of how profiles are arranged inside the security profile group.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →