NGFWEngineer Palo Alto Networks Certified NextGeneration Firewall Engineer Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

An organization\'s network security team has detected a surge of outbound data exfiltration attempts originating from a newly deployed, proprietary internal development tool. This tool utilizes an unconventional communication protocol and port hopping mechanism, rendering it invisible to the firewall\'s existing App-ID signatures. Existing security policies are configured to block all traffic classified as \"unknown\" or \"any\" to external destinations. What is the most effective initial strategic action the security administrator should take to regain granular control over this specific application\'s traffic while minimizing disruption to other network operations?

Implement an Application Override policy to explicitly identify and control the proprietary development tool's traffic.
Disable the security policy that blocks all "unknown" traffic to allow for broader network visibility.
Create a new, highly restrictive custom application signature that blocks all outbound traffic from the tool's known source IP addresses.
Manually analyze packet captures for all traffic originating from the development team's subnet to identify the specific ports and protocols used.

About the NGFWEngineer Palo Alto Networks Certified NextGeneration Firewall Engineer Certification

These free practice questions are designed to help you assess your readiness for the NGFWEngineer Palo Alto Networks Certified NextGeneration Firewall Engineer exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.