Palo Alto Networks Certified Network Security Administrator (PCNSA) flashcards
166 free flashcards. Tap a card to flip it.
Management Access Restriction
Flip cardThe ability to limit which source IP addresses are permitted to access a Palo Alto Networks firewall's management interface (web UI, SSH, SNMP).
- Enhances security by reducing attack surface.
- Configured under Device > Setup > Management.
- Allows specific IP addresses or subnets.
Memory trick: Lock down the admin's door by checking their IP at the Device's setup for Management.
Firewall Registration ID
Flip cardThe Serial Number is the unique identifier for a Palo Alto Networks firewall used for registration, licensing, and support portal access.
- Found on the device label and in the web UI/CLI.
- Required for all licensing and support interactions.
- Distinguishes individual hardware units.
Memory trick: To unlock support for your fiery box, use its unique Serial Number to pick the locks!
Active/Active HA Benefit
Flip cardActive/Active High Availability on Palo Alto Networks firewalls enables both devices to process traffic simultaneously, improving performance and resource utilization.
- Both firewalls are active traffic processors.
- Increases total throughput capacity.
- More complex to configure than Active/Passive.
Memory trick: Active/Active: double the fire, double the power, for peak traffic hour!
Default Admin Password Risk
Flip cardUsing default credentials for administrative accounts on any network device, especially firewalls, creates a critical vulnerability for unauthorized access and system compromise.
- Default admin/admin is widely known.
- Allows full control of the firewall.
- Changes should be made during initial setup.
Memory trick: A wide-open admin door means anyone can walk into your firewall's core!
Palo Alto Subinterface Naming
Flip cardPalo Alto Networks subinterfaces are typically named by appending the VLAN ID to the physical interface name (e.g., ethernet1/1.100) and are used for VLAN tagging.
- Used to handle tagged VLAN traffic.
- Can be Layer 2 or Layer 3.
- Commonly used with Virtual Routers for inter-VLAN routing.
Memory trick: VLAN's number gets hitched to the interface name, like a dot-wedding on the network game!
Palo Alto Initial Feature Enablement
Flip cardThe proper sequence for enabling advanced security features on a Palo Alto Networks firewall involves activating licenses, updating PAN-OS, and then installing content definitions.
- Licenses enable feature functionality.
- PAN-OS updates ensure platform stability and compatibility.
- Content updates provide the latest threat intelligence.
Memory trick: First the Key (license), then the Upgrade (software), then the Shield (content) for threat protection!
Firewall DNS Resolution
Flip cardPalo Alto Networks firewalls rely on DNS for their own operations, including content updates, cloud services, and external name resolution, which requires proper network configuration.
- Firewall uses its management interface for its own DNS queries.
- Requires correct DNS server and default gateway configuration.
- Impacts updates, cloud services, and URL filtering.
Memory trick: Firewall can't find the internet's name, if its own gateway isn't playing the game!
Log Forwarding Profile
Flip cardA configuration object on Palo Alto Networks firewalls that specifies which logs (traffic, threat, system, etc.) to forward and to which external destinations (syslog, SNMP, email, HTTP).
- Links log types to external server profiles.
- Applied to security rules or other logging features.
- Crucial for sending logs off the firewall.
Memory trick: Syslog knows the address, but needs the forwarding profile to mail the logs out!
Active/Passive HA
Flip cardA high availability deployment where one firewall actively processes traffic while the other remains in a passive, synchronized standby state, ready to take over upon failure.
- One firewall is active, one is passive.
- Requires dedicated HA links for control and data plane synchronization.
- Ensures session continuity during failover.
Memory trick: Two firewalls stand ready, one leads, one shadows, linked by unseen threads.
NTP Configuration
Flip cardNetwork Time Protocol (NTP) is essential for accurate logging, certificate validation, and policy scheduling on a firewall.
- Ensures accurate timestamps for logs.
- Critical for certificate validity checks.
- Configured under Device > Setup > Services.
Memory trick: NTP keeps the firewall's clock in precise sync with the network tick.
PAN-OS Upgrade Best Practice
Flip cardAlways back up the firewall configuration before a PAN-OS upgrade to enable rollback and disaster recovery.
- Export configuration to an external location.
- Allows restoration to a known working state.
- Prevents data loss during upgrade failures.
Memory trick: Before you jump to the new OS, back up your config, lest you lose!
Virtual Wire
Flip cardA deployment mode for Palo Alto Networks firewalls where two interfaces are logically bound to act as a 'bump-in-the-wire', inspecting traffic without requiring IP addresses on those interfaces.
- Transparently inserts the firewall into a network segment.
- Requires two physical interfaces.
- Uses 'Virtual Wire' interface type and 'Virtual Wire' object.
Memory trick: To make your firewall a transparent wire, bind two interfaces with a Virtual Wire's fire!
Default Management IP
Flip cardPalo Alto Networks firewalls come with a pre-configured static IP address on their management interface for initial setup.
- Default IP is 192.168.1.1/24.
- HTTPS is enabled by default for web UI access.
- Requires connecting to the MGT port.
Memory trick: Connect to the fiery heart, but check your network part!
Common Network Ports
Flip cardStandardized port numbers used by specific network protocols for communication.
- Port 21: FTP (File Transfer Protocol)
- Port 22: SSH (Secure Shell)
- Port 23: Telnet
- Port 25: SMTP (Simple Mail Transfer Protocol)
Memory trick: Ports are like doors; 80 is for regular web, 443 for secure web, others for different services.
Shift-Left Security
Flip cardThe practice of integrating security testing and practices earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Reduces cost of vulnerability remediation.
- Improves overall software security posture.
- Involves tools like SAST, DAST, and SCA earlier.
Memory trick: Fixing bugs early saves money, like patching a tiny hole before it sinks the ship.
Types of Threat Intelligence
Flip cardCategorization of threat intelligence based on its audience, purpose, and level of detail.
- Strategic: High-level, long-term trends, executive-focused.
- Tactical: Attacker TTPs, security team-focused.
- Operational: Specific campaigns, actor motivations, incident response-focused.
- Technical: IoCs, vulnerability details, machine-consumable, real-time detection-focused.
Memory trick: Threat intel has levels: Strategic for leaders, Tactical for methods, Operational for campaigns, Technical for direct actions.
Zero-Day Vulnerability
Flip cardA software vulnerability that is unknown to the vendor or the public at the time it is discovered and exploited by attackers, meaning no patch is available.
- Highly dangerous due to lack of defense.
- Exploited before a patch is released.
- Often used in targeted attacks.
Memory trick: The 'zero' in zero-day means zero time to patch before the attack.
Distributed Firewall Architecture
Flip cardA network security approach where firewall functions are deployed across multiple points in a network (e.g., branch offices, data centers), managed from a central console for consistent policy enforcement and visibility.
- Enables consistent security across dispersed locations.
- Centralized policy management, distributed enforcement.
- Often integrated with VPN for secure site-to-site communication.
Memory trick: Many doors, one master key, and secret tunnels for communication.
Defense in Depth
Flip cardA cybersecurity strategy in which multiple layers of security controls are placed throughout an IT system to protect the confidentiality, integrity, and availability of data.
- Multiple, overlapping security controls.
- No single point of failure.
- Network segmentation is a key component.
- Aims to slow down and contain attackers.
Memory trick: Security architectures build defenses: Defense in Depth layers walls, Zero Trust checks every door, Segmentation creates rooms.
SYN Flood
Flip cardA type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server without finalizing the handshake.
- Exploits the TCP three-way handshake.
- Sends many SYN packets but no final ACK.
- Fills server's half-open connection queue, preventing legitimate connections.
Memory trick: DoS attacks stop service; SYN floods jam connections, others overwhelm with specific traffic.
Principle of Least Privilege (PoLP)
Flip cardA security concept in which a user, program, or process is given only the minimum necessary rights, permissions, or access level to perform its function.
- Minimizes potential damage from compromised accounts.
- Reduces the attack surface.
- A fundamental security best practice.
Memory trick: Only give the key to exactly what they need, not the whole house.
Cross-Site Scripting (XSS)
Flip cardA type of web security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users.
- Injects malicious script into a legitimate website.
- Script executes in the victim's browser.
- Can steal cookies, session tokens, or deface websites.
Memory trick: Web attacks can be tricky; XSS injects code, SQL injects data, DDoS blocks access.
Advanced Persistent Threat (APT)
Flip cardA stealthy threat actor, typically a nation-state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.
- Highly skilled and resourced attackers.
- Long-term, multi-stage campaigns.
- Adaptive tactics to avoid detection.
- Often target intellectual property or critical infrastructure.
Memory trick: Threat actors vary: APTs are persistent and skilled, script kiddies are basic, insider threats are internal.
Zero Trust
Flip cardA security model where no user or device, whether inside or outside the network perimeter, is trusted by default, and every access request is verified before granting access.
- Based on the principle 'never trust, always verify'.
- Focuses on strict access controls and micro-segmentation.
- Assumes breaches are inevitable and aims to minimize their impact.
Memory trick: Don't trust anyone, verify everything, especially inside the walls.
Nation-State Actor
Flip cardA state-sponsored group or individual that conducts cyber espionage, sabotage, or warfare to advance national interests, often characterized by high sophistication and resources.
- Highly skilled and well-funded.
- Uses advanced persistent threat (APT) tactics.
- Motivated by espionage, sabotage, or political gain.
Memory trick: Who's behind the keyboard? Motive and skill tell the tale.
Non-repudiation
Flip cardA security service that provides undeniable proof of the origin of a message or the integrity of data, preventing a sender from falsely denying having sent a message or an action.
- Ensures accountability for actions and communications.
- Often achieved through digital signatures and trusted timestamps.
- Crucial for legal and contractual agreements.
- Helps combat impersonation and phishing by verifying sender authenticity.
Memory trick: Don't deny, prove it's from you!
Device Hardening
Flip cardThe process of securing a system by reducing its attack surface and mitigating potential vulnerabilities.
- Involves removing unnecessary software, services, and accounts.
- Includes applying security patches and updates regularly.
- Requires configuring strong authentication mechanisms and access controls.
- Aims to minimize potential entry points for attackers.
Memory trick: Harden devices like a fortress: strong gates, minimal windows.
CIA Triad
Flip cardA fundamental model for cybersecurity, representing the three core security goals: Confidentiality, Integrity, and Availability.
- Confidentiality: Protecting data from unauthorized access.
- Integrity: Ensuring data accuracy and preventing unauthorized modification.
- Availability: Guaranteeing access to legitimate users when needed.
Memory trick: CIA: Confidentiality is secrets, Integrity is truth, Availability is always there.
Multi-Factor Authentication (MFA) against Phishing
Flip cardMFA significantly mitigates the risk of successful phishing attacks by requiring an additional verification factor beyond a password, making stolen credentials less useful to attackers.
- Protects against credential stuffing and stolen passwords.
- Adds a layer of security even if phishing is successful.
- Considered a critical control for account security.
Memory trick: Beyond the lure, a second lock stops the catch.
Multi-Factor Authentication (MFA)
Flip cardAn authentication method that requires a user to provide two or more verification factors to gain access to a resource, often categorized as something you know, something you have, and something you are.
- Significantly improves security over single-factor authentication.
- Combines different types of authentication factors.
- Commonly used to protect sensitive accounts.
Memory trick: The more ways you prove you are you, the safer the door.
Supply Chain Attack
Flip cardA cyberattack that targets an organization by compromising less secure elements in its supply chain, such as third-party vendors, software providers, or hardware manufacturers.
- Exploits trust relationships.
- Can affect many downstream customers.
- Difficult to detect and prevent.
Memory trick: A chain is only as strong as its weakest link, especially when it's your vendor.
Intrusion Prevention System (IPS)
Flip cardA network security device that monitors network and/or system activities for malicious or unwanted behavior and can react in real-time to block or prevent those activities.
- Active prevention of attacks.
- Operates inline with network traffic.
- Detects and blocks known malicious patterns (signatures) and anomalies.
Memory trick: To stop the bad stuff mid-flow, you need active guards on the network.
Cyber Attack Kill Chain
Flip cardA model developed by Lockheed Martin that outlines the stages of a typical cyber attack, from reconnaissance to achieving the attacker's objective.
- Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives.
- Helps security teams understand and disrupt attack progression.
- Focuses on preventing the attacker from achieving their goal.
Memory trick: Kill Chain is a sequence: Recon, Weaponize, Deliver, Exploit, Install, C2, Objectives.
Vulnerability Management
Flip cardThe cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities in systems and applications.
- Continuous process.
- Involves scanning, assessment, and patching.
- Reduces attack surface and risk.
Memory trick: Best practices keep us safe: Patching for vulnerabilities, training for people, DLP for data, IR for after.
Web Content Filtering
Flip cardA security measure that controls access to websites based on categories, reputation, or specific URLs, often used to block malicious or inappropriate content.
- Prevents access to known malicious sites.
- Can enforce acceptable use policies.
- Reduces malware infection risk from web browsing.
Memory trick: To stop web nasties, filter the surfing.
Exploitation (Cyber Kill Chain)
Flip cardThe stage in the cyber kill chain where an attacker leverages a vulnerability in a system or application to gain access or control.
- Occurs after delivery of a weaponized payload.
- Aims to execute code or gain unauthorized access.
- Often involves specific vulnerabilities like unpatched software or misconfigurations.
Memory trick: Remember 'Rex Wears Dark Expensive Underwear, Instantly Feeling Comfortable'
Network Segmentation
Flip cardThe practice of dividing a computer network into smaller, isolated sub-networks or segments to improve security, control traffic, and limit the impact of a breach.
- Limits lateral movement of attackers.
- Contains breaches to specific segments.
- Enables granular security policy enforcement.
Memory trick: Divide your network into rooms, so a fire in one doesn't burn down the whole house.
NIST Cybersecurity Framework (CSF)
Flip cardA voluntary framework for organizations to manage and reduce cybersecurity risk, composed of five core functions: Identify, Protect, Detect, Respond, and Recover.
- Developed by the National Institute of Standards and Technology (NIST).
- Provides a common language for cybersecurity risk management.
- Applicable across various sectors and organization sizes.
- Aims to improve critical infrastructure cybersecurity.
Memory trick: NIST's core functions: I Protect Detect, Respond, Recover.
Principle of Least Privilege
Flip cardA security concept in which a user is given the minimum levels of access – or permissions – needed to perform a job function.
- Grants minimum necessary rights.
- Reduces attack surface.
- Limits potential damage from compromise.
Memory trick: Security principles guide protection: Least Privilege limits access, Separation of Duties prevents single points of failure.
Distributed Denial of Service (DDoS)
Flip cardA malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple compromised systems (botnet).
- Floods target with overwhelming traffic.
- Renders service unavailable to legitimate users.
- IoT devices are common components of botnets.
Memory trick: DoS attacks stop service: DDoS uses many sources, DoS uses one.
Rootkit
Flip cardA collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed (for example, to an unauthorized user) and often masks its existence or the existence of other malware.
- Gains root/administrative access.
- Modifies OS kernel/system files.
- Hides its own presence and other malicious activities.
- Difficult to detect and remove.
Memory trick: Malware has many forms: Rootkits hide, Ransomware locks, Worms spread, Trojans trick.
Management Interface Profile
Flip cardA Management Interface Profile on a Palo Alto Networks firewall defines which administrative services (HTTPS, SSH, Ping, SNMP, etc.) are permitted on a specific interface, and from which source IP addresses.
- Controls access to the firewall's management plane.
- Applied per interface (management, data plane interfaces).
- Includes allowed services and IP addresses/ranges.
Memory trick: Management Profile Protects Privileged Ports.
SNMP Management Access
Flip cardTo allow SNMP polling to a Palo Alto Networks firewall, a Management Interface Profile must be configured on the relevant interface, permitting SNMP and specifying the source IP addresses of authorized monitoring stations.
- SNMP is a management service.
- Controlled by Management Interface Profile.
- Restricts access by service and source IP.
- Essential for secure monitoring.
Memory trick: Management Profile Makes Monitoring Possible.
Panorama for Centralized Management
Flip cardPanorama is a centralized management system for Palo Alto Networks firewalls, enabling consistent policy enforcement, device management, and unified logging across multiple firewalls, including centralized licensing and subscription management.
- Manages multiple firewalls from a single console.
- Facilitates consistent policy deployment.
- Provides centralized logging and reporting.
- Handles licensing and subscription updates centrally.
Memory trick: Panorama Provides Pervasive Policy & Procurement.
HA Control Link IP
Flip cardThe Palo Alto Networks HA control link requires a Layer 3 IP address configuration on both peer firewalls, with both IPs residing in the same subnet, to facilitate heartbeat, state exchange, and configuration synchronization.
- Crucial for HA communication.
- Requires IP address on each peer.
- IPs must be in the same subnet.
- Supports heartbeat, state, and config sync.
Memory trick: IP Inconsistency Impedes HA Interconnection.
Virtual Router Assignment
Flip cardIn Palo Alto Networks firewalls, Layer 3 interfaces (including the management interface if configured for in-band management) must be assigned to a Virtual Router to enable routing and participate in Layer 3 functions like ARP.
- Essential for Layer 3 forwarding on interfaces.
- Management interface needs assignment for in-band access.
- Defaults to a 'default' Virtual Router.
Memory trick: Virtual Routers Route Management Right.
Active/Active HA Prerequisites
Flip cardActive/Active High Availability on Palo Alto Networks firewalls requires specific deployment modes like Virtual Wire or the use of multiple Virtual Systems (vsys) to enable both firewalls to actively process traffic concurrently.
- Both firewalls process traffic simultaneously.
- Requires Virtual Wire or multiple Virtual Systems.
- Distributes load and provides redundancy.
- More complex to configure than Active/Passive.
Memory trick: Virtual Wires or Vsys are Vital for Active/Active.
Securing Remote Management
Flip cardSecuring remote administrative access to a Palo Alto Networks firewall involves using the dedicated Management Interface and applying a Management Profile to restrict allowed services (HTTPS, SSH) and source IP addresses to trusted administrators.
- Uses the dedicated Management Interface.
- Management Profile defines allowed services and source IPs.
- Crucial for protecting against unauthorized access.
- Out-of-band management is preferred.
Memory trick: Management Interface Profile Provides Perimeter Protection.
Service Routes
Flip cardService Routes on a Palo Alto Networks firewall define the egress interface and source IP address the firewall itself uses for its own management-plane services, such as DNS, NTP, WildFire, and software updates.
- Controls firewall's own outgoing traffic.
- Specifies source interface and IP.
- Critical for reaching external management services.
- Configured under Device > Setup > Services > Service Route Configuration.
Memory trick: Service Routes Send Firewall Services Smoothly.
Firewall Serial Number
Flip cardThe serial number is a unique hardware identifier for a Palo Alto Networks firewall, essential for device registration on the customer support portal, enabling licensing, software downloads, and support services.
- Unique hardware identifier.
- Required for support portal registration.
- Enables licensing and software updates.
- Can be found on the device label or via CLI/web UI.
Memory trick: Serial Number Secures Support Subscriptions.
PAN-OS Installation Step
Flip cardAfter downloading a PAN-OS software image to the firewall, the next step is to install it. This action stages the new operating system for activation upon the next reboot.
- Follows image download.
- Precedes firewall reboot.
- Prepares the system for the new OS version.
Memory trick: Download, Install, Reboot - Simple Software Steps.
HA Session Synchronization
Flip cardIn a Palo Alto Networks HA pair, session synchronization ensures that the passive firewall maintains an up-to-date copy of all active sessions from the active firewall, allowing existing connections to continue uninterrupted after a failover.
- Prevents session drops during failover.
- Requires dedicated HA control and data links.
- Critical for stateful firewall operations.
Memory trick: Sync Sessions Smoothly Saves Services.
Virtual Wire Mode
Flip cardA transparent deployment mode for Palo Alto Networks firewalls where it functions as a 'bump in the wire' at Layer 2, without requiring changes to IP addressing or routing.
- Invisible to the network.
- Provides full Layer 2-7 inspection.
- Ideal for sensitive segments or gradual deployments.
Memory trick: Virtual Wire is like an invisible security guard standing directly in the pathway.
Default Management Access
Flip cardThe standard interface and port used to access the Palo Alto Networks firewall's web interface (GUI) or CLI for configuration and monitoring, typically out-of-band.
- Dedicated 'management' interface
- HTTPS (port 443) for GUI access
- SSH (port 22) for CLI access
Memory trick: Manage securely on port 443, to the interface that's free.
Layer 3 Deployment Mode
Flip cardA firewall deployment mode where the Palo Alto Networks firewall acts as a router, participating in routing protocols and performing full packet inspection with policy enforcement.
- Acts as a router
- Enforces security policies (App-ID, User-ID, Content-ID)
- Requires IP address configuration on interfaces
Memory trick: Route, Inspect, Protect: Layer 3 is the best.
Panorama
Flip cardPalo Alto Networks' centralized management solution for multiple firewalls, offering unified policy management, logging, reporting, and software updates.
- Scalable for large deployments.
- Reduces operational complexity.
- Provides a single pane of glass for security operations.
Memory trick: Panorama gives you a panoramic view and control over all your firewalls.
Tap Mode
Flip cardA passive deployment mode for Palo Alto Networks firewalls where it receives a mirrored copy of network traffic for analysis, without being in the active data path.
- Provides visibility without disruption.
- Cannot block or modify traffic.
- Used for monitoring, forensics, and proof-of-concept.
Memory trick: Tap Mode is like a silent observer, listening in without interfering.
Single-Pass Parallel Processing (SP3)
Flip cardThe unique architectural approach of Palo Alto Networks firewalls where all security functions (App-ID, User-ID, Content-ID, Threat Prevention, etc.) are performed simultaneously on a single pass of the traffic.
- Optimizes performance and reduces latency.
- Eliminates redundant scanning.
- Enables full context-aware security.
Memory trick: SP3 is like a super-efficient assembly line where every security check happens at once.
Security Operating Platform
Flip cardThe Palo Alto Networks Security Operating Platform is an integrated, end-to-end cybersecurity architecture designed to provide consistent protection across cloud, network, and endpoint environments, focusing on prevention, detection, and response.
- Unified and integrated approach to security
- Covers network, cloud, and endpoint
- Focuses on prevention, detection, and response lifecycle
- Comprises Next-Generation Firewalls, Panorama, WildFire, GlobalProtect, etc.
Memory trick: An 'Operating Platform' for all your security operations.
Security Zones
Flip cardLogical groupings of interfaces on a Palo Alto Networks firewall that share similar security requirements, forming the basis for defining security policies.
- Interfaces assigned to zones
- Policies defined between zones
- Essential for granular security control
Memory trick: Zones unite interfaces for policy might.