Palo Alto Networks Certified Network Security Administrator (PCNSA) flashcards
166 free flashcards. Tap a card to flip it.
Custom Report Filter Validation
Flip cardTo validate custom report filter criteria, copy the exact filter string and apply it directly to the corresponding log type's filter bar in the 'Monitor > Logs' section of the firewall GUI. This provides real-time feedback on matching log entries.
- Ensures the filter syntax is correct and logically sound.
- Allows immediate visual confirmation of matching log entries.
- Prevents wasting resources on generating empty or incorrect reports.
Memory trick: For a 'report filter' that's 'broken', 'copy' it to 'logs' and see what's 'spoken'!
WildFire Submissions Logs
Flip cardWildFire Submissions logs provide detailed records of files submitted to the WildFire cloud for advanced threat analysis, including the analysis verdict, source, destination, and user information.
- Shows the WildFire verdict (malicious, benign, grayware).
- Includes sender/receiver and user details for submitted files.
- Crucial for investigating patient zero and spread of new malware.
Memory trick: For 'WildFire' verdicts, check the 'WildFire Submissions' logs directly!
Security Profile Logging
Flip cardPalo Alto Networks Security Profiles (Threat Prevention, URL Filtering, etc.) have their own logging settings that must be enabled to generate detailed logs related to their specific inspection functions.
- Basic session logging is controlled by 'Log at Session Start/End' on the security rule.
- Detailed threat logs are generated by the Threat Prevention profile.
- Detailed URL logs are generated by the URL Filtering profile.
- These profiles must be attached to the security rule, and their internal logging enabled, for comprehensive data.
Memory trick: Logging: Rule for session, profiles for detail, forward for storage, visibility's the prize.
Content-ID Security Profiles
Flip cardContent-ID leverages multiple security profiles to inspect traffic for threats and sensitive data, providing comprehensive protection.
- Antivirus: Blocks known malware.
- Anti-Spyware: Detects and blocks spyware and C2 traffic.
- Vulnerability Protection: Prevents exploits of known vulnerabilities.
- Data Filtering: Identifies and blocks sensitive data patterns.
Memory trick: Content-ID is like a meticulous security inspector, checking for every type of forbidden item (malware, spyware, sensitive data).
Common Security Profiles
Flip cardPalo Alto Networks firewalls use various security profiles to protect traffic. Antivirus detects known malware, and URL Filtering controls access to web categories.
- Antivirus: Blocks known viruses, worms, and spyware.
- URL Filtering: Controls web access based on categories or specific URLs.
- Threat Prevention: Comprehensive protection against exploits, malware, spyware.
Memory trick: Scan for Bugs, Block Bad Sites.
WildFire Logs
Flip cardWildFire logs on a Palo Alto Networks firewall record information about files submitted to the WildFire cloud for advanced malware analysis. They detail the file hash, verdict (malicious, benign, grayware), and associated session information.
- Crucial for identifying and understanding zero-day threats.
- Generated when a WildFire Analysis profile is applied to a security rule.
- Provides a comprehensive audit trail of advanced threat detection.
Memory trick: Each log type tells a different story about your network's life.
Traffic Logs for Blocked Sessions
Flip cardTraffic logs in Palo Alto Networks firewalls record details for all network sessions, including the application identified and the action taken (allow, deny, drop, reset-client, reset-server, reset-both).
- Contain 'action' field to determine if a session was blocked.
- Include 'application' field for identifying the application.
- Can be filtered and grouped to report on blocked applications by session count.
Memory trick: For 'blocked apps', check the 'traffic' flow to see what was 'denied'.
File Blocking & Data Filtering
Flip cardFile Blocking controls the transfer of specific file types, while Data Filtering inspects file content for sensitive information based on patterns or keywords.
- File Blocking: Enforces policy on file types (e.g., .pdf, .docx).
- Data Filtering: Enforces policy based on content patterns or keywords within files.
- Both are part of Content-ID.
- Often used together for comprehensive data loss prevention (DLP).
Memory trick: DLP is like a postal inspector: it checks the 'package type' (File Blocking) and then scans the 'contents' for secret messages (Data Filtering).
Palo Alto Custom Alerts
Flip cardCustom alerts on Palo Alto Networks firewalls allow administrators to define specific conditions based on log data that, when met, trigger notifications or other actions. These are configured under the 'Monitor' tab.
- Provide proactive notification of critical events.
- Can be based on any log type and complex query criteria.
- Actions include email, SNMP trap, or syslog messages.
Memory trick: Monitor your reports to manage your alerts.
Traffic Logs
Flip cardTraffic logs record all network sessions processed by the firewall, detailing source, destination, application, action, and bytes transferred.
- Captures allowed, denied, dropped, and reset sessions.
- Essential for monitoring network activity and security policy effectiveness.
- Includes information like application, user, zone, and security rule.
Memory trick: Each log type tells a different story about firewall activity.
URL Filtering Actions
Flip cardURL Filtering actions define how the firewall responds when traffic matches a specific URL category in a URL Filtering profile.
- Block: Denies access to the URL.
- Alert: Logs access without blocking.
- Allow: Permits access to the URL.
- Continue: Allows traffic, but may prompt user for confirmation or log.
Memory trick: URL Filtering is like a bouncer: it checks your ID (URL category) and decides if you're in or out.
ACC Top Applications Widget
Flip cardThe 'Top Applications by Bandwidth' widget in the Application Command Center (ACC) displays a ranked list of applications consuming the most network bandwidth over a specified period.
- Provides quick visibility into application bandwidth usage.
- Helps identify bandwidth hogs and unapproved application usage.
- Data can be filtered by time range and other parameters.
Memory trick: ACC's got the 'wiz' to show what's 'biz' with your bandwidth.
Decryption Policy 'No Decrypt'
Flip cardThe 'No Decrypt' action in a decryption policy rule prevents the firewall from intercepting and decrypting SSL/TLS traffic that matches the rule criteria.
- Used for privacy, legal, or technical reasons.
- Traffic passes through encrypted.
- Rule order is critical, 'No Decrypt' rules should be placed above 'Decrypt' rules.
Memory trick: Decrypt or Not? Policy Decides.
Application Command Center (ACC)
Flip cardThe ACC provides an interactive, graphical summary of network activity, security posture, and threat trends on the firewall.
- Offers real-time and historical data visualization.
- Includes widgets for applications, users, threats, and URLs.
- Facilitates quick identification of network anomalies and security incidents.
Memory trick: ACC is your dashboard for all network insights.
Dynamic IP and Port (DIPP) Source NAT
Flip cardDIPP Source NAT translates both the source IP address and source port of outbound connections, allowing multiple internal hosts to share a limited pool of public IP addresses.
- Many-to-one or many-to-few mapping.
- Uses both IP and port translation.
- Commonly used for outbound internet access from internal networks.
- Preserves session state for return traffic.
Memory trick: NAT is like a postal service: it changes the 'return address' (Source NAT) or the 'destination address' (Destination NAT) of packets.
Application Groups
Flip cardAn Application Group in Palo Alto Networks is a logical grouping of multiple App-IDs that can be used in a single security policy rule. This helps to consolidate the rulebase and simplify management while maintaining granular application control.
- Combines multiple App-IDs into one object.
- Reduces rulebase complexity and size.
- Allows for consistent policy application across related applications.
Memory trick: Group Applications, Simplify Rules.
Policy Optimizer
Flip cardThe Policy Optimizer feature in Palo Alto Networks firewalls provides analytics on security policy rule usage, helping administrators identify over-permissive, under-utilized, or unused rules for optimization.
- Located under Monitor > Policy Optimizer.
- Shows hit counts for security rules.
- Helps identify unused rules, over-provisioned rules, and opportunities for 'App-ID' adoption.
Memory trick: To 'optimize' your 'policies', 'monitor' them closely!
Email Server Profile
Flip cardThe Email Server Profile in Palo Alto Networks firewalls specifies the SMTP server details required for the firewall to send email notifications for reports, alerts, and other events.
- Configured under Device > Server Profiles > Email.
- Contains SMTP server address, port, sender email, and authentication details.
- Essential for any email-based notifications from the firewall.
Memory trick: For 'email' issues, check the 'Email Server Profile' first!
App-ID for ICMP
Flip cardPalo Alto Networks App-ID can identify specific types of ICMP traffic, such as 'ping', allowing granular control over ICMP in security policies beyond just allowing the entire protocol.
- App-ID can differentiate between ICMP types (e.g., ping, traceroute, unreachable).
- Using 'ping' App-ID allows only echo request/reply.
- 'application-default' service works with App-ID to enforce standard ports/protocols.
- More precise than port/protocol-only rules for ICMP.
Memory trick: Controlling ICMP with App-ID is like having a smart filter for radio signals: you only pick up 'ping' messages, ignoring all the other static.
App-ID and Security Policy
Flip cardPalo Alto Networks App-ID technology identifies applications traversing the network, regardless of port, protocol, or evasive tactics. Security policies should leverage App-ID for granular control.
- App-ID identifies applications based on multiple techniques (signatures, decryption, heuristics).
- Using App-ID in security policies provides more granular control than port-based policies.
- The 'application-default' service setting ensures that the policy only allows the identified application on its standard ports.
Memory trick: App-ID is your first line, then service, then action, keeping traffic aligned.
App-ID Granularity
Flip cardPalo Alto Networks App-ID provides granular application identification beyond port numbers, allowing specific applications (even cloud-based ones) to be controlled with precision in security policies.
- Identifies applications based on signatures, decryption, and heuristics.
- More granular than port-based rules.
- Specific App-IDs may be required for distinct cloud applications.
- App-ID runs before policy rule matching.
Memory trick: App-ID is like a specialized detective: it knows the specific 'fingerprint' of each application, even if they share the same 'door' (port).
Secure Administrative Access
Flip cardConfiguring a Palo Alto Networks firewall to allow administrative logins using centralized authentication and encrypted protocols.
- Centralized auth: RADIUS, LDAP, TACACS+.
- Secure protocols: HTTPS (WebUI), SSH (CLI).
- Management profiles restrict access by IP/interface.
Memory trick: Centralized keys, encrypted doors: That's how admins get in.
Service Route
Flip cardA configuration that specifies which interface the management plane of a Palo Alto Networks firewall should use to communicate with external services.
- Directs management traffic (DNS, NTP, syslog, updates).
- Configured under Device > Setup > Services > Service Route Configuration.
- Essential for management plane's external connectivity.
Memory trick: Management's GPS: Service Route guides its way.
Layer 3 Subinterface
Flip cardA logical interface created on a physical Layer 3 interface, associated with a VLAN tag, allowing a single physical port to route traffic for multiple VLANs.
- Requires a VLAN ID.
- Has its own IP address and routing table entry.
- Ideal for 'router-on-a-stick' scenarios on a firewall.
Memory trick: When one physical port needs to 'speak' to many VLANs, Layer 3 subinterfaces give each VLAN its own 'voice' (IP) and 'map' (routing).
Mixed L2/L3 Interface
Flip cardA configuration on a Palo Alto Networks firewall where a single physical interface simultaneously handles both Layer 2 switching and Layer 3 routing for different VLANs.
- Physical interface is configured as Layer 2.
- VLAN interfaces (Layer 3) are created on the Layer 2 physical interface.
- Enables flexible deployment in complex network segments.
Memory trick: To make one physical port 'speak' both L2 and L3, you teach the port L2, then give its VLANs their own L3 'voices'.
PAN-OS Upgrade Pre-check
Flip cardEssential checks performed on a Palo Alto Networks firewall before initiating a PAN-OS software update to ensure a successful and stable upgrade process.
- Verify disk space and memory.
- Check current PAN-OS version and upgrade path.
- Backup configuration and state.
Memory trick: Check the health and space before the big software surgery.
Palo Alto Panorama
Flip cardA centralized management solution for Palo Alto Networks Next-Generation Firewalls, enabling unified policy and device management, and log aggregation.
- Provides a single pane of glass for multiple firewalls.
- Facilitates policy deployment and configuration synchronization.
- Aggregates logs for centralized analysis and reporting.
Memory trick: For a 'panoramic' view and control of all your firewalls, you need Panorama.
Management Profile
Flip cardA configuration object in Palo Alto Networks firewalls that controls access to the firewall's interfaces, specifying allowed services and source IP addresses.
- Applied to physical or virtual interfaces (including management).
- Restricts administrative services (HTTPS, SSH, Ping, SNMP).
- Enhances security by limiting management access.
Memory trick: The Management Profile is the bouncer for the firewall's admin door.
NTP for Firewall Time Sync
Flip cardThe use of Network Time Protocol (NTP) on a Palo Alto Networks firewall to ensure accurate and synchronized system time.
- Crucial for log timestamps, certificate validity, and policy scheduling.
- Firewall can act as an NTP client.
- Configured under Device > Setup > Services > NTP.
Memory trick: To keep the firewall's clock in 'perfect time', you need NTP.
Firewall System DNS
Flip cardConfiguration of DNS servers that the Palo Alto Networks firewall uses for its internal services and operations.
- Located under Device > Setup > Services > DNS.
- Essential for WildFire, URL filtering, software updates, etc.
- Allows the firewall to resolve external domain names.
Memory trick: For the firewall to 'know' the internet, its 'brain' (Device > Setup > Services) needs its own 'phonebook' (DNS servers).
CLI Management IP Configuration
Flip cardThe `set deviceconfig system` command in the Palo Alto Networks CLI is used to configure the management interface's IP address, netmask, and default gateway for initial setup and access.
- Essential for initial out-of-band management access.
- Requires `commit` to save changes.
- Can also configure hostname, DNS, and NTP settings.
Memory trick: Device System settings are the first step to online.
PAN-OS Image Integrity Check
Flip cardThe process of verifying that a downloaded PAN-OS software image is complete, uncorrupted, and authentic before installation.
- Typically involves comparing checksums (MD5/SHA256).
- Prevents failed upgrades and potential system instability.
- Checksums are provided by Palo Alto Networks.
Memory trick: Before you 'install' the new PAN-OS 'brain', always 'check' if it's healthy and complete.
HA Session Sync Link
Flip cardA dedicated link or channel between two Palo Alto Networks firewalls in an HA pair, used to synchronize session state information.
- Enables seamless failover of active connections.
- Transmits runtime information between HA peers.
- Separate from the HA control link, though often carried over the same physical connection.
Memory trick: To keep HA sessions 'in sync', the firewalls need a dedicated 'whisper line' for their state secrets.
DHCP Client Mode
Flip cardA network interface configuration that allows a device, like a Palo Alto Networks firewall, to dynamically obtain its IP address and other network parameters from a DHCP server.
- Automates IP address assignment.
- Obtains subnet mask, gateway, DNS servers.
- Useful for initial setup or dynamic environments.
Memory trick: DHCP Client: The firewall asks for its address, no manual maps needed.
IPv6 Layer 3 Routing Prerequisite
Flip cardFor a Palo Alto Networks firewall's Layer 3 interface with an IPv6 address to route traffic, it must be assigned to a virtual router.
- Applies to both IPv4 and IPv6 on Layer 3 interfaces.
- Virtual Router makes routing decisions.
- Without it, interface is 'isolated' from routing table.
Memory trick: An IPv6 interface without a Virtual Router is a road with no map.
Device Support Information
Flip cardThe section within the Palo Alto Networks WebUI where administrators can quickly view critical operational details such as PAN-OS version, content versions, and license status.
- Located under Device > Support.
- Shows current PAN-OS version.
- Lists installed content versions (App/Threat, AV, WildFire).
- Displays license expiry dates.
Memory trick: Device > Support: Your one-stop shop for firewall health reports.
LDAP Admin Authentication
Flip cardUsing an LDAP authentication profile on a Palo Alto Networks firewall to authenticate administrative users against a centralized directory service.
- Provides unique user accounts and centralized credential management.
- Integrates with Active Directory and other LDAP-compatible directories.
- Enhances security, accountability, and simplifies password management.
Memory trick: To manage all your admin 'keys' centrally, 'LDAP' lets your firewall 'look up' users in the main directory.
Default Route for Firewall Services
Flip cardA 0.0.0.0/0 route configured on a Palo Alto Networks firewall to direct traffic for all unknown destinations, essential for reaching external services.
- Acts as a 'last resort' route.
- Critical for firewall updates, WildFire, external DNS, and cloud services.
- Configured under Network > Virtual Routers.
Memory trick: For the firewall to 'find its way' to the internet for updates, it needs a 'default map' (default route).
Management Interface DHCP
Flip cardConfiguring the Palo Alto Networks firewall's management interface to obtain its IP address and network settings dynamically via DHCP.
- Simplifies initial setup in networks with DHCP servers.
- Requires an upstream DHCP server.
- Configured under Device > Setup > Management > Management Interface.
Memory trick: If the firewall's management interface needs an IP 'delivered', it becomes a 'DHCP Client'.
CLI System Info Command
Flip cardThe 'show system info' CLI command on a Palo Alto Networks firewall, used to display a summary of device software, content, and license information.
- Provides PAN-OS version, content versions, serial number.
- Includes license status (e.g., valid, expired).
- Useful for initial checks and troubleshooting.
Memory trick: To quickly 'see' everything about the firewall's 'system', just 'show system info'.
NTP Synchronization
Flip cardThe process of configuring a Palo Alto Networks firewall to synchronize its system clock with an external Network Time Protocol (NTP) server for accuracy.
- Crucial for accurate logs, certificates, and security policy.
- Configured under Device > Setup > Services > NTP.
- Requires management plane connectivity to the NTP server.
Memory trick: NTP: The firewall's trusty watchmaker for external time.
Default Route for System Services
Flip cardA default route (0.0.0.0/0) configured on a Palo Alto Networks firewall's Layer 3 data plane interface directs outbound traffic from the firewall's own system services (e.g., DNS, NTP, updates) to the internet or an upstream router.
- Essential for firewall services to reach external resources.
- Typically configured on a Layer 3 (routed) data plane interface.
- Distinct from management interface routing, though it can overlap.
Memory trick: Firewall's own voice needs a clear path out.
Internal Reconnaissance
Flip cardThe phase in a cyberattack where an attacker, having gained initial access to a network, actively explores the internal environment to identify valuable assets, vulnerabilities, and pathways for lateral movement.
- Occurs after initial compromise.
- Aims to map the internal network.
- Precedes lateral movement and action on objectives.
Memory trick: Remember the 'Kill Chain' as a step-by-step detective story.
DevSecOps
Flip cardAn organizational software engineering culture and practice that aims to automate, monitor, and apply security at every phase of the software development lifecycle (SDLC), from initial design through integration, testing, deployment, and software delivery.
- Integrates security into all SDLC phases.
- Automates security tasks.
- Promotes collaboration between development, security, and operations teams.
Memory trick: Think 'DevSecOps' as 'Development, Security, Operations' all working together from the start.
CAPTCHA
Flip cardA type of challenge-response test used in computing to determine whether or not the user is human. It is designed to prevent automated software (bots) from performing actions that human users would typically do.
- Distinguishes humans from bots.
- Used to prevent spam, fake accounts, and automated abuse.
- Can be image-based, text-based, or audio-based.
Memory trick: Bots are sneaky, need a clever 'CAP' to stop them.
Traffic Logs for Data Volume Analysis
Flip cardTraffic logs in Palo Alto Networks firewalls record details about network sessions, including the amount of data transferred (bytes-sent and bytes-received).
- Crucial for bandwidth usage analysis and identifying large data transfers.
- Includes fields like 'bytes-sent', 'bytes-received', 'duration', 'source', 'destination'.
- Can be filtered to investigate potential data exfiltration or unusual data patterns.
Memory trick: Traffic Logs Track Transferred Terabytes.