1. Home
  2. Palo Alto Networks
  3. NetSec-Pro Exam Syllabus

Palo Alto Networks NetSec-Pro Exam Syllabus

Start Free NetSec-Pro Exam Practice After Reviewing the Topics

Before starting your NetSec-Pro exam preparation, it is recommended to review the complete Palo Alto Networks Certified Network Security Professional exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free NetSec-Pro questions. We also provide premium NetSec-Pro practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

NetSec-Pro
Exam Code
73
Total Questions
6
Total Exam Domains

START FREE NetSec-Pro EXAM PRACTICE

NO SIGNUP REQUIRED  •  100% FREE TO START

NetSec-Pro EXAM QUESTIONS

Palo Alto Networks NetSec-Pro Exam Objectives

Section 1: Network Security Fundamentals
Weight:
17%
  • 1.1 Explain Application Layer inspection for Strata and SASE products
  • 1.2 Explain the functionality of slow path and fast path for packet inspection
  • 1.3 Explain the use of decryption on Strata and SASE products (e.g., SSL Forward Proxy, SSL Inbound Inspection, SSH Proxy, no decrypt)
  • 1.4 Explain the application of network hardening methods for enhanced security on Strata and SASE products (e.g., Content-ID, Zero Trust, User-ID, Device-ID, Zones)
Section 2: NGFW and SASE Solution Functionality
Weight:
13%
  • 2.1 Explain the function of Cloud NGFWs, PA-Series, CN-Series, and VM-Series firewalls (e.g., perimeter and core security, zone security and segmentation, high availability [HA], security and NAT policy implementation, monitoring and logging)
  • 2.2 Explain the function of Prisma SD-WAN (e.g., WAN optimization, path and NAT policies, Zone-based firewalls, monitoring and logging)
  • 2.3 Explain the function of Prisma Access (e.g., remote user configuration, remote network configuration, public and private application access, security and NAT policy implementation, monitoring and logging)
  • 2.4 Explain the functionality of Panorama and Strata Cloud Manager (SCM) for managing Strata and SASE solutions
Section 3: Platform Solutions, Services, and Tools
Weight:
30%
3.1 Explain the security efficacy of Palo Alto Networks NGFW and Prisma SASE products (e.g., security and NAT policy, User-ID, App-ID, decryption, monitoring and logging)
3.2 Explain the functionality of Cloud-Delivered Security Services (CDSS) components
  • 3.2.1 Internet of things (IoT) security
  • 3.2.2 Enterprise Data Loss Prevention (DLP)
  • 3.2.3 SaaS Security
  • 3.2.4 PAN-OS SD-WAN
  • 3.2.5 Premium GlobalProtect
  • 3.2.6 Advanced WildFire, Advanced Threat Prevention, Advanced URL Filtering, and Advanced DNS
3.3 Explain the alignment of AIOps to Palo Alto Networks best practices (e.g., dashboards, Best Practice Assessment [BPA], administration)
3.4 Explain how Next-Generation Trust Security (NGTS) supports identity governance, trust relationships, and adaptive security decisions across the enterprise platform
3.5 Identify and describe quantum security risks (e.g., harvest now, decrypt later attacks) and Palo Alto Networks platform capabilities to address them (e.g., post-quantum readiness, hybrid cryptography)
3.6 Identify and describe AI-related security risks and mitigation techniques (e.g., AI use, sensitive
data exposure, AI application access, AI-enabled threats) and explain how Palo Alto Networks
platform capabilities can help discover, monitor, control, and secure them
Section 4: NGFW and SASE Solution Maintenance and Configuration
Weight:
10%
  • 4.1 Explain the configuration and maintenance of Palo Alto Networks hardware firewalls, VM-Series firewalls, CN-Series firewalls, and Cloud NGFWs (e.g., Security policies, profiles, updates, upgrades)
  • 4.2 Explain the configuration and maintenance of Prisma Access (e.g., Security policies, profiles, updates, upgrades, monitoring and logging)
Section 5: Infrastructure Management and CDSS
Weight:
17%
  • 5.1 Explain the function of Security policies, profiles, and updates in the configuration and maintenance of CDSS
  • 5.2 Explain the function of Security policies, Device-IDs, and monitoring and logging in the configuration and maintenance of IoT security
  • 5.3 Explain the function of data encryption, access control, and monitoring and logging in the configuration and maintenance of Enterprise DLP and Enterprise SaaS Security
  • 5.4 Explain the function of supported products, new device addition, reporting, and configuration management in SCM and Panorama in network security environments
Section 6: Connectivity and Security
Weight:
13%
  • 6.1 Explain the configuration and maintenance of network security for on-premises, cloud, and hybrid networks (e.g., network segmentation, policies, monitoring and logging, certificates)
  • 6.2 Identify and describe the components used to maintain connectivity and security of remote users (e.g., remote access solutions, network segmentation, Security policy tuning, monitoring and logging, certificates)
Info