NetSec-Pro ยท Final Exam Prep
Final Exam Attack Plan
Domain weights, policy evaluation decision maps, security profile guide, NAT trap catalogue, IPsec VPN tree, 7-day protocol, and 20 rapid-recall cards.
| Domain | Weight | Priority | Key Focus Areas |
|---|---|---|---|
| D3 Platform Solutions & CDSS | 30% | ๐ด Highest | WildFire, Advanced URL Filtering, Threat Prevention, DNS Security, IoT/CDSS efficacy |
| D1 Network Security Fundamentals | 17% | ๐ด Highest | SP3 packet flow, zones, App-ID, User-ID, decryption concepts |
| D5 Infrastructure Management | 17% | ๐ High | Panorama, templates, device groups, rule push order, SCM |
| D6 Connectivity & Security | 13% | ๐ High | GlobalProtect, Prisma Access, site-to-site VPN, SD-WAN integration |
| D2 NGFW & SASE Functionality | 13% | ๐ก Medium | VM-Series, CN-Series, SASE architecture, cloud NGFW placement |
| D4 Maintenance & Configuration | 10% | ๐ก Medium | Commit/validate, upgrades, HA, logging, operational troubleshooting |
Exam profile: 75 questions ยท 90 minutes ยท 86% pass mark (860/1000) ยท scenario-driven single- and multi-select items.
Four Unbreakable Rules:
- Policy rule order = top to bottom, first match wins (always)
- NAT is evaluated BEFORE security policy; post-NAT zone is used for policy matching
- Security profiles ONLY apply to Allow rules โ never Deny rules
- All changes require a Commit โ no exceptions, including password changes
Remember: Security profiles have NO effect on Deny rules. All profiles require SSL Decryption for HTTPS traffic inspection.
web-browsing โ HTTPS: 'web-browsing' = HTTP/TCP-80. 'ssl' = HTTPS. Allowing only 'web-browsing' does NOT allow HTTPS. Always include 'ssl' for HTTPS access.
App-ID reclassification: If a session is allowed as 'ssl' and reclassified to 'google-drive-web', the session is blocked if google-drive-web isn't allowed. Include dependent apps.
Profiles on Deny rules = useless: The most common trap. Attaching Antivirus/IPS/URL to a Deny rule = zero inspection. Only Allow rules execute profiles.
User-ID on untrust zone: NEVER. Attackers can spoof IP-to-user mappings from outside, bypassing user-based policies. Internal zones only.
WildFire = async delivery: Standard WildFire delivers the file THEN analyses. The file reaches the user before the verdict returns. WildFire Inline ML blocks synchronously.
No-Decrypt ABOVE Decrypt: Decryption policy is top-to-bottom. No-Decrypt rule for banking must be ABOVE the general Decrypt rule or it never matches.
IKE Phase 1 โ ONE mismatch = total failure: All parameters (encryption, hash, DH group, lifetime, IKE version) must match. SHA-256 โ SHA-1 = Phase 1 fails.
U-Turn NAT needs SNAT too: Without source NAT in U-Turn, the internal server replies directly to the client, causing a TCP session mismatch.
| Day | Focus | Activity |
|---|---|---|
| Day 7 | D3 Platform/CDSS (30%) | WildFire, URL Filtering, Threat Prevention, DNS Security โ highest-weight domain |
| Day 6 | D1 Fundamentals + D6 Connectivity | Packet flow, zones, GlobalProtect, Prisma Access, VPN |
| Day 5 | D5 Infrastructure + D2 SASE | Panorama rule order, templates, VM-Series, SASE architecture |
| Day 4 | D4 Maintenance + Sequence Exam | Commit/validate, HA, upgrades โ then Configuration Sequence Exam |
| Day 3 | Mock Set A (Exam Simulation) | Full 75-question timed mock in strict mode โ identify weak domains |
| Day 2 | Mock Set B + Focused Practice | Second full mock + focused exam on wrong answers from Set A |
| Day 1 | Exam Prep + Rapid Recall | Exam Prep (75 questions, includes multi-select) + cheatsheet + flashcards โ then rest |