wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

practica2

Total questions: 104

Worksheet time: 3hrs 28mins

Name
Class
Date
1.

Which operation will impact performance of the management plane?

a)

DoS protection

b)

WildFire submissions

c)

generating a SaaS Application report

d)

decrypting SSL sessions

2.

Which User-ID method maps IP addresses to usernames for users connecting through a web proxy that has already authenticated the user?

a)

syslog listening

b)

server monitoring

c)

client probing

d)

port mapping

3.

The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?

a)

6-tuple match:

Source IP Address, Destination IP Address, Source port, Destination Port, Protocol, andSource SecurityZone

b)

5-tuple match:Source IP Address, Destination IP Address, Source port, Destination Port, Protocol

c)

7-tuple match:

Source IP Address, Destination IP Address, Source port, Destination Port, Source User, URLCategory,and SourceSecurityZone

d)

9-tuple match:

Source IP Address, Destination IP Address, Source port, Destination Port, Source User,SourceSecurityZone,Destination SecurityZone,Application,and URL Category

4.

Which GlobalProtect Client connect method requires the distribution and use of machine certificates?

a)

At-boot

b)

Pre-logon

c)

User-logon (Always on)

d)

On-demand

5.

Which feature can provide NGFWs with User-ID mapping information?

a)

Web Captcha

b)

Native 802.1q authentication

c)

GlobalProtect

d)

Native 802.1x authentication

6.

Which Panorama administrator types require the configuration of at least one access domain? (Choose two.)

a)

Role Based

b)

Custom Panorama Admin

c)

Device Group

d)

Dynamic

e)

Template Admin

7.

Which option enables a Palo Alto Networks NGFW administrator to schedule Application and Threat updates while applying only new content IDs to traffic?

a)

Select download-and-install

b)

Select download-only

c)

Select download-and-install, with "Disable new apps in content update" selected

d)

Select disable application updates and select "Install only Threat updates"

8.

Which is the maximum number of samples that can be submitted to WildFire per day, based on a WildFire subscription?

a)

10,000

b)

15,000

c)

7,500

d)

5,000

9.

In which two types of deployment is active/active HA configuration supported? (Choose two.)

a)

Layer 3 mode

b)

TAP mode

c)

Virtual Wire mode

d)

Layer 2 mode

10.

For which two reasons would a firewall discard a packet as part of the packet flow sequence? (Choose two.)

a)

ingress processing errors

b)

rule match with action "deny"

c)

rule match with action "allow"

d)

equal-cost multipath

11.

Which logs enable a firewall administrator to determine whether a session was decrypted?

a)

Traffic

b)

Security Policy

c)

Decryption

d)

Correlated Event

12.

An administrator needs to upgrade an NGFW to the most current version of PAN-OS?software. The following is occurring:

-  Firewall has internet connectivity through e 1/1.

-  Default security rules and security rules allowing all SSL and web- browsing traffic to and from any zone.

-  Service route is configured, sourcing update traffic from e1/1.

-  A communication error appears in the System logs when updates are performed.

-  Download does not complete.

 

What must be configured to enable the firewall to download the current version of PAN-OS software?

a)

Static route pointing application PaloAlto-updates to the update servers

b)

Security policy rule allowing PaloAlto-updates as the application

c)

Scheduler for timed downloads of PAN-OS software

d)

DNS settings for the firewall to use for resolution

13.

A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks.

 

How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?

a)

Add an Anti-Spyware Profile to block attacking IP address

b)

Define a custom App-ID to ensure that only legitimate application traffic reaches the server

c)

Add QoS Profiles to throttle incoming requests

d)

Add a tuned DoS Protection Profile

14.

An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled.

 

What must be verified to upgrade the firewalls to the most recent version of PAN-OS?software?

a)

Antivirus update package

b)

Applications and Threats update package

c)

User-ID agent

d)

WildFire update package

15.

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and- control (C2) servers.

Which Security Profile type will prevent these behaviors?

a)

Anti-Spyware

b)

WildFire

c)

Vulnerability Protection

d)

Antivirus

16.

What should an administrator consider when planning to revert Panorama to a pre-PAN-OS 8.1 version?

a)

Panorama cannot be reverted to an earlier PAN-OS release if variables are used in templates or

templatestacks

b)

An administrator must use the Expedition tool to adapt the configuration to the pre-PAN-OS 8.1 state.

c)

When Panorama is reverted to an earlier PAN-OS release, variables used in templates or template stacks will be removed automatically

d)

Administrators need to manually update variable characters to those used in pre-PAN-OS 8.1.

17.

Which two methods can be configured to validate the revocation status of a certificate? (Choose two.)

a)

CRL

b)

CRT

c)

OCSP

d)

Cert-Validation-Profile

e)

SSL/TLS Service Profile

18.

Which administrative authentication method supports authorization by an external service?

a)

Certificates

b)

LDAP

c)

RADIUS

d)

SSH keys

19.

Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)

a)

.dll

b)

.exe

c)

.fon

d)

.apk

e)

.pdf

20.

An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.

Which configuration will enable this HA scenario?

a)

The two firewalls will share a single floating IP and will use gratuitous ARP to share the floating

IP

b)

Each firewall will have a separate floating IP, and priority will determine which firewall has the primary IP

c)

The firewalls do not use floating IPs in active/active HA.

d)

The firewalls will share the same interface IP address, and device 1 will use the floating IP if device 0 fails

21.

Which version of GlobalProtect supports split tunneling based on destination domain, client process, and HTTP/HTTPS video streaming application?

a)

GlobalProtect version 4.0 with PAN-OS 8.1

b)

GlobalProtect version 4.1 with PAN-OS 8.1

c)

GlobalProtect version 4.1 with PAN-OS 8.0

d)

GlobalProtect version 4.0 with PAN-OS 8.0

22.

How does Panorama prompt VMWare NSX to quarantine an infected VM?

a)

HTTP Server Profile

b)

Syslog Server Profile

c)

Email Server Profile

d)

SNMP Server Profile

23.

An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)

a)
b)
c)
d)
24.

Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)

a)

Create a no-decrypt Decryption Policy rule.

b)

Configure an EDL to pull IP addresses of known sites resolved from a CRL

c)

Create a Dynamic Address Group for untrusted sites

d)

Create a Security Policy rule with vulnerability Security Profile attached

e)

Enable the "Block sessions with untrusted issuers" setting

25.

An administrator is defining protection settings on the Palo Alto Networks NGFW to guard against resource exhaustion. When platform utilization is considered, which steps must the administrator take to configure and apply packet buffer protection?

a)

Enable and configure the Packet Buffer protection thresholds.

EnablePacketBuffer Protection per ingresszone

b)

Enable and then configure Packet Buffer thresholds Enable Interface Buffer protection

c)

Create and Apply Zone Protection Profiles in all ingress zones. Enable Packet Buffer Protection per ingress zone

d)

Configure and apply Zone Protection Profiles for all egress zones. Enable Packet Buffer Protection pre egress zone

e)

Enable per-vsys Session Threshold alerts and triggers for Packet Buffer Limits. Enable Zone Buffer Protection per zone

26.

What is the purpose of the firewall decryption broker?

a)

decrypt SSL traffic and then send it as cleartext to a security chain of inspection tools.

b)

force decryption of previously unknown cipher suites

c)

reduce SSL traffic to a weaker cipher before sending it to a security chain of inspection tools.

d)

inspect traffic within IPsec tunnels

27.

SAML SLO is supported for which two firewall features? (Choose two.)

a)

GlobalProtect Portal

b)

CaptivePortal

c)

WebUI

d)

CLI

28.

When you configure an active/active high availability pair which two links can you use? (Choose two)

a)

HA2 backup

b)

HA3

c)

Console Backup

d)

HSCI-C

29.

Which CLI command displays the physical media that are connected to ethernetl/8?

a)

show system state filter-pretty sys.si.p8.stats

b)

show interface ethernetl/8

c)

show system state filter-pretty sys.sl.p8.phy

d)

show system state filter-pretty sys.si.p8.med

30.

In a firewall, which three decryption methods are valid? (Choose three )

a)

SSL Inbound Inspection

b)

SSL Outbound Proxyless Inspection

c)

SSL Inbound Proxy

d)

Decryption Mirror

e)

SSH Proxy

31.

The UDP-4501 protocol-port is used between which two GlobalProtect components?

a)

GlobalProtect app and GlobalProtect gateway

b)

GlobalProtect portal and GlobalProtect gateway

c)

GlobalProtect app and GlobalProtect satellite

d)

GlobalProtect app and GlobalProtect portal

32.

Users within an enterprise have been given laptops that are joined to the corporate domain. In some cases, IT has also deployed Linux-based OS systems with a graphical desktop. Information Security needs IP-to-user mapping, which it will use in group-based policies that will limit internet access for the Linux desktop users.

Which method can capture IP-to-user mapping information for users on the Linux machines?

a)

You can configure Captive Portal with an authentication policy

b)

IP-to-user mapping for Linux users can only be learned if the machine is joined to the domain.

c)

You can set up a group-based security policy to restrict internet access based on group membership

d)

You can deploy the User-ID agent on the Linux desktop machines

33.

What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three)

a)

configure a device block list

b)

rename a vsys on a multi-vsys firewall

c)

enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode

d)

add administrator accounts

e)

change the firewall management IP address

34.

A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration.

Once deployed each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.

Which VPN preconfigured configuration would adapt to changes when deployed to the future site?

a)

IPsec tunnels using IKEv2

b)

PPTP tunnels

c)

GlobalProtect satellite

d)

GlobalProtect client

35.

PBF can address which two scenarios? (Select Two)

a)

forwarding all traffic by using source port 78249 to a specific egress interface

b)

providing application connectivity the primary circuit fails

c)

enabling the firewall to bypass Layer 7 inspection

d)

routing FTP to a backup ISP link to save bandwidth on the primary ISP link

36.

In a security-first network what is the recommended threshold value for content updates to be dynamically updated?

a)

1 to 4 hours

b)

6 to 12 hours

c)

24 hours

d)

36 hours

37.

A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas):

 

i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system )

ii. Enterpnse-Untrusted-CA, which is verified as Forward Untrust Certificate

iii. Enterprise-lntermediate-CA

iv.  Enterprise-Root-CA which is verified only as Trusted Root CA

An end-user visits https //www example-website com/ with a server certificate Common Name (CN) www example-website com

The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall.

The end-user's browser will show that the certificate for www example-website com was issued by which of the following?

a)

Enterprise-Untrusted-CA which is a self-signed CA

b)

Enterprise-Trusted-CA which is a self-signed CA

c)

Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA

d)

Enterprise-Root-CA which is a self-signed CA

38.

An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls.

The firewalls will provide access to mobile users and act as edge locations to on-premises Infrastructure.

The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration.

Which two solutions can the administrator use to scale this configuration? (Choose two.)

a)

variables

b)

template stacks

c)

collector groups

d)

virtual systems

39.

A traffic log might list an application as "not-applicable" for which two reasons? (Choose two )

a)

The firewall did not install the session

b)

The TCP connection terminated without identifying any application data

c)

The firewall dropped a TCP SYN packet

d)

There was not enough application data after the TCP connection was established

40.

An administrator is considering upgrading the Palo Alto Networks NGFW and central management Panorama version.

What is considered best practice for this scenario?

a)

Perform the Panorama and firewall upgrades simultaneously

b)

Upgrade the firewall first wait at least 24 hours and then upgrade the Panorama version

c)

Upgrade Panorama to a version at or above the target firewall version

d)

Export the device state perform the update, and then import the device state

41.

When you configure a Layer 3 interface what is one mandatory step?

a)

Configure Security profiles, which need to be attached to each Layer 3 interface

b)

Configure Interface Management profiles which need to be attached to each Layer 3 interface

c)

Configure virtual routers to route the traffic for each Layer 3 interface

d)

Configure service routes to route the traffic for each Layer 3 interface

42.

An administrator has a PA-820 firewall with an active Threat Prevention subscription. The administrator is considering adding a WildFire subscription.

How does adding the WildFire subscription improve the security posture of the organization1?

a)

Protection against unknown malware can be provided in near real-time

b)

WildFire and Threat Prevention combine to provide the utmost security posture for the firewall

c)

After 24 hours WildFire signatures are included in the antivirus update

d)

WildFire and Threat Prevention combine to minimize the attack surface

43.

Which three statements accurately describe Decryption Mirror? (Choose three.)

a)

Decryption Mirror requires a tap interface on the firewall

b)

Decryption, storage, inspection and use of SSL traffic are regulated in certain countries

c)

Only management consent is required to use the Decryption Mirror feature

d)

You should consult with your corporate counsel before activating and using Decryption Mirror in a

productionenvironment

e)

Use of Decryption Mirror might enable malicious users with administrative access to the firewall to harvest sensitive information that is submitted via an encrypted channel

44.

As a best practice, which URL category should you target first for SSL decryption?

a)

Online Storage and Backup

b)

High Risk

c)

Health and Medicine

d)

Financial Services

45.

An administrator wants to enable zone protection. Before doing so, what must the administrator consider?

a)

Activate a zone protection subscription

b)

To increase bandwidth no more than one firewall interface should be connected to a zone

c)

Security policy rules do not prevent lateral movement of traffic between zones

d)

The zone protection profile will apply to all interfaces within that zone

46.

What are two characteristic types that can be defined for a variable? (Choose two)

a)

zone

b)

FQDN

c)

path group

d)

IP netmask

47.

What are three valid qualifiers for a Decryption Policy Rule match? (Choose three )

a)

Destination Zone

b)

App-ID

c)

Custom URL Category

d)

User-ID

e)

Source Interface

48.

Given the following configuration, which route is used for destination 10.10.0.4?

a)

Route 4

b)

Route 3

c)

Route 1

d)

Route 3

49.

When an in-band data port is set up to provide access to required services, what is required for an interface that is assigned to service routes?

a)

The interface must be used for traffic to the required services

b)

You must enable DoS and zone protection

c)

You must set the interface to Layer 2 Layer 3, or virtual wire

d)

You must use a static IP address

50.

What does SSL decryption require to establish a firewall as a trusted third party and to establish trust between a client and server to secure an SSL/TLS connection?

a)

link state

b)

stateful firewall connection

c)

certificates

d)

profiles

51.

When setting up a security profile which three items can you use? (Choose three )

a)

Wildfire analysis

b)

anti-ransom ware

c)

antivirus

d)

URL filtering

e)

decryption profile

52.

A variable name must start with which symbol?

a)

$

b)

&

c)

!

d)

#

53.

An administrator needs to troubleshoot a User-ID deployment. The administrator believes that there is an issue related to LDAP authentication. The administrator wants to create a packet capture on the management plane.

Which CLI command should the administrator use to obtain the packet capture for validating the configuration?

a)

ftp export mgmt-pcap from mgmt.pcap to <FTP host>

b)

scp export mgmt-pcap from mgmt.pcap to (username@host:path)

c)

scp export poap-mgmt from poap.mgmt to (username@host:path)

d)

scp export pcap from pcap to (usernameQhost:path)

54.

What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)

a)

the website matches a category that is not allowed for most users

b)

the website matches a high-risk category

c)

the web server requires mutual authentication

d)

the website matches a sensitive category

55.

During SSL decryption which three factors affect resource consumption1? (Choose three )

a)

TLS protocol version

b)

transaction size

c)

key exchange algorithm

d)

applications that use non-standard ports

e)

certificate issuer

56.

An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used.

After looking at the configuration, the administrator believes that the firewall is not using a static route.

What are two reasons why the firewall might not use a static route? (Choose two.)

a)

no install on the route

b)

duplicate static route

c)

path monitoring on the static route

d)

disabling of the static route

57.

Before you upgrade a Palo Alto Networks NGFW what must you do?

a)

Make sure that the PAN-OS support contract is valid for at least another year

b)

Export a device state of the firewall

c)

Make sure that the firewall is running a version of antivirus software and a version of WildFire that support the licensed subscriptions.

d)

Make sure that the firewall is running a supported version of the app + threat update

58.

Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?

a)

PAN-OS integrated User-ID agent

b)

LDAP Server Profile configuration

c)

GlobalProtect

d)

Windows-based User-ID agent

59.

Given the following snippet of a WildFire submission log. did the end-user get access to the requested information and why or why not?

a)

Yes. because the action is set to "allow''

b)

No because WildFire categorized a file with the verdict "malicious"

c)

Yes because the action is set to "alert"

d)

No because WildFire classified the seventy as "high."

60.

An administrator needs to gather information about the CPU utilization on both the management plane and the data plane.

Where does the administrator view the desired data?

a)

Monitor > Utilization

b)

Resources Widget on the Dashboard

c)

Support > Resources

d)

Application Command and Control Center

61.

Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?

a)

Create a zone protection profile with flood protection configured to defend an entire egress zone

againstSYN, ICMP,ICMPv6,UDP,andother IPflood attacks

b)

Add a WildFire subscription to activate DoS and zone protection features.

c)

Replace the hardware firewall, because DoS and zone protection are not available with VM- Series systems

d)

Measure and monitor the CPU consumption of the firewall data plane to ensure that each firewall is properly sized to support DoS and zone protection

62.

An administrator receives the following error message:

"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192.168.33.33/24 type IPv4 address protocol 0 port 0, received remote id 172.16.33.33/24 type IPv4 address protocol 0 port 0."

 

How should the administrator identify the root cause of this error message?

a)

Verify that the IP addresses can be pinged and that routing issues are not causing the connection

failure

b)

Check whether the VPN peer on one end is set up correctly using policy-based VPN

c)

In the IKE Gateway configuration, verify that the IP address for each VPN peer is accurate

d)

In the IPSec Crypto profile configuration, verify that PFS is either enabled on both VPN peers or disabled on both VPN peers

63.

The following objects and policies are defined in a device group hierarchy.

Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group NYC-DC has NYC-FW as a member of the NYC-DC device-group

What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?

a)

Address Objects

-  Shared Address1

-  Branch Address1 Policies

-  Shared Policy1

BranchPolicy1

b)

Address Objects

-Shared Address1

-  Shared Address2

-  Branch Address1 Policies

-  Shared Policy1

-  Shared Policy2

BranchPolicy1

c)

Address Objects

-  Shared Address1

-  Shared Address2

-  Branch Address1

-  DC Address1 Policies

-  Shared Policy1

-  Shared Policy2

BranchPolicy1

d)

Address Objects

-  Shared Address1

-  Shared Address2

-  Branch Address1 Policies

-  Shared Policy1

BranchPolicy1

64.

An administrator has purchased WildFire subscriptions for 90 firewalls globally. What should the administrator consider with regards to the WildFire infrastructure?

a)

To comply with data privacy regulations, WildFire signatures and verdicts are not shared globally.

b)

Palo Alto Networks owns and maintains one global cloud and four WildFire regional clouds.

c)

Each WildFire cloud analyzes samples and generates malware signatures and verdicts independently of the other WildFire clouds

d)

The WildFire Global Cloud only provides bare metal analysis

65.

What are three reasons for excluding a site from SSL decryption? (Choose three.)

a)

the website is not present in English

b)

unsupported ciphers

c)

certificate pinning

d)

unsupported browser version

e)

mutual authentication

66.

What are three types of Decryption Policy rules? (Choose three.)

a)

SSL Inbound Inspection

b)

SSH Proxy

c)

SSL Forward Proxy

d)

Decryption Broker

e)

Decryption Mirror

67.

Which two features require another license on the NGFW? (Choose two.)

a)

SSL Inbound Inspection

b)

SSL Forward Proxy

c)

Decryption Mirror

d)

Decryption Broker

68.

A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)

a)

Permitted IP Addresses

b)

SSH

c)

https

d)

User-ID

e)

HTTP

69.

A customer is replacing its legacy remote-access VPN solution. Prisma Access has been selected as the replacement. During onboarding, the following options and licenses were selected and enabled:

-  Prisma Access for Remote Networks: 300Mbps

-  Prisma Access for Mobile Users: 1500 Users

-  Cortex Data Lake: 2TB

-  Trusted Zones: trust

-  Untrusted Zones: untrust

-  Parent Device Group: shared

 

The customer wants to forward to a Splunk SIEM the logs that are generated by users that are connected to Prisma Access for Mobile Users.

Which two settings must the customer configure? (Choose two.)

a)

Configure Panorama Collector group device log forwarding to send logs to the Splunk syslog

server.

b)

Configure Cortex Data Lake log forwarding and add the Splunk syslog server.

c)

Configure a log forwarding profile and select the Panorama/Cortex Data Lake checkbox. Apply the Log

Forwardingprofile to allofthesecuritypolicy rules inMobile_User_Device_Group.

d)

Configure a Log Forwarding profile, select the syslog checkbox, and add the Splunk syslog

server. Apply the Log Forwarding profile to all of the security policy rules in theMobile_User_Device_Group.

70.

Using multiple templates in a stack to manage many firewalls provides which two advantages? (Choose two.)

a)

inherit address-objects from templates

b)

define a common standard template configuration for firewalls

c)

standardize server profiles and authentication configuration across all stacks

d)

standardize log-forwarding profiles for security polices across all stacks

71.

Refer to the diagram. An administrator needs to create an address object that will be useable by the NYC. MA, CA and WA device groups.

Where will the object need to be created within the device-group hierarchy?

a)

Americas

b)

US

c)

East

d)

West

72.

You need to allow users to access the office-suite applications of their choice.

How should you configure the firewall to allow access to any office-suite application?

a)

Create an Application Group and add Office 365, Evernote Google Docs and Libre Office

b)

Create an Application Group and add business-systems to it

c)

Create an Application Filter and name it Office Programs, then filter it on the office programs subcategory.

d)

Create an Application Filter and name it Office Programs then filter on the business-systems category.

73.

A network administrator wants to deploy GlobalProtect with pre-logon for Windows 10 endpoints and follow Palo Alto Networks best practices.

To install the certificate and key for an endpoint, which three components are required? (Choose three.)

a)

server certificate

b)

local computer store

c)

private key

d)

self-signed certificate

e)

machine certificate

74.

To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?

a)

Add the policy in the shared device group as a pre-rule

b)

Reference the targeted device's templates in the target device group

c)

Add the policy to the target device group and apply a master device to the device group

d)

Clone the security policy and add it to the other device groups

75.

Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?

a)

No Direct Access to local networks

b)

Satellite mode

c)

Tunnel mode

d)

IPSec mode

76.

Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two)

a)

Dos Protection policy

b)

QoS Profile

c)

Zone Protection Profile

d)

DoS Protection Profile

77.

An administrator is attempting to create policies tor deployment of a device group and template stack.

When creating the policies, the zone drop down list does not include the required zone. What must the administrator do to correct this issue?

a)

Specify the target device as the master device in the device group

b)

Enable "Share Unused Address and Service Objects with Devices" in Panorama settings

c)

Add the template as a reference template in the device group

d)

Add a firewall to both the device group and the template

78.

An administrator is building Security rules within a device group to block traffic to and from malicious locations.

How should those rules be configured to ensure that they are evaluated with a high priority?

a)

Create the appropriate rules with a Block action and apply them at the top of the Default Rules

b)

Create the appropriate rules with a Block action and apply them at the top of the Security Post- Rules.

c)

Create the appropriate rules with a Block action and apply them at the top of the local firewall Security rules

d)

Create the appropriate rules with a Block action and apply them at the top of the Security Pre- Rules

79.

An engineer is in the planning stages of deploying User-ID in a diverse directory services environment.

Which server OS platforms can be used for server monitoring with User-ID?

a)

Microsoft Terminal Server, Red Hat Linux, and Microsoft Active Directory

b)

Microsoft Active Directory, Red Hat Linux, and Microsoft Exchange

c)

Microsoft Exchange, Microsoft Active Directory, and Novell eDirectory

d)

Novell eDirectory, Microsoft Terminal Server, and Microsoft Active Directory

80.

Your company has to Active Directory domain controllers spread across multiple WAN links. All users authenticate to Active Directory Each link has substantial network bandwidth to support all mission-critical applications. The firewalls management plane is highly utilized.

Given this scenario which type of User-ID agent is considered a best practice by Palo Alto Networks?

a)

PAN-OS integrated agent

b)

Captive Portal

c)

Citrix terminal server agent with adequate data-plane resources

d)

Windows-based User-ID agent on a standalone server

81.

A customer is replacing their legacy remote access VPN solution. The current solution is in place to secure only internet egress for the connected clients.

Prisma Access has been selected to replace the current remote access VPN solution. During onboarding the following options and licenses were selected and enabled:

-  Prisma Access for Remote Networks 300Mbps

-  Prisma Access for Mobile Users 1500 Users

-  Cortex Data Lake 2TB

-  Trusted Zones trust

-  Untrusted Zones untrust

-  Parent Device Group shared

 

How can you configure Prisma Access to provide the same level of access as the current VPN solution?

a)

Configure mobile users with trust-to-untrust Security policy rules to allow the desired traffic

outboundto the internet

b)

Configure mobile users with a service connection and trust-to-trust Security policy rules to allow the desired traffic outbound to the internet

c)

Configure remote networks with a service connection and trust-to-untrust Security policy rules to allow the desired traffic outbound to the internet

d)

Configure remote networks with trust-to-trust Security policy rules to allow the desired traffic outbound to the internet

82.

What best describes the HA Promotion Hold Time?

a)

the time that is recommended to avoid an HA failover due to the occasional flapping of neighboring

devices

b)

the time that is recommended to avoid a failover when both firewalls experience the same link/path monitor failure simultaneously

c)

the time that the passive firewall will wait before taking over as the active firewall after communications with the HA peer have been lost

d)

the time that a passive firewall with a low device priority will wait before taking over as the active firewall if the firewall is operational again

83.

During the process of developing a decryption strategy and evaluating which websites are required for corporate users to access, several sites have been identified that cannot be decrypted due to technical reasons.

In this case, the technical reason is unsupported ciphers. Traffic to these sites will therefore be blocked if decrypted.

How should the engineer proceed?

a)

Allow the firewall to block the sites to improve the security posture

b)

Add the sites to the SSL Decryption Exclusion list to exempt them from decryption

c)

Install the unsupported cipher into the firewall to allow the sites to be decrypted

d)

Create a Security policy to allow access to those sites

84.

When using certificate authentication for firewall administration, which method is used for authorization?

a)

Radius

b)

LDAP

c)

Kerberos

d)

Local

85.

When you navigate to Network: > GlobalProtect > Portals > Method section, which three options are available? (Choose three )

a)

user-logon (always on)

b)

pre-logon then on-demand

c)

on-demand (manual user initiated connection)

d)

post-logon (always on)

e)

certificate-logon

86.

An administrator analyzes the following portion of a VPN system log and notices the following issue "Received local id 10.10.1.4/24 type IPv4 address protocol 0 port 0, received remote id 10.1.10.4/24 type IPv4 address protocol 0 port 0."

What is the cause of the issue?

a)

IPSec crypto profile mismatch

b)

IPSec protocol mismatch

c)

mismatched Proxy-IDs

d)

bad local and peer identification IP addresses in the IKE gateway

87.

What is considered the best practice with regards to zone protection?

a)

Review DoS threat activity (ACC > Block Activity) and look for patterns of abuse

b)

Use separate log-forwarding profiles to forward DoS and zone threshold event logs separately from other threat logs

c)

If the levels of zone and DoS protection consume too many firewall resources, disable zone protection

d)

Set the Alarm Rate threshold for event-log messages to high severity or critical severity

88.

An engineer wants to implement the Palo Alto Networks firewall in VWire mode on the internet gateway and wants to be sure of the functions that are supported on the vwire interface. What are three supported functions on the VWire interface? (Choose three )

a)

NAT

b)

QoS

c)

IPSec

d)

OSPF

e)

SSL Decryption

89.

An administrator needs to build Security rules in a Device Group that allow traffic to specific users and groups defined in Active Directory.

What must be configured in order to select users and groups for those rules from Panorama?

a)

The Security rules must be targeted to a firewall in the device group and have Group Mapping

configured

b)

A master device with Group Mapping configured must be set in the device group where the

Securityrulesare configured

c)

User-ID Redistribution must be configured on Panorama to ensure that all firewalls have the same mappings

d)

A User-ID Certificate profile must be configured on Panorama

90.

Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three )

a)

The environment requires real, full-time redundancy from both firewalls at all times

b)

The environment requires Layer 2 interfaces in the deployment

c)

The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence

d)

The environment requires that all configuration must be fully synchronized between both members of the HA pair

e)

The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes

91.

Which protocol is supported by GlobalProtect Clientless VPN?

a)

HTTPS

b)

FTP

c)

RDP

d)

SSH

92.

Cortex XDR notifies an administrator about grayware on the endpoints. There are no entnes about grayware in any of the logs of the corresponding firewall.

Which setting can the administrator configure on the firewall to log grayware verdicts?

a)

within the log settings option in the Device tab

b)

within the log forwarding profile attached to the Security policy rule

c)

in WildFire General Settings, select "Report Grayware Files"

d)

in Threat General Settings, select "Report Grayware Files"

93.

What would allow a network security administrator to authenticate and identify a user with a new BYOD-type device that is not joined to the corporate domain'?

a)

a Security policy with 'known-user" selected in the Source User field

b)

an Authentication policy with 'unknown' selected in the Source User field

c)

a Security policy with 'unknown' selected in the Source User field

d)

an Authentication policy with 'known-user' selected in the Source User field

94.

Which statement is correct given the following message from the PanGPA log on the GlobalProtect app?

Failed to connect to server at port:4767

a)

The PanGPS process failed to connect to the PanGPA process on port 4767

b)

The GlobalProtect app failed to connect to the GlobalProtect Portal on port 4767

c)

The PanGPA process failed to connect to the PanGPS process on port 4767

d)

The GlobalProtect app failed to connect to the GlobalProtect Gateway on port 4767

95.

Which GlobalProtect component must be configured to enable Chentless VPN?

a)

GlobalProtect satellite

b)

GlobalProtect app

c)

GlobalProtect portal

d)

GlobalProtect gateway

96.

A network security engineer must implement Quality of Service policies to ensure specific levels of delivery guarantees for various applications in the environment.

]They want to ensure that they know as much as they can about QoS before deploying. Which statement about the QoS feature is correct?

a)

QoS is only supported on firewalls that have a single virtual system configured

b)

QoS can be used in conjunction with SSL decryption

c)

QoS is only supported on hardware firewalls

d)

QoS can be used on firewalls with multiple virtual systems configured

97.

Which statement regarding HA timer settings is true?

a)

Use the Recommended profile for typical failover timer settings

b)

Use the Moderate profile for typical failover timer settings

c)

Use the Aggressive profile for slower failover timer settings

d)

Use the Critical profile for faster failover timer settings

98.

What is the best description of the HA4 Keep-Alive Threshold (ms)?

a)

the maximum interval between hello packets that are sent to verify that the HA functionality on the

otherfirewallisoperational

b)

The time that a passive or active-secondary firewall will wait before taking over as the active or active-primary firewall

c)

the timeframe within which the firewall must receive keepalives from a cluster member to know that the cluster member is functional

d)

The timeframe that the local firewall wait before going to Active state when another cluster member is preventing the cluster from fully synchronizing

99.

Where is information about packet buffer protection logged?

a)

Alert entries are in the Alarms log Entries for dropped traffic, discarded sessions, and blocked IP

addressare in the Threatlog

b)

All entries are in the System log

c)

Alert entries are in the System log Entries for dropped traffic, discarded sessions and blocked IP addresses are in the Threat log

d)

All entries are in the Alarms log

100.

An administrator needs firewall access on a trusted interface. Which two components are required to configure certificate based, secure authentication to the web Ul? (Choose two )

a)

certificate profile

b)

server certificate

c)

SSH Service Profile

d)

SSL/TLS Service Profile

101.

When planning to configure SSL Froward Proxy on a PA 5260, a user asks how SSL decryption can be implemented using phased approach in alignment with Palo Alto Networks best practices What should you recommend?

a)

Enable SSL decryption for known malicious source IP addresses

b)

Enable SSL decryption for source users and known malicious URL categories

c)

Enable SSL decryption for malicious source users

d)

Enable SSL decryption for known malicious destination IP addresses

102.

A prospect is eager to conduct a Security Lifecycle Review (SLR) with the aid of the Palo Alto Networks NGFW.

Which interface type is best suited to provide the raw data for an SLR from the network in a way that is minimally invasive?

a)

Layer 3

b)

Virtual Wire

c)

Tap

d)

Layer 2

103.

A user at an internal system queries the DNS server for their web server with a private IP of 10.250.241.131 in the webserver.

The DNS server returns an address of the web server's public address 200.1.1.10.

In order to reach the web server, which security rule and U-Turn NAT rule must be configured on the firewall?

a)
b)
c)
d)
104.

An administrator allocates bandwidth to a Prisma Access Remote Networks compute location with three remote networks.

What is the minimum amount of bandwidth the administrator could configure at the compute location?

a)

90Mbps

b)

300 Mbps

c)

75Mbps

d)

50Mbps