Font size
Worksheetspractica2
Total questions: 104
Worksheet time: 3hrs 28mins
Which operation will impact performance of the management plane?
DoS protection
WildFire submissions
generating a SaaS Application report
decrypting SSL sessions
Which User-ID method maps IP addresses to usernames for users connecting through a web proxy that has already authenticated the user?
syslog listening
server monitoring
client probing
port mapping
The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?
6-tuple match:
Source IP Address, Destination IP Address, Source port, Destination Port, Protocol, andSource SecurityZone
5-tuple match:Source IP Address, Destination IP Address, Source port, Destination Port, Protocol
7-tuple match:
Source IP Address, Destination IP Address, Source port, Destination Port, Source User, URLCategory,and SourceSecurityZone
9-tuple match:
Source IP Address, Destination IP Address, Source port, Destination Port, Source User,SourceSecurityZone,Destination SecurityZone,Application,and URL Category
Which GlobalProtect Client connect method requires the distribution and use of machine certificates?
At-boot
Pre-logon
User-logon (Always on)
On-demand
Which feature can provide NGFWs with User-ID mapping information?
Web Captcha
Native 802.1q authentication
GlobalProtect
Native 802.1x authentication
Which Panorama administrator types require the configuration of at least one access domain? (Choose two.)
Role Based
Custom Panorama Admin
Device Group
Dynamic
Template Admin
Which option enables a Palo Alto Networks NGFW administrator to schedule Application and Threat updates while applying only new content IDs to traffic?
Select download-and-install
Select download-only
Select download-and-install, with "Disable new apps in content update" selected
Select disable application updates and select "Install only Threat updates"
Which is the maximum number of samples that can be submitted to WildFire per day, based on a WildFire subscription?
10,000
15,000
7,500
5,000
In which two types of deployment is active/active HA configuration supported? (Choose two.)
Layer 3 mode
TAP mode
Virtual Wire mode
Layer 2 mode
For which two reasons would a firewall discard a packet as part of the packet flow sequence? (Choose two.)
ingress processing errors
rule match with action "deny"
rule match with action "allow"
equal-cost multipath
Which logs enable a firewall administrator to determine whether a session was decrypted?
Traffic
Security Policy
Decryption
Correlated Event
An administrator needs to upgrade an NGFW to the most current version of PAN-OS?software. The following is occurring:
- Firewall has internet connectivity through e 1/1.
- Default security rules and security rules allowing all SSL and web- browsing traffic to and from any zone.
- Service route is configured, sourcing update traffic from e1/1.
- A communication error appears in the System logs when updates are performed.
- Download does not complete.
What must be configured to enable the firewall to download the current version of PAN-OS software?
Static route pointing application PaloAlto-updates to the update servers
Security policy rule allowing PaloAlto-updates as the application
Scheduler for timed downloads of PAN-OS software
DNS settings for the firewall to use for resolution
A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks.
How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?
Add an Anti-Spyware Profile to block attacking IP address
Define a custom App-ID to ensure that only legitimate application traffic reaches the server
Add QoS Profiles to throttle incoming requests
Add a tuned DoS Protection Profile
An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled.
What must be verified to upgrade the firewalls to the most recent version of PAN-OS?software?
Antivirus update package
Applications and Threats update package
User-ID agent
WildFire update package
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and- control (C2) servers.
Which Security Profile type will prevent these behaviors?
Anti-Spyware
WildFire
Vulnerability Protection
Antivirus
What should an administrator consider when planning to revert Panorama to a pre-PAN-OS 8.1 version?
Panorama cannot be reverted to an earlier PAN-OS release if variables are used in templates or
templatestacks
An administrator must use the Expedition tool to adapt the configuration to the pre-PAN-OS 8.1 state.
When Panorama is reverted to an earlier PAN-OS release, variables used in templates or template stacks will be removed automatically
Administrators need to manually update variable characters to those used in pre-PAN-OS 8.1.
Which two methods can be configured to validate the revocation status of a certificate? (Choose two.)
CRL
CRT
OCSP
Cert-Validation-Profile
SSL/TLS Service Profile
Which administrative authentication method supports authorization by an external service?
Certificates
LDAP
RADIUS
SSH keys
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
.dll
.exe
.fon
.apk
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.
Which configuration will enable this HA scenario?
The two firewalls will share a single floating IP and will use gratuitous ARP to share the floating
IP
Each firewall will have a separate floating IP, and priority will determine which firewall has the primary IP
The firewalls do not use floating IPs in active/active HA.
The firewalls will share the same interface IP address, and device 1 will use the floating IP if device 0 fails
Which version of GlobalProtect supports split tunneling based on destination domain, client process, and HTTP/HTTPS video streaming application?
GlobalProtect version 4.0 with PAN-OS 8.1
GlobalProtect version 4.1 with PAN-OS 8.1
GlobalProtect version 4.1 with PAN-OS 8.0
GlobalProtect version 4.0 with PAN-OS 8.0
How does Panorama prompt VMWare NSX to quarantine an infected VM?
HTTP Server Profile
Syslog Server Profile
Email Server Profile
SNMP Server Profile
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)
Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)
Create a no-decrypt Decryption Policy rule.
Configure an EDL to pull IP addresses of known sites resolved from a CRL
Create a Dynamic Address Group for untrusted sites
Create a Security Policy rule with vulnerability Security Profile attached
Enable the "Block sessions with untrusted issuers" setting
An administrator is defining protection settings on the Palo Alto Networks NGFW to guard against resource exhaustion. When platform utilization is considered, which steps must the administrator take to configure and apply packet buffer protection?
Enable and configure the Packet Buffer protection thresholds.
EnablePacketBuffer Protection per ingresszone
Enable and then configure Packet Buffer thresholds Enable Interface Buffer protection
Create and Apply Zone Protection Profiles in all ingress zones. Enable Packet Buffer Protection per ingress zone
Configure and apply Zone Protection Profiles for all egress zones. Enable Packet Buffer Protection pre egress zone
Enable per-vsys Session Threshold alerts and triggers for Packet Buffer Limits. Enable Zone Buffer Protection per zone
What is the purpose of the firewall decryption broker?
decrypt SSL traffic and then send it as cleartext to a security chain of inspection tools.
force decryption of previously unknown cipher suites
reduce SSL traffic to a weaker cipher before sending it to a security chain of inspection tools.
inspect traffic within IPsec tunnels
SAML SLO is supported for which two firewall features? (Choose two.)
GlobalProtect Portal
CaptivePortal
WebUI
CLI
When you configure an active/active high availability pair which two links can you use? (Choose two)
HA2 backup
HA3
Console Backup
HSCI-C
Which CLI command displays the physical media that are connected to ethernetl/8?
show system state filter-pretty sys.si.p8.stats
show interface ethernetl/8
show system state filter-pretty sys.sl.p8.phy
show system state filter-pretty sys.si.p8.med
In a firewall, which three decryption methods are valid? (Choose three )
SSL Inbound Inspection
SSL Outbound Proxyless Inspection
SSL Inbound Proxy
Decryption Mirror
SSH Proxy
The UDP-4501 protocol-port is used between which two GlobalProtect components?
GlobalProtect app and GlobalProtect gateway
GlobalProtect portal and GlobalProtect gateway
GlobalProtect app and GlobalProtect satellite
GlobalProtect app and GlobalProtect portal
Users within an enterprise have been given laptops that are joined to the corporate domain. In some cases, IT has also deployed Linux-based OS systems with a graphical desktop. Information Security needs IP-to-user mapping, which it will use in group-based policies that will limit internet access for the Linux desktop users.
Which method can capture IP-to-user mapping information for users on the Linux machines?
You can configure Captive Portal with an authentication policy
IP-to-user mapping for Linux users can only be learned if the machine is joined to the domain.
You can set up a group-based security policy to restrict internet access based on group membership
You can deploy the User-ID agent on the Linux desktop machines
What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three)
configure a device block list
rename a vsys on a multi-vsys firewall
enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode
add administrator accounts
change the firewall management IP address
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration.
Once deployed each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.
Which VPN preconfigured configuration would adapt to changes when deployed to the future site?
IPsec tunnels using IKEv2
PPTP tunnels
GlobalProtect satellite
GlobalProtect client
PBF can address which two scenarios? (Select Two)
forwarding all traffic by using source port 78249 to a specific egress interface
providing application connectivity the primary circuit fails
enabling the firewall to bypass Layer 7 inspection
routing FTP to a backup ISP link to save bandwidth on the primary ISP link
In a security-first network what is the recommended threshold value for content updates to be dynamically updated?
1 to 4 hours
6 to 12 hours
24 hours
36 hours
A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas):
i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system )
ii. Enterpnse-Untrusted-CA, which is verified as Forward Untrust Certificate
iii. Enterprise-lntermediate-CA
iv. Enterprise-Root-CA which is verified only as Trusted Root CA
An end-user visits https //www example-website com/ with a server certificate Common Name (CN) www example-website com
The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall.
The end-user's browser will show that the certificate for www example-website com was issued by which of the following?
Enterprise-Untrusted-CA which is a self-signed CA
Enterprise-Trusted-CA which is a self-signed CA
Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
Enterprise-Root-CA which is a self-signed CA
An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls.
The firewalls will provide access to mobile users and act as edge locations to on-premises Infrastructure.
The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration.
Which two solutions can the administrator use to scale this configuration? (Choose two.)
variables
template stacks
collector groups
virtual systems
A traffic log might list an application as "not-applicable" for which two reasons? (Choose two )
The firewall did not install the session
The TCP connection terminated without identifying any application data
The firewall dropped a TCP SYN packet
There was not enough application data after the TCP connection was established
An administrator is considering upgrading the Palo Alto Networks NGFW and central management Panorama version.
What is considered best practice for this scenario?
Perform the Panorama and firewall upgrades simultaneously
Upgrade the firewall first wait at least 24 hours and then upgrade the Panorama version
Upgrade Panorama to a version at or above the target firewall version
Export the device state perform the update, and then import the device state
When you configure a Layer 3 interface what is one mandatory step?
Configure Security profiles, which need to be attached to each Layer 3 interface
Configure Interface Management profiles which need to be attached to each Layer 3 interface
Configure virtual routers to route the traffic for each Layer 3 interface
Configure service routes to route the traffic for each Layer 3 interface
An administrator has a PA-820 firewall with an active Threat Prevention subscription. The administrator is considering adding a WildFire subscription.
How does adding the WildFire subscription improve the security posture of the organization1?
Protection against unknown malware can be provided in near real-time
WildFire and Threat Prevention combine to provide the utmost security posture for the firewall
After 24 hours WildFire signatures are included in the antivirus update
WildFire and Threat Prevention combine to minimize the attack surface
Which three statements accurately describe Decryption Mirror? (Choose three.)
Decryption Mirror requires a tap interface on the firewall
Decryption, storage, inspection and use of SSL traffic are regulated in certain countries
Only management consent is required to use the Decryption Mirror feature
You should consult with your corporate counsel before activating and using Decryption Mirror in a
productionenvironment
Use of Decryption Mirror might enable malicious users with administrative access to the firewall to harvest sensitive information that is submitted via an encrypted channel
As a best practice, which URL category should you target first for SSL decryption?
Online Storage and Backup
High Risk
Health and Medicine
Financial Services
An administrator wants to enable zone protection. Before doing so, what must the administrator consider?
Activate a zone protection subscription
To increase bandwidth no more than one firewall interface should be connected to a zone
Security policy rules do not prevent lateral movement of traffic between zones
The zone protection profile will apply to all interfaces within that zone
What are two characteristic types that can be defined for a variable? (Choose two)
zone
FQDN
path group
IP netmask
What are three valid qualifiers for a Decryption Policy Rule match? (Choose three )
Destination Zone
App-ID
Custom URL Category
User-ID
Source Interface
Given the following configuration, which route is used for destination 10.10.0.4?
Route 4
Route 3
Route 1
Route 3
When an in-band data port is set up to provide access to required services, what is required for an interface that is assigned to service routes?
The interface must be used for traffic to the required services
You must enable DoS and zone protection
You must set the interface to Layer 2 Layer 3, or virtual wire
You must use a static IP address
What does SSL decryption require to establish a firewall as a trusted third party and to establish trust between a client and server to secure an SSL/TLS connection?
link state
stateful firewall connection
certificates
profiles
When setting up a security profile which three items can you use? (Choose three )
Wildfire analysis
anti-ransom ware
antivirus
URL filtering
decryption profile
A variable name must start with which symbol?
$
&
!
#
An administrator needs to troubleshoot a User-ID deployment. The administrator believes that there is an issue related to LDAP authentication. The administrator wants to create a packet capture on the management plane.
Which CLI command should the administrator use to obtain the packet capture for validating the configuration?
ftp export mgmt-pcap from mgmt.pcap to <FTP host>
scp export mgmt-pcap from mgmt.pcap to (username@host:path)
scp export poap-mgmt from poap.mgmt to (username@host:path)
scp export pcap from pcap to (usernameQhost:path)
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
the website matches a category that is not allowed for most users
the website matches a high-risk category
the web server requires mutual authentication
the website matches a sensitive category
During SSL decryption which three factors affect resource consumption1? (Choose three )
TLS protocol version
transaction size
key exchange algorithm
applications that use non-standard ports
certificate issuer
An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used.
After looking at the configuration, the administrator believes that the firewall is not using a static route.
What are two reasons why the firewall might not use a static route? (Choose two.)
no install on the route
duplicate static route
path monitoring on the static route
disabling of the static route
Before you upgrade a Palo Alto Networks NGFW what must you do?
Make sure that the PAN-OS support contract is valid for at least another year
Export a device state of the firewall
Make sure that the firewall is running a version of antivirus software and a version of WildFire that support the licensed subscriptions.
Make sure that the firewall is running a supported version of the app + threat update
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
PAN-OS integrated User-ID agent
LDAP Server Profile configuration
GlobalProtect
Windows-based User-ID agent
Given the following snippet of a WildFire submission log. did the end-user get access to the requested information and why or why not?
Yes. because the action is set to "allow''
No because WildFire categorized a file with the verdict "malicious"
Yes because the action is set to "alert"
No because WildFire classified the seventy as "high."
An administrator needs to gather information about the CPU utilization on both the management plane and the data plane.
Where does the administrator view the desired data?
Monitor > Utilization
Resources Widget on the Dashboard
Support > Resources
Application Command and Control Center
Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?
Create a zone protection profile with flood protection configured to defend an entire egress zone
againstSYN, ICMP,ICMPv6,UDP,andother IPflood attacks
Add a WildFire subscription to activate DoS and zone protection features.
Replace the hardware firewall, because DoS and zone protection are not available with VM- Series systems
Measure and monitor the CPU consumption of the firewall data plane to ensure that each firewall is properly sized to support DoS and zone protection
An administrator receives the following error message:
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192.168.33.33/24 type IPv4 address protocol 0 port 0, received remote id 172.16.33.33/24 type IPv4 address protocol 0 port 0."
How should the administrator identify the root cause of this error message?
Verify that the IP addresses can be pinged and that routing issues are not causing the connection
failure
Check whether the VPN peer on one end is set up correctly using policy-based VPN
In the IKE Gateway configuration, verify that the IP address for each VPN peer is accurate
In the IPSec Crypto profile configuration, verify that PFS is either enabled on both VPN peers or disabled on both VPN peers
The following objects and policies are defined in a device group hierarchy.
Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group NYC-DC has NYC-FW as a member of the NYC-DC device-group
What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?
Address Objects
- Shared Address1
- Branch Address1 Policies
- Shared Policy1
BranchPolicy1
Address Objects
-Shared Address1
- Shared Address2
- Branch Address1 Policies
- Shared Policy1
- Shared Policy2
BranchPolicy1
Address Objects
- Shared Address1
- Shared Address2
- Branch Address1
- DC Address1 Policies
- Shared Policy1
- Shared Policy2
BranchPolicy1
Address Objects
- Shared Address1
- Shared Address2
- Branch Address1 Policies
- Shared Policy1
BranchPolicy1
An administrator has purchased WildFire subscriptions for 90 firewalls globally. What should the administrator consider with regards to the WildFire infrastructure?
To comply with data privacy regulations, WildFire signatures and verdicts are not shared globally.
Palo Alto Networks owns and maintains one global cloud and four WildFire regional clouds.
Each WildFire cloud analyzes samples and generates malware signatures and verdicts independently of the other WildFire clouds
The WildFire Global Cloud only provides bare metal analysis
What are three reasons for excluding a site from SSL decryption? (Choose three.)
the website is not present in English
unsupported ciphers
certificate pinning
unsupported browser version
mutual authentication
What are three types of Decryption Policy rules? (Choose three.)
SSL Inbound Inspection
SSH Proxy
SSL Forward Proxy
Decryption Broker
Decryption Mirror
Which two features require another license on the NGFW? (Choose two.)
SSL Inbound Inspection
SSL Forward Proxy
Decryption Mirror
Decryption Broker
A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)
Permitted IP Addresses
SSH
https
User-ID
HTTP
A customer is replacing its legacy remote-access VPN solution. Prisma Access has been selected as the replacement. During onboarding, the following options and licenses were selected and enabled:
- Prisma Access for Remote Networks: 300Mbps
- Prisma Access for Mobile Users: 1500 Users
- Cortex Data Lake: 2TB
- Trusted Zones: trust
- Untrusted Zones: untrust
- Parent Device Group: shared
The customer wants to forward to a Splunk SIEM the logs that are generated by users that are connected to Prisma Access for Mobile Users.
Which two settings must the customer configure? (Choose two.)
Configure Panorama Collector group device log forwarding to send logs to the Splunk syslog
server.
Configure Cortex Data Lake log forwarding and add the Splunk syslog server.
Configure a log forwarding profile and select the Panorama/Cortex Data Lake checkbox. Apply the Log
Forwardingprofile to allofthesecuritypolicy rules inMobile_User_Device_Group.
Configure a Log Forwarding profile, select the syslog checkbox, and add the Splunk syslog
server. Apply the Log Forwarding profile to all of the security policy rules in theMobile_User_Device_Group.
Using multiple templates in a stack to manage many firewalls provides which two advantages? (Choose two.)
inherit address-objects from templates
define a common standard template configuration for firewalls
standardize server profiles and authentication configuration across all stacks
standardize log-forwarding profiles for security polices across all stacks
Refer to the diagram. An administrator needs to create an address object that will be useable by the NYC. MA, CA and WA device groups.
Where will the object need to be created within the device-group hierarchy?
Americas
US
East
West
You need to allow users to access the office-suite applications of their choice.
How should you configure the firewall to allow access to any office-suite application?
Create an Application Group and add Office 365, Evernote Google Docs and Libre Office
Create an Application Group and add business-systems to it
Create an Application Filter and name it Office Programs, then filter it on the office programs subcategory.
Create an Application Filter and name it Office Programs then filter on the business-systems category.
A network administrator wants to deploy GlobalProtect with pre-logon for Windows 10 endpoints and follow Palo Alto Networks best practices.
To install the certificate and key for an endpoint, which three components are required? (Choose three.)
server certificate
local computer store
private key
self-signed certificate
machine certificate
To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?
Add the policy in the shared device group as a pre-rule
Reference the targeted device's templates in the target device group
Add the policy to the target device group and apply a master device to the device group
Clone the security policy and add it to the other device groups
Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?
No Direct Access to local networks
Satellite mode
Tunnel mode
IPSec mode
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two)
Dos Protection policy
QoS Profile
Zone Protection Profile
DoS Protection Profile
An administrator is attempting to create policies tor deployment of a device group and template stack.
When creating the policies, the zone drop down list does not include the required zone. What must the administrator do to correct this issue?
Specify the target device as the master device in the device group
Enable "Share Unused Address and Service Objects with Devices" in Panorama settings
Add the template as a reference template in the device group
Add a firewall to both the device group and the template
An administrator is building Security rules within a device group to block traffic to and from malicious locations.
How should those rules be configured to ensure that they are evaluated with a high priority?
Create the appropriate rules with a Block action and apply them at the top of the Default Rules
Create the appropriate rules with a Block action and apply them at the top of the Security Post- Rules.
Create the appropriate rules with a Block action and apply them at the top of the local firewall Security rules
Create the appropriate rules with a Block action and apply them at the top of the Security Pre- Rules
An engineer is in the planning stages of deploying User-ID in a diverse directory services environment.
Which server OS platforms can be used for server monitoring with User-ID?
Microsoft Terminal Server, Red Hat Linux, and Microsoft Active Directory
Microsoft Active Directory, Red Hat Linux, and Microsoft Exchange
Microsoft Exchange, Microsoft Active Directory, and Novell eDirectory
Novell eDirectory, Microsoft Terminal Server, and Microsoft Active Directory
Your company has to Active Directory domain controllers spread across multiple WAN links. All users authenticate to Active Directory Each link has substantial network bandwidth to support all mission-critical applications. The firewalls management plane is highly utilized.
Given this scenario which type of User-ID agent is considered a best practice by Palo Alto Networks?
PAN-OS integrated agent
Captive Portal
Citrix terminal server agent with adequate data-plane resources
Windows-based User-ID agent on a standalone server
A customer is replacing their legacy remote access VPN solution. The current solution is in place to secure only internet egress for the connected clients.
Prisma Access has been selected to replace the current remote access VPN solution. During onboarding the following options and licenses were selected and enabled:
- Prisma Access for Remote Networks 300Mbps
- Prisma Access for Mobile Users 1500 Users
- Cortex Data Lake 2TB
- Trusted Zones trust
- Untrusted Zones untrust
- Parent Device Group shared
How can you configure Prisma Access to provide the same level of access as the current VPN solution?
Configure mobile users with trust-to-untrust Security policy rules to allow the desired traffic
outboundto the internet
Configure mobile users with a service connection and trust-to-trust Security policy rules to allow the desired traffic outbound to the internet
Configure remote networks with a service connection and trust-to-untrust Security policy rules to allow the desired traffic outbound to the internet
Configure remote networks with trust-to-trust Security policy rules to allow the desired traffic outbound to the internet
What best describes the HA Promotion Hold Time?
the time that is recommended to avoid an HA failover due to the occasional flapping of neighboring
devices
the time that is recommended to avoid a failover when both firewalls experience the same link/path monitor failure simultaneously
the time that the passive firewall will wait before taking over as the active firewall after communications with the HA peer have been lost
the time that a passive firewall with a low device priority will wait before taking over as the active firewall if the firewall is operational again
During the process of developing a decryption strategy and evaluating which websites are required for corporate users to access, several sites have been identified that cannot be decrypted due to technical reasons.
In this case, the technical reason is unsupported ciphers. Traffic to these sites will therefore be blocked if decrypted.
How should the engineer proceed?
Allow the firewall to block the sites to improve the security posture
Add the sites to the SSL Decryption Exclusion list to exempt them from decryption
Install the unsupported cipher into the firewall to allow the sites to be decrypted
Create a Security policy to allow access to those sites
When using certificate authentication for firewall administration, which method is used for authorization?
Radius
LDAP
Kerberos
Local
When you navigate to Network: > GlobalProtect > Portals > Method section, which three options are available? (Choose three )
user-logon (always on)
pre-logon then on-demand
on-demand (manual user initiated connection)
post-logon (always on)
certificate-logon
An administrator analyzes the following portion of a VPN system log and notices the following issue "Received local id 10.10.1.4/24 type IPv4 address protocol 0 port 0, received remote id 10.1.10.4/24 type IPv4 address protocol 0 port 0."
What is the cause of the issue?
IPSec crypto profile mismatch
IPSec protocol mismatch
mismatched Proxy-IDs
bad local and peer identification IP addresses in the IKE gateway
What is considered the best practice with regards to zone protection?
Review DoS threat activity (ACC > Block Activity) and look for patterns of abuse
Use separate log-forwarding profiles to forward DoS and zone threshold event logs separately from other threat logs
If the levels of zone and DoS protection consume too many firewall resources, disable zone protection
Set the Alarm Rate threshold for event-log messages to high severity or critical severity
An engineer wants to implement the Palo Alto Networks firewall in VWire mode on the internet gateway and wants to be sure of the functions that are supported on the vwire interface. What are three supported functions on the VWire interface? (Choose three )
NAT
QoS
IPSec
OSPF
SSL Decryption
An administrator needs to build Security rules in a Device Group that allow traffic to specific users and groups defined in Active Directory.
What must be configured in order to select users and groups for those rules from Panorama?
The Security rules must be targeted to a firewall in the device group and have Group Mapping
configured
A master device with Group Mapping configured must be set in the device group where the
Securityrulesare configured
User-ID Redistribution must be configured on Panorama to ensure that all firewalls have the same mappings
A User-ID Certificate profile must be configured on Panorama
Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three )
The environment requires real, full-time redundancy from both firewalls at all times
The environment requires Layer 2 interfaces in the deployment
The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence
The environment requires that all configuration must be fully synchronized between both members of the HA pair
The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes
Which protocol is supported by GlobalProtect Clientless VPN?
HTTPS
FTP
RDP
SSH
Cortex XDR notifies an administrator about grayware on the endpoints. There are no entnes about grayware in any of the logs of the corresponding firewall.
Which setting can the administrator configure on the firewall to log grayware verdicts?
within the log settings option in the Device tab
within the log forwarding profile attached to the Security policy rule
in WildFire General Settings, select "Report Grayware Files"
in Threat General Settings, select "Report Grayware Files"
What would allow a network security administrator to authenticate and identify a user with a new BYOD-type device that is not joined to the corporate domain'?
a Security policy with 'known-user" selected in the Source User field
an Authentication policy with 'unknown' selected in the Source User field
a Security policy with 'unknown' selected in the Source User field
an Authentication policy with 'known-user' selected in the Source User field
Which statement is correct given the following message from the PanGPA log on the GlobalProtect app?
Failed to connect to server at port:4767
The PanGPS process failed to connect to the PanGPA process on port 4767
The GlobalProtect app failed to connect to the GlobalProtect Portal on port 4767
The PanGPA process failed to connect to the PanGPS process on port 4767
The GlobalProtect app failed to connect to the GlobalProtect Gateway on port 4767
Which GlobalProtect component must be configured to enable Chentless VPN?
GlobalProtect satellite
GlobalProtect app
GlobalProtect portal
GlobalProtect gateway
A network security engineer must implement Quality of Service policies to ensure specific levels of delivery guarantees for various applications in the environment.
]They want to ensure that they know as much as they can about QoS before deploying. Which statement about the QoS feature is correct?
QoS is only supported on firewalls that have a single virtual system configured
QoS can be used in conjunction with SSL decryption
QoS is only supported on hardware firewalls
QoS can be used on firewalls with multiple virtual systems configured
Which statement regarding HA timer settings is true?
Use the Recommended profile for typical failover timer settings
Use the Moderate profile for typical failover timer settings
Use the Aggressive profile for slower failover timer settings
Use the Critical profile for faster failover timer settings
What is the best description of the HA4 Keep-Alive Threshold (ms)?
the maximum interval between hello packets that are sent to verify that the HA functionality on the
otherfirewallisoperational
The time that a passive or active-secondary firewall will wait before taking over as the active or active-primary firewall
the timeframe within which the firewall must receive keepalives from a cluster member to know that the cluster member is functional
The timeframe that the local firewall wait before going to Active state when another cluster member is preventing the cluster from fully synchronizing
Where is information about packet buffer protection logged?
Alert entries are in the Alarms log Entries for dropped traffic, discarded sessions, and blocked IP
addressare in the Threatlog
All entries are in the System log
Alert entries are in the System log Entries for dropped traffic, discarded sessions and blocked IP addresses are in the Threat log
All entries are in the Alarms log
An administrator needs firewall access on a trusted interface. Which two components are required to configure certificate based, secure authentication to the web Ul? (Choose two )
certificate profile
server certificate
SSH Service Profile
SSL/TLS Service Profile
When planning to configure SSL Froward Proxy on a PA 5260, a user asks how SSL decryption can be implemented using phased approach in alignment with Palo Alto Networks best practices What should you recommend?
Enable SSL decryption for known malicious source IP addresses
Enable SSL decryption for source users and known malicious URL categories
Enable SSL decryption for malicious source users
Enable SSL decryption for known malicious destination IP addresses
A prospect is eager to conduct a Security Lifecycle Review (SLR) with the aid of the Palo Alto Networks NGFW.
Which interface type is best suited to provide the raw data for an SLR from the network in a way that is minimally invasive?
Layer 3
Virtual Wire
Tap
Layer 2
A user at an internal system queries the DNS server for their web server with a private IP of 10.250.241.131 in the webserver.
The DNS server returns an address of the web server's public address 200.1.1.10.
In order to reach the web server, which security rule and U-Turn NAT rule must be configured on the firewall?
An administrator allocates bandwidth to a Prisma Access Remote Networks compute location with three remote networks.
What is the minimum amount of bandwidth the administrator could configure at the compute location?
90Mbps
300 Mbps
75Mbps
50Mbps
