wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

PANWCOE

Total questions: 100

Worksheet time: 3hrs 20mins

Name
Class
Date
1.

What action will inform end users when their access to Internet content is being restricted?

a)

Ensure that the 'site access" setting for all URL sites is set to 'alert'.

b)

Create a custom 'URL Category' object with notifications enabled.

c)

Enable 'Response Pages' on the interface providing Internet access.

d)

Publish monitoring data for Security policy deny logs.

2.

What must be configured before setting up Credential Phishing Prevention?

a)

Anti Phishing Block Page

b)

Threat Prevention

c)

Anti Phishing profiles

d)

User-ID

3.

A Security Profile can block or allow traffic at which point?

a)

after it is matched to a Security policy rule that allows or blocks traffic

b)

on either the data plane or the management plane

c)

after it is matched to a Security policy rule that allows traffic

d)

before it is matched to a Security policy rule

4.

Which link in the web interface enables a security administrator to view the security policy rules that match new application signatures?

a)

Pre-analyze

b)

Review Policies

c)

Review App Matches

d)

Review Apps

5.

Which Security profile would you apply to identify infected hosts on the protected network using DNS traffic?

a)

anti-spyware

b)

URL traffic

c)

vulnerability protection

d)

antivirus

6.

Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor?

a)

network processing

b)

data

c)

management

d)

security processing

7.

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.

Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

a)

All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application

b)

No impact because the apps were automatically downloaded and installed

c)

No impact because the firewall automatically adds the rules to the App-ID interface

d)

All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications

8.

How many zones can an interface be assigned with a Palo Alto Networks firewall?

a)

two

b)

three

c)

one

d)

four

9.

Which option shows the attributes that are selectable when setting up application filters?

a)

Category, Subcategory, Technology, and Characteristic

b)

Name, Category, Technology, Risk, and Characteristic

c)

Category, Subcategory, Technology, Risk, and Characteristic

d)

Category, Subcategory, Risk, Standard Ports, and Technology

10.

Actions can be set for which two items in a URL filtering security profile? (Choose two.)

a)

Custom URL Categories

b)

Block List

c)

Allow List

d)

PAN-DB URL Categories

11.

Which two statements are correct about App-ID content updates? (Choose two.)

a)

Updated application content might change how Security policy rules are enforced.

b)

After an application content update, new applications must be manually classified prior to use.

c)

Existing security policy rules are not affected by application content updates.

d)

After an application content update, new applications are automatically identified and classified.

12.

An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?

a)

Create an Application Filter and name it Office Programs, then filter it on the business-systems category, office-programs subcategory

b)

Create an Application Group and add business-systems to it

c)

Create an Application Filter and name it Office Programs, then filter it on the business-systems category

d)

Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office

13.

Which statement is true regarding a Best Practice Assessment?

a)

The BPA tool can be run only on firewalls

b)

The assessment, guided by an experienced sales engineer, helps determine the areas of greatest risk where you should focus prevention activities

c)

It provides a percentage of adoption for each assessment area

d)

It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture

14.

Employees are shown an application block page when they try to access YouTube. Which security policy is blocking the YouTube application?

a)

intrazone-default

b)

Deny Google

c)

allowed-security services

d)

interzone-default

15.

Choose the option that correctly completes this statement. A Security Profile can block or allow traffic ____________.

a)

on either the data place or the management plane.

b)

after it is matched by a security policy rule that allows traffic.

c)

before it is matched to a Security policy rule.

d)

after it is matched by a security policy rule that allows or blocks traffic.

16.

When creating a Source NAT policy, which entry in the Translated Packet tab will display the options Dynamic IP and Port, Dynamic, Static IP, and None?

a)

Translation Type

b)

Interface

c)

Address Type

d)

IP Address

17.

Which interface does not require a MAC or IP address?

a)

Layer3

b)

Virtual Wire

c)

Layer2

d)

Loopback

18.

A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?

a)

Policies > Policy Optimizer > No App Specified

b)

Policies > Policy Optimizer > Unused in 30 days

c)

Policies > Policy Optimizer > Unused Apps

d)

Policies > Policy Optimizer > Unused in 90 days

19.

What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.)

a)

An implicit dependency does not require the dependent application to be added in the security policy

b)

An explicit dependency requires the dependent application to be added in the security policy

c)

An implicit dependency requires the dependent application to be added in the security policy

d)

An explicit dependency does not require the dependent application to be added in the security policy

20.

Recently changes were made to the firewall to optimize the policies and the security team wants to see if those changes are helping. What is the quickest way to reset the hit counter to zero in all the security policy rules?

a)

At the CLI enter the command reset rules and press Enter

b)

Highlight a rule and use the Reset Rule Hit Counter > Selected Rules for each rule

c)

Reboot the firewall

d)

Use the Reset Rule Hit Counter > All Rules option

21.

Which two App-ID applications will you need to allow in your Security policy to use facebook-chat? (Choose two.)

a)

facebook

b)

facebook-chat

c)

facebook-base

d)

facebook-email

22.

Which User-ID agent would be appropriate in a network with multiple WAN links, limited network bandwidth, and limited firewall management plane resources?

a)

PAN-OS integrated agent deployed on the internal network

b)

Windows-based agent deployed on the internal network

c)

Citrix terminal server deployed on the internal network

d)

Windows-based agent deployed on each of the WAN Links

23.

Your company requires positive username attribution of every IP address used by wireless devices to support a new compliance requirement. You must collect IP-to-user mappings as soon as possible with minimal downtime and minimal configuration changes to the wireless devices themselves. The wireless devices are from various manufactures. Given the scenario, choose the option for sending IP-to-user mappings to the NGFW.

a)

syslog

b)

RADIUS

c)

UID redistribution

d)

XFF headers

24.

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command- and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)

a)

vulnerability protection profile applied to outbound security policies

b)

antivirus profile applied to outbound security policies

c)

anti-spyware profile applied to outbound security policies

d)

URL filtering profile applied to outbound security policies

25.

At which stage of the Cyber-Attack Lifecycle would the attacker attach an infected PDF file to an email?

a)

Delivery

b)

Reconnaissance

c)

Command and Control

d)

Exploitation

26.

Identify the correct order to configure the PAN-OS integrated USER-ID agent.

1. create a service account on the Domain Controller with sufficient permissions to execute the User- ID agent

2. define the address of the servers to be monitored on the firewall

3. add the service account to monitor the server(s)

4. commit the configuration, and verify agent connection status

a)

2-3-4-1

b)

1-4-3-2

c)

3-1-2-4

d)

1-3-2-4

27.

Which URL Filtering profile action would you set to allow users the option to access a site only if they provide a URL admin password?

a)

override

b)

authorization

c)

authentication

d)

continue

28.

Based on the security policy rules shown, ssh will be allowed on which port?

a)

80

b)

53

c)

22

d)

23

29.

Which license must an Administrator acquire prior to downloading Antivirus Updates for use with the firewall?

a)

Threat Prevention

b)

WildFire

c)

Antivirus

d)

URL Filtering

30.

An administrator notices that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would the administrator need to monitor and block to mitigate the malicious activity?

a)

branch office traffic

b)

north-south traffic

c)

perimeter traffic

d)

east-west traffic

31.

Given the topology, which zone type should zone A and zone B to be configured with?

a)

Layer2

b)

Tap

c)

Layer3

d)

Virtual Wire

32.

To use Active Directory to authenticate administrators, which server profile is required in the authentication profile?

a)

domain controller

b)

LDAP

c)

TACACS+

d)

RADIUS

33.

Which interface type is used to monitor traffic and cannot be used to perform traffic shaping?

a)

Tap

b)

Layer 2

c)

Layer 3

d)

Virtual Wire

34.

Which administrator type provides more granular options to determine what the administrator can view and modify when creating an administrator account?

a)

Root

b)

Role-based

c)

Dynamic

d)

Superuser

35.

Which administrator type utilizes predefined roles for a local administrator account?

a)

Superuser

b)

Dynamic

c)

Role-based

d)

Device administrator

36.

Which two security profile types can be attached to a security policy? (Choose two.)

a)

antivirus

b)

threat

c)

vulnerability

d)

DDoS protection

37.

The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.

Which security profile feature could have been used to prevent the communication with the CnC server?

a)

Create an anti-spyware profile and enable DNS Sinkhole

b)

Create an antivirus profile and enable DNS Sinkhole

c)

Create a URL filtering profile and block the DNS Sinkhole category

d)

Create a security policy and enable DNS Sinkhole

Hide Solution  Discussion

38.

Which user mapping method could be used to discover user IDs in an environment with multiple Windows domain controllers?

a)

Active Directory monitoring

b)

Windows session monitoring

c)

Windows client probing

d)

domain controller monitoring

39.

Which three statements describe the operation of Security policy rules and Security Profiles? (Choose three.)

a)

Security policy rules can block or allow traffic.

b)

Security Profiles are attached to Security policy rules.

c)

Security Profiles should be used only on allowed traffic.

d)

Security policy rules inspect but do not block traffic.

e)

Security policy rules are attached to Security Profiles.

40.

Given the image, which two options are true about the Security policy rules. (Choose two.)

a)

The Allow Office Programs rule is using an Application Filter

b)

In the Allow FTP to web server rule, FTP is allowed using App-ID

c)

The Allow Office Programs rule is using an Application Group

d)

In the Allow Social Networking rule, allows all of Facebook's functions

41.

Which type of Security policy rule would match traffic flowing between the Inside zone and Outside zone, within the Inside zone, and within the Outside zone?

a)

global

b)

intrazone

c)

interzone

d)

universal

42.

Which Palo Alto Networks firewall security platform provides network security for mobile endpoints by inspecting traffic deployed as internet gateways?

a)

AutoFocus

b)

GlobalProtect

c)

Aperture

d)

Panorama

43.

Which two statements are correct regarding multiple static default routes when they are configured as shown in the image? (Choose two.)

a)

Path monitoring does not determine if route is useable.

b)

Route with highest metric is actively used.

c)

Path monitoring determines if route is useable.

d)

Route with lowest metric is actively used.

44.

Given the Cyber-Attack Lifecycle diagram, identify the stage in which the attacker can run malicious code against a targeted machine.

a)

Exploitation

b)

Installation

c)

Reconnaissance

d)

Act on Objective

45.

Which file is used to save the running configuration with a Palo Alto Networks firewall?

a)

run-config.xml

b)

running-configuration.xml

c)

running-config.xml

d)

run-configuration.xml

46.

In the example security policy shown, which two websites would be blocked? (Choose two.)

a)

Amazon

b)

LinkedIn

c)

Facebook

d)

YouTube

47.

Which Palo Alto Networks component provides consolidated policy creation and centralized management?

a)

GlobalProtect

b)

Panorama

c)

Prisma

d)

AutoFocus

48.

Which statement is true regarding a Prevention Posture Assessment?

a)

The Security Policy Adoption Heatmap component filters the information by device groups, serial numbers, zones, areas of architecture, and other categories

b)

It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture

c)

It provides a percentage of adoption for each assessment area

d)

It performs over 200 security checks on Panorama/firewall for the assessment

49.

Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis Unit 42 research and data gathered from telemetry?

a)

Palo Alto Networks Bulletproof IP Addresses

b)

Palo Alto Networks High-Risk IP Addresses

c)

Palo Alto Networks Known Malicious IP Addresses

d)

Palo Alto Networks Tor Exit IP Addresses

50.

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server.

Which security profile components will detect and prevent this threat after the firewall's signature database has been updated?

a)

antivirus profile applied to outbound security policies

b)

data filtering profile applied to inbound security policies

c)

data filtering profile applied to outbound security policies

d)

vulnerability profile applied to inbound security policies

51.

Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content, whose services are frequently used by attackers to distribute illegal or unethical material?

a)

Palo Alto Networks C&C IP Addresses

b)

Palo Alto Networks Bulletproof IP Addresses

c)

Palo Alto Networks Known Malicious IP Addresses

d)

Palo Alto Networks High-Risk IP Addresses

52.

Which administrative management services can be configured to access a management interface?

a)

HTTP, CLI, SNMP, HTTPS

b)

SSH, telnet, HTTP, HTTPS

c)

HTTPS, SSH, telnet SNMP

d)

HTTPS, HTTP. CLI, XML-API

53.

How often does WildFire release dynamic updates?

a)

every 5 minutes

b)

every 15 minutes

c)

every 30 minutes

d)

every 60 minutes

54.

What is the minimum frequency for which you can configure the firewall to check for new WildFire antivirus signatures?

a)

every 24 hours

b)

every 30 minutes

c)

every 5 minutes

d)

every 1 minute

55.

Your company has 10 Active Directory domain controllers spread across multiple WAN links. All users authenticate to Active Directory. Each link has substantial network bandwidth to support all mission-critical applications. The firewall's management plane is highly utilized.

Given the scenario, which type of User-ID agent is considered a best practice by Palo Alto Networks?

a)

Captive Portal

b)

Windows-based agent on a domain controller

c)

Citrix terminal server agent with adequate data-plane resources

d)

PAN-OS integrated agent

56.

What must you configure to enable the firewall to access multiple Authentication Profiles to authenticate a non-local account?

a)

LDAP server profile

b)

authentication server list

c)

authentication sequence

d)

authentication list profile

57.

Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?

a)

alert

b)

sinkhole

c)

block

d)

allow

58.

Which interface type uses virtual routers and routing protocols?

a)

Layer3

b)

Tap

c)

Layer2

d)

Virtual Wire

59.

Which URL Filtering Profile action does not generate a log entry when a user attempts to access a URL?

a)

Override

b)

Block

c)

Continue

d)

Allow

60.

Which path in PAN-OS displays the list of port-based security policy rules?

a)

Policies> Security> Policy Optimizer> No Apps Specified

b)

Policies> Security> Policy Optimizer> Port only specified

c)

Policies> Security> Policy Optimizer> Port-based Rules

d)

Policies> Security> Policy Optimizer> Unused Apps

61.

Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilized.

Which User-ID agent is sufficient in your network?

a)

Windows-based agent deployed on each domain controller

b)

PAN-OS integrated agent deployed on the firewall

c)

Citrix terminal server agent deployed on the network

d)

Windows-based agent deployed on the internal network a domain member

62.

Which path in PAN-OS displays the list of port-based security policy rules?

a)

Policies> Security> Policy Optimizer> Port-based Rules

b)

Policies> Security> Policy Optimizer> Port only specified

c)

Policies> Security> Policy Optimizer> No App Specified

d)

Policies> Security> Policy Optimizer> Unused Apps

63.

Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)

a)

User-ID

b)

App-ID

c)

Layer-ID

d)

QoS-ID

64.

Which path is used to save and load a configuration with a Palo Alto Networks firewall?

a)

Device>Setup>Services

b)

Device>Setup>Operations

c)

Device>Setup>Management

d)

Device>Setup>Interfaces

65.

Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that matches new application signatures?

a)

Review Apps

b)

Review App Matches

c)

Pre-analyze

d)

Review Policies

66.

How do you reset the hit count on a Security policy rule?

a)

Select a Security policy rule, and then select Hit Count > Reset.

b)

Reboot the data-plane.

c)

First disable and then re-enable the rule.

d)

Type the CLI command reset hitcount <POLICY-NAME>.

67.

Given the topology, which zone type should you configure for firewall interface E1/1?

a)

Virtual Wire

b)

Tunnel

c)

Layer3

d)

Tap

68.

Which dynamic update type includes updated anti-spyware signatures?

a)

PAN-DB

b)

Applications and Threats

c)

GlobalProtect Data File

d)

Antivirus

69.

Which security policy rule would be needed to match traffic that passes between the Outside zone and Inside zone, but does not match traffic that passes within the zones?

a)

intrazone

b)

interzone

c)

universal

d)

global

70.

How are Application Filters or Application Groups used in firewall policy?

a)

An Application Group is a static way of grouping applications and cannot be configured as a nested member of Application Group.

b)

An Application Group is a dynamic way of grouping applications and can be configured as a nested member of an Application Group.

c)

An Application Filter is a static way of grouping applications and can be configured as a nested member of an Application Group.

d)

An Application Filter is a dynamic way to group applications and can be configured as a nested member of an Application Group.

71.

Which data flow direction is protected in a zero-trust firewall deployment that is not protected in a perimeter-only firewall deployment?

a)

north-south

b)

inbound

c)

outbound

d)

east-west

72.

What is an advantage for using application tags?

a)

They help with the design of IP address allocations in DHCP.

b)

They help with the creation of interfaces

c)

They help content updates automate policy updates

d)

They are helpful during the creation of new zones

73.

Which license is required to use the Palo Alto Networks built-in IP address EDLs?

a)

DNS Security

b)

Threat Prevention

c)

WildFire

d)

SD-Wan

74.

You receive notification about new malware that is being used to attack hosts The malware exploits a software bug in a common application Which Security Profile detects and blocks access to this threat after you update the firewall's threat signature database?

a)

Data Filtering Profile applied to inbound Security policy rules

b)

Antivirus Profile applied to outbound Security policy rules

c)

Data Filtering Profile applied to outbound Security policy rules

d)

Vulnerability Profile applied to inbound Security policy rules

75.

Employees are shown an application block page when they try to access YouTube. Which security policy is blocking the YouTube application?

a)

intrazone-default

b)

Deny Google

c)

allowed-security services

d)

interzone-default

76.

Which plane on a Palo alto networks firewall provides configuration logging and reporting functions on a separate processor?

a)

network processing

b)

security processing

c)

management

d)

data

77.

Which protocol used to map username to user groups when user-ID is configured?

a)

RADIUS

b)

LDAP

c)

TACACS+

d)

SAML

78.

Given the image, which two options are true about the Security policy rules. (Choose two.)

a)

The Allow-Office-Programs rule is using an Application Filter.

b)

The Allow-Social-Media rule allows all of Facebook's functions.

c)

In the Allow-FTP policy, FTP is allowed using App-ID.

d)

The Allow-Office-Programs rule is using an Application Group.

79.

The Palo Alto Networks NGFW was configured with a single virtual router named VR-1 What changes are required on VR-1 to route traffic between two interfaces on the NGFW?

a)

Add a static routes to route between the two interfaces

b)

Enable the redistribution profile to redistribute connected routes

c)

Add interfaces to the virtual router

d)

Add zones attached to interfaces to the virtual router

80.

During the packet flow process, which two processes are performed in application identification? (Choose two.)

a)

pattern based application identification

b)

application changed from content inspection

c)

session application identified

d)

application override policy match

81.

Which license is required to use the Palo Alto Networks built-in IP address EDLs?

a)

DNS Security

b)

Threat Prevention

c)

URL Filtering

d)

WildFire

82.

An administrator wants to prevent access to media content websites that are risky Which two URL categories should be combined in a custom URL category to accomplish this goal? (Choose two)

a)

recreation-and-hobbies

b)

high-risk 

c)

known-risk 

d)

streaming-media

83.

In path monitoring, what is used to monitor remote network devices?

a)

Ping

b)

SSL

c)

HTTP

d)

HTTPS

e)

Link State

84.

What are three methods of mapping usernames to IP addresses?

a)

Server Monitoring 

b)

Traps

c)

port mapping

d)

syslog

e)

AutoFocus

85.

What are two predefined Anti­Spyware profiles? (Choose two.) 

a)

Default

b)

Standard

c)

Secure

d)

Strict

86.

Which type of profile must be applied to the Security policy rule to protect against buffer overflows illegal code execution and other attempts to exploit system flaws?

a)

URL filtering 

b)

vulnerability protection

c)

anti-spyware

d)

file blocking

87.

A Decryption policy rule allows administrators to:

a)

Require certificates

b)

Inspect inside encrypted sessions

c)

Re-encrypt firewall settings

d)

Decrypt VPN traffic

88.

Which operations are allowed when working with App-ID application tags?

a)

Predefined tags may be modified. 

b)

Predefined tags may be deleted.

c)

Predefined tags may be augmented by custom tags.

d)

Predefined tags may be updated by WildFire dynamic updates. 

89.

Which Security profile can you apply to protect against malware such as worms and Trojans?

a)

data filtering

b)

vulnerability protection 

c)

antivirus

d)

anti-spyware

90.

Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)

a)

SAML

b)

TACACS+ 

c)

Kerberos

d)

PAP

e)

RADIUS

91.

Which action results in the firewall blocking network traffic without notifying the sender?

a)

Reset Server 

b)

Deny

c)

Reset Client

d)

Drop

92.

An administrator has configured a Security policy where the matching condition includes a single application and the action is deny.

If the application's default deny action is reset-both what action does the firewall take?

a)

It sends a TCP reset to the server-side device

b)

It silently drops the traffic 

c)

It sends a TCP reset to the client-side and server-side devices

d)

It silently drops the traffic and sends an ICMP unreachable code 

93.

An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs.

What is the correct process to enable this logging?

a)

Select the interzone-default rule and edit the rule; on the Actions tab, select Log at Session End and click OK.

b)

Select the interzone-default rule and edit the rule; on the Actions tab, select Log at Session Start and click OK.

c)

Select the interzone-default rule and click Override; on the Actions tab, select Log at Session End and click OK.

d)

This rule has traffic logging enabled by default; no further action is required.

94.

Which statement is true about Panorama managed devices? 

a)

Panorama automatically removes local configuration locks after a commit from Panorama 

b)

Security policy rules configured on local firewalls always take precedence 

c)

Local configuration locks prohibit Security policy changes for a Panorama managed device 

d)

Local configuration locks can be manually unlocked from Panorama 

95.

Which two settings allow you to restrict access to the management interface? (Choose two)  

a)

enabling the Content-ID filter

b)

restricting HTTP and telnet using App-ID

c)

permitted IP addresses

d)

administrative management services 

96.

Which User-ID mapping method should be used for an environment with users that do not authenticate to Active Directory? 

a)

Windows session monitoring 

b)

passive server monitoring using the Windows-based agent

c)

Captive Portal

d)

passive server monitoring using a PAN-OS integrated User-ID agent 

97.

Which three types of authentication services can be used to authenticate user traffic flowing through the firewalls data plane? (Choose three) 

a)

SAML 1.0 

b)

SAML 2.0 

c)

Kerberos

d)

TACACS+

e)

TACACS

98.

You receive notification about new malware that is being used to attack hosts. The malware exploits a software bug in common application.

Which Security Profile detects and blocks access to this threat after you update the firewall's threat signature database?

a)

Data Filtering Profile applied to outbound Security policy rules

b)

Vulnerability Protection Profile applied to inbound Security policy rules

c)

Data Filtering Profile applied to inbound Security policy rules

d)

Antivirus Profile applied to outbound Security policy rules

99.

Which definition describes the guiding principle of the zero-trust architecture?

a)

never trust, never connect 

b)

always connect and verify 

c)

trust, but verity 

d)

never trust, always verify 

100.

Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two.) 

a)

QoS profile 

b)

DoS Protection policy 

c)

DoS Protection profile 

d)

Zone Protection profile