Font size
WorksheetsPANWCOE
Total questions: 100
Worksheet time: 3hrs 20mins
What action will inform end users when their access to Internet content is being restricted?
Ensure that the 'site access" setting for all URL sites is set to 'alert'.
Create a custom 'URL Category' object with notifications enabled.
Enable 'Response Pages' on the interface providing Internet access.
Publish monitoring data for Security policy deny logs.
What must be configured before setting up Credential Phishing Prevention?
Anti Phishing Block Page
Threat Prevention
Anti Phishing profiles
User-ID
A Security Profile can block or allow traffic at which point?
after it is matched to a Security policy rule that allows or blocks traffic
on either the data plane or the management plane
after it is matched to a Security policy rule that allows traffic
before it is matched to a Security policy rule
Which link in the web interface enables a security administrator to view the security policy rules that match new application signatures?
Pre-analyze
Review Policies
Review App Matches
Review Apps
Which Security profile would you apply to identify infected hosts on the protected network using DNS traffic?
anti-spyware
URL traffic
vulnerability protection
antivirus
Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor?
network processing
data
management
security processing
A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.
Based on the information, how is the SuperApp traffic affected after the 30 days have passed?
All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
No impact because the apps were automatically downloaded and installed
No impact because the firewall automatically adds the rules to the App-ID interface
All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
How many zones can an interface be assigned with a Palo Alto Networks firewall?
two
three
one
four
Which option shows the attributes that are selectable when setting up application filters?
Category, Subcategory, Technology, and Characteristic
Name, Category, Technology, Risk, and Characteristic
Category, Subcategory, Technology, Risk, and Characteristic
Category, Subcategory, Risk, Standard Ports, and Technology
Actions can be set for which two items in a URL filtering security profile? (Choose two.)
Custom URL Categories
Block List
Allow List
PAN-DB URL Categories
Which two statements are correct about App-ID content updates? (Choose two.)
Updated application content might change how Security policy rules are enforced.
After an application content update, new applications must be manually classified prior to use.
Existing security policy rules are not affected by application content updates.
After an application content update, new applications are automatically identified and classified.
An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?
Create an Application Filter and name it Office Programs, then filter it on the business-systems category, office-programs subcategory
Create an Application Group and add business-systems to it
Create an Application Filter and name it Office Programs, then filter it on the business-systems category
Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office
Which statement is true regarding a Best Practice Assessment?
The BPA tool can be run only on firewalls
The assessment, guided by an experienced sales engineer, helps determine the areas of greatest risk where you should focus prevention activities
It provides a percentage of adoption for each assessment area
It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture
Employees are shown an application block page when they try to access YouTube. Which security policy is blocking the YouTube application?
intrazone-default
Deny Google
allowed-security services
interzone-default
Choose the option that correctly completes this statement. A Security Profile can block or allow traffic ____________.
on either the data place or the management plane.
after it is matched by a security policy rule that allows traffic.
before it is matched to a Security policy rule.
after it is matched by a security policy rule that allows or blocks traffic.
When creating a Source NAT policy, which entry in the Translated Packet tab will display the options Dynamic IP and Port, Dynamic, Static IP, and None?
Translation Type
Interface
Address Type
IP Address
Which interface does not require a MAC or IP address?
Layer3
Virtual Wire
Layer2
Loopback
A company moved its old port-based firewall to a new Palo Alto Networks NGFW 60 days ago. Which utility should the company use to identify out-of-date or unused rules on the firewall?
Policies > Policy Optimizer > No App Specified
Policies > Policy Optimizer > Unused in 30 days
Policies > Policy Optimizer > Unused Apps
Policies > Policy Optimizer > Unused in 90 days
What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.)
An implicit dependency does not require the dependent application to be added in the security policy
An explicit dependency requires the dependent application to be added in the security policy
An implicit dependency requires the dependent application to be added in the security policy
An explicit dependency does not require the dependent application to be added in the security policy
Recently changes were made to the firewall to optimize the policies and the security team wants to see if those changes are helping. What is the quickest way to reset the hit counter to zero in all the security policy rules?
At the CLI enter the command reset rules and press Enter
Highlight a rule and use the Reset Rule Hit Counter > Selected Rules for each rule
Reboot the firewall
Use the Reset Rule Hit Counter > All Rules option
Which two App-ID applications will you need to allow in your Security policy to use facebook-chat? (Choose two.)
facebook-chat
facebook-base
facebook-email
Which User-ID agent would be appropriate in a network with multiple WAN links, limited network bandwidth, and limited firewall management plane resources?
PAN-OS integrated agent deployed on the internal network
Windows-based agent deployed on the internal network
Citrix terminal server deployed on the internal network
Windows-based agent deployed on each of the WAN Links
Your company requires positive username attribution of every IP address used by wireless devices to support a new compliance requirement. You must collect IP-to-user mappings as soon as possible with minimal downtime and minimal configuration changes to the wireless devices themselves. The wireless devices are from various manufactures. Given the scenario, choose the option for sending IP-to-user mappings to the NGFW.
syslog
RADIUS
UID redistribution
XFF headers
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command- and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)
vulnerability protection profile applied to outbound security policies
antivirus profile applied to outbound security policies
anti-spyware profile applied to outbound security policies
URL filtering profile applied to outbound security policies
At which stage of the Cyber-Attack Lifecycle would the attacker attach an infected PDF file to an email?
Delivery
Reconnaissance
Command and Control
Exploitation
Identify the correct order to configure the PAN-OS integrated USER-ID agent.
1. create a service account on the Domain Controller with sufficient permissions to execute the User- ID agent
2. define the address of the servers to be monitored on the firewall
3. add the service account to monitor the server(s)
4. commit the configuration, and verify agent connection status
2-3-4-1
1-4-3-2
3-1-2-4
1-3-2-4
Which URL Filtering profile action would you set to allow users the option to access a site only if they provide a URL admin password?
override
authorization
authentication
continue
Based on the security policy rules shown, ssh will be allowed on which port?
80
53
22
23
Which license must an Administrator acquire prior to downloading Antivirus Updates for use with the firewall?
Threat Prevention
WildFire
Antivirus
URL Filtering
An administrator notices that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would the administrator need to monitor and block to mitigate the malicious activity?
branch office traffic
north-south traffic
perimeter traffic
east-west traffic
Given the topology, which zone type should zone A and zone B to be configured with?
Layer2
Tap
Layer3
Virtual Wire
To use Active Directory to authenticate administrators, which server profile is required in the authentication profile?
domain controller
LDAP
TACACS+
RADIUS
Which interface type is used to monitor traffic and cannot be used to perform traffic shaping?
Tap
Layer 2
Layer 3
Virtual Wire
Which administrator type provides more granular options to determine what the administrator can view and modify when creating an administrator account?
Root
Role-based
Dynamic
Superuser
Which administrator type utilizes predefined roles for a local administrator account?
Superuser
Dynamic
Role-based
Device administrator
Which two security profile types can be attached to a security policy? (Choose two.)
antivirus
threat
vulnerability
DDoS protection
The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.
Which security profile feature could have been used to prevent the communication with the CnC server?
Create an anti-spyware profile and enable DNS Sinkhole
Create an antivirus profile and enable DNS Sinkhole
Create a URL filtering profile and block the DNS Sinkhole category
Create a security policy and enable DNS Sinkhole
Hide Solution Discussion
Which user mapping method could be used to discover user IDs in an environment with multiple Windows domain controllers?
Active Directory monitoring
Windows session monitoring
Windows client probing
domain controller monitoring
Which three statements describe the operation of Security policy rules and Security Profiles? (Choose three.)
Security policy rules can block or allow traffic.
Security Profiles are attached to Security policy rules.
Security Profiles should be used only on allowed traffic.
Security policy rules inspect but do not block traffic.
Security policy rules are attached to Security Profiles.
Given the image, which two options are true about the Security policy rules. (Choose two.)
The Allow Office Programs rule is using an Application Filter
In the Allow FTP to web server rule, FTP is allowed using App-ID
The Allow Office Programs rule is using an Application Group
In the Allow Social Networking rule, allows all of Facebook's functions
Which type of Security policy rule would match traffic flowing between the Inside zone and Outside zone, within the Inside zone, and within the Outside zone?
global
intrazone
interzone
universal
Which Palo Alto Networks firewall security platform provides network security for mobile endpoints by inspecting traffic deployed as internet gateways?
AutoFocus
GlobalProtect
Aperture
Panorama
Which two statements are correct regarding multiple static default routes when they are configured as shown in the image? (Choose two.)
Path monitoring does not determine if route is useable.
Route with highest metric is actively used.
Path monitoring determines if route is useable.
Route with lowest metric is actively used.
Given the Cyber-Attack Lifecycle diagram, identify the stage in which the attacker can run malicious code against a targeted machine.
Exploitation
Installation
Reconnaissance
Act on Objective
Which file is used to save the running configuration with a Palo Alto Networks firewall?
run-config.xml
running-configuration.xml
running-config.xml
run-configuration.xml
In the example security policy shown, which two websites would be blocked? (Choose two.)
Amazon
YouTube
Which Palo Alto Networks component provides consolidated policy creation and centralized management?
GlobalProtect
Panorama
Prisma
AutoFocus
Which statement is true regarding a Prevention Posture Assessment?
The Security Policy Adoption Heatmap component filters the information by device groups, serial numbers, zones, areas of architecture, and other categories
It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture
It provides a percentage of adoption for each assessment area
It performs over 200 security checks on Panorama/firewall for the assessment
Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis Unit 42 research and data gathered from telemetry?
Palo Alto Networks Bulletproof IP Addresses
Palo Alto Networks High-Risk IP Addresses
Palo Alto Networks Known Malicious IP Addresses
Palo Alto Networks Tor Exit IP Addresses
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server.
Which security profile components will detect and prevent this threat after the firewall's signature database has been updated?
antivirus profile applied to outbound security policies
data filtering profile applied to inbound security policies
data filtering profile applied to outbound security policies
vulnerability profile applied to inbound security policies
Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content, whose services are frequently used by attackers to distribute illegal or unethical material?
Palo Alto Networks C&C IP Addresses
Palo Alto Networks Bulletproof IP Addresses
Palo Alto Networks Known Malicious IP Addresses
Palo Alto Networks High-Risk IP Addresses
Which administrative management services can be configured to access a management interface?
HTTP, CLI, SNMP, HTTPS
SSH, telnet, HTTP, HTTPS
HTTPS, SSH, telnet SNMP
HTTPS, HTTP. CLI, XML-API
How often does WildFire release dynamic updates?
every 5 minutes
every 15 minutes
every 30 minutes
every 60 minutes
What is the minimum frequency for which you can configure the firewall to check for new WildFire antivirus signatures?
every 24 hours
every 30 minutes
every 5 minutes
every 1 minute
Your company has 10 Active Directory domain controllers spread across multiple WAN links. All users authenticate to Active Directory. Each link has substantial network bandwidth to support all mission-critical applications. The firewall's management plane is highly utilized.
Given the scenario, which type of User-ID agent is considered a best practice by Palo Alto Networks?
Captive Portal
Windows-based agent on a domain controller
Citrix terminal server agent with adequate data-plane resources
PAN-OS integrated agent
What must you configure to enable the firewall to access multiple Authentication Profiles to authenticate a non-local account?
LDAP server profile
authentication server list
authentication sequence
authentication list profile
Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?
alert
sinkhole
block
allow
Which interface type uses virtual routers and routing protocols?
Layer3
Tap
Layer2
Virtual Wire
Which URL Filtering Profile action does not generate a log entry when a user attempts to access a URL?
Override
Block
Continue
Allow
Which path in PAN-OS displays the list of port-based security policy rules?
Policies> Security> Policy Optimizer> No Apps Specified
Policies> Security> Policy Optimizer> Port only specified
Policies> Security> Policy Optimizer> Port-based Rules
Policies> Security> Policy Optimizer> Unused Apps
Your company occupies one floor in a single building. You have two Active Directory domain controllers on a single network. The firewall's management plane is only slightly utilized.
Which User-ID agent is sufficient in your network?
Windows-based agent deployed on each domain controller
PAN-OS integrated agent deployed on the firewall
Citrix terminal server agent deployed on the network
Windows-based agent deployed on the internal network a domain member
Which path in PAN-OS displays the list of port-based security policy rules?
Policies> Security> Policy Optimizer> Port-based Rules
Policies> Security> Policy Optimizer> Port only specified
Policies> Security> Policy Optimizer> No App Specified
Policies> Security> Policy Optimizer> Unused Apps
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)
User-ID
App-ID
Layer-ID
QoS-ID
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
Device>Setup>Services
Device>Setup>Operations
Device>Setup>Management
Device>Setup>Interfaces
Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that matches new application signatures?
Review Apps
Review App Matches
Pre-analyze
Review Policies
How do you reset the hit count on a Security policy rule?
Select a Security policy rule, and then select Hit Count > Reset.
Reboot the data-plane.
First disable and then re-enable the rule.
Type the CLI command reset hitcount <POLICY-NAME>.
Given the topology, which zone type should you configure for firewall interface E1/1?
Virtual Wire
Tunnel
Layer3
Tap
Which dynamic update type includes updated anti-spyware signatures?
PAN-DB
Applications and Threats
GlobalProtect Data File
Antivirus
Which security policy rule would be needed to match traffic that passes between the Outside zone and Inside zone, but does not match traffic that passes within the zones?
intrazone
interzone
universal
global
How are Application Filters or Application Groups used in firewall policy?
An Application Group is a static way of grouping applications and cannot be configured as a nested member of Application Group.
An Application Group is a dynamic way of grouping applications and can be configured as a nested member of an Application Group.
An Application Filter is a static way of grouping applications and can be configured as a nested member of an Application Group.
An Application Filter is a dynamic way to group applications and can be configured as a nested member of an Application Group.
Which data flow direction is protected in a zero-trust firewall deployment that is not protected in a perimeter-only firewall deployment?
north-south
inbound
outbound
east-west
What is an advantage for using application tags?
They help with the design of IP address allocations in DHCP.
They help with the creation of interfaces
They help content updates automate policy updates
They are helpful during the creation of new zones
Which license is required to use the Palo Alto Networks built-in IP address EDLs?
DNS Security
Threat Prevention
WildFire
SD-Wan
You receive notification about new malware that is being used to attack hosts The malware exploits a software bug in a common application Which Security Profile detects and blocks access to this threat after you update the firewall's threat signature database?
Data Filtering Profile applied to inbound Security policy rules
Antivirus Profile applied to outbound Security policy rules
Data Filtering Profile applied to outbound Security policy rules
Vulnerability Profile applied to inbound Security policy rules
Employees are shown an application block page when they try to access YouTube. Which security policy is blocking the YouTube application?
intrazone-default
Deny Google
allowed-security services
interzone-default
Which plane on a Palo alto networks firewall provides configuration logging and reporting functions on a separate processor?
network processing
security processing
management
data
Which protocol used to map username to user groups when user-ID is configured?
RADIUS
LDAP
TACACS+
SAML
Given the image, which two options are true about the Security policy rules. (Choose two.)
The Allow-Office-Programs rule is using an Application Filter.
The Allow-Social-Media rule allows all of Facebook's functions.
In the Allow-FTP policy, FTP is allowed using App-ID.
The Allow-Office-Programs rule is using an Application Group.
The Palo Alto Networks NGFW was configured with a single virtual router named VR-1 What changes are required on VR-1 to route traffic between two interfaces on the NGFW?
Add a static routes to route between the two interfaces
Enable the redistribution profile to redistribute connected routes
Add interfaces to the virtual router
Add zones attached to interfaces to the virtual router
During the packet flow process, which two processes are performed in application identification? (Choose two.)
pattern based application identification
application changed from content inspection
session application identified
application override policy match
Which license is required to use the Palo Alto Networks built-in IP address EDLs?
DNS Security
Threat Prevention
URL Filtering
WildFire
An administrator wants to prevent access to media content websites that are risky Which two URL categories should be combined in a custom URL category to accomplish this goal? (Choose two)
recreation-and-hobbies
high-risk
known-risk
streaming-media
In path monitoring, what is used to monitor remote network devices?
Ping
SSL
HTTP
HTTPS
Link State
What are three methods of mapping usernames to IP addresses?
Server Monitoring
Traps
port mapping
syslog
AutoFocus
What are two predefined AntiSpyware profiles? (Choose two.)
Default
Standard
Secure
Strict
Which type of profile must be applied to the Security policy rule to protect against buffer overflows illegal code execution and other attempts to exploit system flaws?
URL filtering
vulnerability protection
anti-spyware
file blocking
A Decryption policy rule allows administrators to:
Require certificates
Inspect inside encrypted sessions
Re-encrypt firewall settings
Decrypt VPN traffic
Which operations are allowed when working with App-ID application tags?
Predefined tags may be modified.
Predefined tags may be deleted.
Predefined tags may be augmented by custom tags.
Predefined tags may be updated by WildFire dynamic updates.
Which Security profile can you apply to protect against malware such as worms and Trojans?
data filtering
vulnerability protection
antivirus
anti-spyware
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
SAML
TACACS+
Kerberos
PAP
RADIUS
Which action results in the firewall blocking network traffic without notifying the sender?
Reset Server
Deny
Reset Client
Drop
An administrator has configured a Security policy where the matching condition includes a single application and the action is deny.
If the application's default deny action is reset-both what action does the firewall take?
It sends a TCP reset to the server-side device
It silently drops the traffic
It sends a TCP reset to the client-side and server-side devices
It silently drops the traffic and sends an ICMP unreachable code
An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs.
What is the correct process to enable this logging?
Select the interzone-default rule and edit the rule; on the Actions tab, select Log at Session End and click OK.
Select the interzone-default rule and edit the rule; on the Actions tab, select Log at Session Start and click OK.
Select the interzone-default rule and click Override; on the Actions tab, select Log at Session End and click OK.
This rule has traffic logging enabled by default; no further action is required.
Which statement is true about Panorama managed devices?
Panorama automatically removes local configuration locks after a commit from Panorama
Security policy rules configured on local firewalls always take precedence
Local configuration locks prohibit Security policy changes for a Panorama managed device
Local configuration locks can be manually unlocked from Panorama
Which two settings allow you to restrict access to the management interface? (Choose two)
enabling the Content-ID filter
restricting HTTP and telnet using App-ID
permitted IP addresses
administrative management services
Which User-ID mapping method should be used for an environment with users that do not authenticate to Active Directory?
Windows session monitoring
passive server monitoring using the Windows-based agent
Captive Portal
passive server monitoring using a PAN-OS integrated User-ID agent
Which three types of authentication services can be used to authenticate user traffic flowing through the firewalls data plane? (Choose three)
SAML 1.0
SAML 2.0
Kerberos
TACACS+
TACACS
You receive notification about new malware that is being used to attack hosts. The malware exploits a software bug in common application.
Which Security Profile detects and blocks access to this threat after you update the firewall's threat signature database?
Data Filtering Profile applied to outbound Security policy rules
Vulnerability Protection Profile applied to inbound Security policy rules
Data Filtering Profile applied to inbound Security policy rules
Antivirus Profile applied to outbound Security policy rules
Which definition describes the guiding principle of the zero-trust architecture?
never trust, never connect
always connect and verify
trust, but verity
never trust, always verify
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two.)
QoS profile
DoS Protection policy
DoS Protection profile
Zone Protection profile
