wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Software NGFW Associate

Total questions: 83

Worksheet time: 50mins

Name
Class
Date
1.

What is the primary purpose of applying infrastructure tags in the public 

cloud?

a)

Increasing cloud resource visibility

b)

Connecting security posture to CI/CD pipeline

c)

Dynamically applying policy as the environment changes

d)

Synchronizing native cloud security policy with the firewall

2.

Which compliance regulation must an organization follow when storing, processing, or transmitting payment cardholder data?

a)

Payment Card Industry (PCI)

b)

Protected Cardholder Data (PCD)

c)

Guaranteed Basic Livable Income (GLBI)

d)

Health Insurance Portability and Accountability Act of 1996

3.

What is the preferred way to analyze traffic logs generated from multiple data 

center firewalls?

a)

Use Palo Alto Networks Prisma Access console to view all firewall logs

b)

Log in to one of the firewalls in order to request the log of the other firewalls.

c)

Log in to each firewall and generate the log in a PDF format before analyzing it

d)

Use Panorama for aggregated logging with central oversight for analysis and reporting.

4.

What is used to deploy CN-Series firewalls within a Kubernetes cluster?

a)

YAML files

b)

Docker images

c)

License authorization codes

d)

Kubernetes plugin for Panorama

5.

What is the unit of autoscaling for CN-Series and VM-Series firewalls?

a)

Nodes

b)

VCPUs

c)

Clusters

d)

Gigabytes

6.

Which plugin is required to enable Panorama to connect to and manage a 

cluster running CN-Series?

a)

Docker

b)

vCluster

c)

Kubernetes

d)

Amazon ECS

7.

What is used to apply policies that can track public/private cloud resources?

a)

URLS

b)

IP addresses

c)

Access Control Lists

d)

Dynamic address groups

8.

Which technology allows for granular control of east-west traffic in a 

software-defined network?

a)

Routing

b)

Virtualization

c)

Microsegmentation

d)

MAC Access Control List

9.

Which Palo Alto Networks product provides centralized security, control, and visibility for a multicloud environment?

a)

WildFire

b)

Panorama

c)

DNS security

d)

GlobalProtect

10.

What is Palo Alto Networks software firewall credit licensing is based on?

a)

VCPU

b)

Memory

c)

Storage

d)

Throughput

11.

Where are sample automation templates for VM-Series and CN-Series located?

a)

Marketplace

b)

Palo Alto Networks support center

c)

Palo Alto Networks public github repo

d)

Palo Alto Networks public documentation

12.

How can the Palo Alto Networks Next-Generation Firewall (NGFW) simplify 

security deployments for software-defined networks (SDNs) in a data center?

a)

By applying the data center version of PAN-OS

b)

By using the Palo Alto Networks SDN controller

c)

By deploying the Palo Alto Networks Cortex XDR SDN feature

d)

By integrating with the leading virtualization and SDN solutions

13.

Which tool should be used to estimate the number of credits required for a VM-Series or CN-Series deployment?

a)

Software NGFW Credit Estimator

b)

Customer service portal

c)

TechDocs

d)

Salesforce 

14.

Which security subscription provides an inline web protection engine powered by deep learning to stop unknown web-based attacks in real time?

a)

DNS Security

b)

GlobalProtect

c)

Intelligent traffic offload

d)

Advanced URL Filtering (AURLF)

15.

With which three private cloud environments does Palo Alto Networks have 

deep integrations? (Choose three.)

a)

Nutanix

b)

Cisco ACI

c)

Dell APEX

d)

HPE Synergy

e)

VMware NSX-T

16.

Which third-party tool allows customers to easily deploy and manage CN- 

Series? 

a)

AWS Marketplace

b)

Alicloud Marketplace

c)

IBM Cloud Marketplace

d)

Digital Ocean Marketplace

17.

What are two functions of CN-Series next-generation firewalls (NGFWs) in Kubernetes environments? (Choose two.) 

a)

Replacing the CI/CD pipeline security tools

b)

Providing Layer 7 visibility into container traffic

c)

Replacing VM-Series firewalls for network security in the data center

d)

Enforcing security policies with threat prevention profiles between namespaces

18.

Which two CN-Series deployment options provide visibility into Kubernetes 

clusters? (Choose two.) 

a)

CNF

b)

Hybrid

c)

Daemonset

d)

Kubernetes service

19.

Which portal allows management and monitoring of flex credits?

a)

Olive.paloaltonetworks.com

b)

sales.paloaltonetworks.com

c)

beacon.paloaltonetworks.com

d)

customersupport.paloaltonetworks.com

20.

Which three subscriptions should be recommended to a customer who is 

deploying VM-Series firewalls to a private data center, but is concerned with 

protecting data center resources from malware and lateral movement? 

(Choose three.)

a)

WildFire

b)

SD-WAN 

c)

GlobalProtect

d)

Threat Prevention

e)

Intelligent Traffic Offload

21.

Which VM-Series deployment model within vSphere allows for firewall 

insertion into an existing network and will also require additional VLANs for 

each tenant or application boundary?

a)

Layer 2 

b)

Layer 3

c)

Layer 7

d)

Virtual wire (vwire)

22.

In which two locations can information pertaining to Palo Alto Networks software firewalls be located? (Choose two.)

a)

TechDocs

b)

StackOverflow

c)

Product landing pages

d)

Google Container Registry

23.

Which two pieces of information are needed prior to estimating the number of 

software next-generation firewall (NGFW) credits that a VM-Series or CN- 

Series deployment requires? (Choose two.)

a)

Number of nodes

b)

Scaling requirements

c)

Deployment environment

d)

Number of availability zones

24.

Which level of abstraction allows definition of common policy across multiple next-generation firewalls (NGFWs) in Panorama?

a)

Zones

b)

Interfaces

c)

Zone profiles

d)

Security profiles

25.

What is the maximum number of application pods that a CN-Series can secure on a single node?

a)

12

b)

18

c)

30

d)

36

26.

Why are dynamic address groups critical to modern network security?

a)

They enable DNS port forwarding

b)

They create a pool of IP addresses that can be used for security purposes.

c)

They provide a way to consistently apply policies to a set of dynamically changing resources.

d)

They allow customers to apply cloud delivered security subscriptions to their VM-Series or CN-Series deployments.

27.

Which two configuration objects will allow servers from different operating system (OS) types to get package updates from a given domain? (Choose two.)

a)

Static IP address objects for every server, grouped together by OS type

b)

A single external dynamic list that maintains a list of all of the update domains

c)

One custom URL category for each list of update domains needed for a particular OS type

d)

A dynamic address group mapped to an NSX-T inventory group that groups virtual machines (VMs) and bare metal servers together based on OS type

28.

What are two reasons network security is important for containerized 

applications? (Choose two.)

a)

Shift-left products are designed to provide end-to-end security

b)

It provides protection against unpatched and unknown vulnerabilities.

c)

Containers are ephemeral and therefore do not require network security.

d)

Containers run on the same networking stack as virtual or bare metal applications and are 

vulnerable to the same network-based attacks.

29.

What type of firewalls are used in the data center as segmentation gateways to provide visibility into data center traffic? 

a)

Segment and secure non-virtualized servers with physical firewalls and the virtual network with VM- 

Series firewalls

b)

Physical firewalls should be used for all data center traffic.

c)

Data centers are mostly virtualized and only VM-Series firewalls need to be used

d)

Segment users with Prisma access

30.

What are two environments supported by the CN-Series firewall? (Choose 

two.)

a)

OpenStack

b)

OpenShift

c)

Native K8

d)

PositiveK

31.

Which component of a public cloud is used to simplify security deployment?

a)

Security Center

b)

Elastic Load Balancer

c)

Elastic Block Storage (EBS)

d)

Gateway Load Balancer (GWLB)

32.

Panorama has a plugin for which three integrations in a data center? (Choose 

three.)

a)

Cisco APIC

b)

VMware NSX Manager

c)

OpenShift orchestration controller

d)

Hyperconvergence solutions

e)

Nutanix

33.

Which tool can be used to automate the process of deploying CN-Series?

a)

Puppet

b)

Ansible

c)

Operator

d)

Postman

34.

Which two elements can be used to deploy VM-Series in a public cloud? 

(Choose two.)

a)

RedHat Operator Hub

b)

Manual deployment from Marketplace

c)

Azure Resource Manager (ARM) templates

d)

Palo Alto Networks customer support portal

35.

Which VM-Series deployment model within vSphere simplifies segmentation, provides flexibility by participating in the routing infrastructure, and does not 

require changes to the default virtual switch (vSwitch) and port-group security 

settings? 

a)

Layer 2

b)

Layer 3

c)

Layer 7

d)

Virtual wire (vwire)

36.

What is the correct path to get the YAML files from GitHub?

a)

Deployment\Environment\Kubernetes

b)

Kubernetes\Environment\Deployment

c)

Environment\Deployment\Kubernetes

d)

Deployment\Kubernetes\Environment

e)

Kubernetes\Deployment\Environment

37.

How do you upgrade a container?

a)

in the registry

b)

delete and redeploy

c)

modify the YAML file

d)

run a script

38.

In a CNF Deployment, what is used to direct traffic to the data plane?

a)

L3 Policy Based Routing (PBR)

b)

Default Route

c)

Proxy Arp

d)

Static Routes

39.

How is traffic forwarded in Cisco ACI fabrics?

a)

Static Routes

b)

Layer 2 Vlan

c)

Vwire

d)

Layer 3 policy-based redirect

40.

How is VM-Series deployed in Cisco ACI?

a)

Policy based redirect. (north-south)

b)

Layer 4 to Layer 7 services (east-west)

c)

Layer 3 overlay

d)

Layer 2

41.

What is required to use Terraform in Cloud NGFW?

a)

API access

b)

AWS credentials

c)

CLI access

d)

AWS STS role

42.

What are the beneifts of deploying CN-Series?

a)

Layer7 visibility

b)

cost efficient

c)

runtime security

d)

autoscaling

43.

What file format does Terraform Use?

a)

JSON

b)

YAML

c)

BAT

d)

HTML

44.

What does Prisma Cloud Compute provide?

a)

vulnerability mgmt in the CI process

b)

Identify and prevent compliance

c)

Runtime Defense

d)

Web App/API security

45.

What does Prisma Cloud Compute protect?

a)

CI process

b)

Docker registry

c)

code repository

d)

Production

e)

Windows Registry

46.

In order for NSX-T Manager to deploy VM-Series, what is required?

a)

Panorama connects to Palo Alto Networks Update Server

b)

Panorma connects to NsX-T Manager

c)

NSX-T Manager

d)

License installed on NSX-T Manager

47.

If DAGs are not showing up in Panorama, what is missing from NSX or needs to be done?

a)

Push the updated configuration from NSX-T Manager

b)

Delete the DG, template, svc mgr, and svc definition on Panorama. Delete the security group and redirect rule on NSX. Recreate the configuration

c)

Commit the configuration in Panorama

d)

Reboot Panorama

48.

What needs to be done to prevent HA split brain?

a)

Configure MGMT port as backup HA1

b)

Configure HA3 as backup link to HA2

c)

Configure any other data plane port as HA1 backup

d)

Configure HA2 as backup link.

49.

What is used in HA as the IP address when a failover occurs?

a)

IP address of the active interface.

b)

Floating IP

c)

HSRP

d)

Changes to the IP address of the new active firewall.

50.

What determines the primary firewall in an active/active HA pair?

a)

First one online

b)

Firewall controllling route table

c)

Device ID

d)

Lowest IP address

51.

What triggers a HA failover?

a)

ping monitoring

b)

path monitoring

c)

link monitoring

d)

heartbeat

52.

Why are CN-Series good for whitelisting?

a)

Operations has visibility into the app-scripts that should run

b)

The docker file contains a list of application that should be running.

c)

Compares to known CVEs

d)

microservices are intended by the developer to only execute certain applications.

53.

What protocol is used for communication between vm series and GWLB in AWS?

a)

Geneve

b)

GRE

c)

VRLAN

d)

VXLAN

54.

Where are containers typically patched?

a)

In registry

b)

At Instantiation

c)

in CI/CD

d)

At Shutdown

55.

What entity does Cloud Workload protection protect?

a)

Hosts

b)

Virtual Machines

c)

API Scripts

d)

Registry

56.

Why are cn-series beneficial for inspecting traffic between pods and other workloads?

a)

Ensures overall consistent security

b)

Protection against known and unknown Malware

c)

Protect east-west traffic

d)

Because I said so

57.

 What does Prisma Cloud Compute protect?

a)

Hosts

b)

Virtual Machines

c)

api scripts

d)

web apps

58.

When deploying terraform for cloud NGFW in AWS, what needs to be enabled?

a)

Access to support portal

b)

 access to cloud NGFW for AWS console

c)

 access to AWS firewall manager

d)

access to cloud NGFW AWS CLI

e)

Cloud NGFW for AWS API

59.

Who is the session owner in a HA firewall deployment?

a)

the one routing all traffic

b)

the one that receives the first packet

c)

the one with the most resources to identify packets

d)

the first one on

60.

What can you implement to avoid split brain in a A/A HA deployment?

a)

heartbeat backup

b)

ha1 backup

c)

enable preemption

d)

ha3 backup

61.

what entity provides internal network security for outbound traffic

a)

AURL

b)

DLP

c)

APP-ID

d)

WILDFIRE

62.

 what provides inspection and protection against encrypted traffic?

a)

TLS INSPECTION

b)

WILDFIRE

c)

THREAT PREVENTION

d)

AURL

63.

what provides inspection of a web server encrypted communication?

a)

APP-ID

b)

SSL INBOUND INSPECTION

c)

DNS security

d)

SSH INSPECTION

64.

what file format does kubernetes use?

a)

JSON

b)

XML

c)

EXE

d)

YAML

65.

NSX manager and vm-series firewall. What is needed for auto service deployment?

a)

The deployed vm-series connected to Panorama

b)

Panorama connection to NSX Manager

c)

Panorama connected to update server

d)

licenses added to NSX Manager

66.

Ansible is beneficial because?

a)

It is cloud-agnostic to all cloud platforms

b)

It provides easy orchestration across all platforms

c)

It does not require complex coding

d)

It is free

67.

 What entity provides real-time analysis and ML to protect against attacks?

a)

TP

b)

ANTI-SPYWARE

c)

DNS

d)

AURL

68.

what can be funded with VM flex credits?

a)

DNS SECURITY

b)

VIRTUAL PANORAMA INSTANCE

c)

MIGRATION FROM PAYG TO FLEX CREDITS

d)

Support

69.

What type of group makes it easier to define cloud-based tags on on-prem firewalls?

a)

Address

b)

Notify

c)

Device

d)

Template

70.

User case question about one VM group and you want to insert a VM-series firewall without having to change IP addresses or edit anything.

a)

move vms to another vswitch and enable v-wire between vSwitches

b)

add layer 3 interface on the firewall and enable Address Resolution Protocol (ARP)

c)

Steer traffic to an on-prem Palo Alto firewall

d)

Change the default gateway

71.

What two openstack components are used in the creation of VM-series firewall?

a)

Openstack Heat template

b)

 VM-series VHD image

c)

VM-series qsow2 image

d)

VM-Series bootstrap files

72.

In Pan-OS which three NSX features can be pushed from Panorama?

a)

User IP mapping to User

b)

Steering Rules

c)

  Multiple Authorization codes

d)

Security group assignments of VMs

e)

 Security Groups

73.

What features are required to integrate VM-series and NSX?

a)

User-id agent on windows controller

b)

NSX plugin

c)

vCenter

d)

NSX Manager

e)

VM-Series Plugin

74.

Where do you go to change a default route for an internet route?

a)

Network>Virtual Router

b)

Click on static tab and add static route

c)

Network> Interfaces

d)

Routing>Add Route

75.

AWS requIres what?

a)

A/P

b)

A/A

c)

3 INTERFACES

d)

GWLB

76.

What is required to connect to Azure Orchestration?

a)

API Key

b)

Azure OE agent

c)

Azure Active Directory

d)

Service Principal

77.

What does the VM-series plug-in provide?

a)

Manages the physical the same as vm-series

b)

Must match PAN-OS to the Plug-IN

c)

updating the cloud specific features

d)

management of the vm-series

78.

Does ACI require the VM-Series firewall as a gateway?

a)

TRUE

b)

FALSE

79.

Steps to deploy GWLB in AWS

a)

AWS Transit Gateway

b)

Security VPC

c)

VNET peering

80.

What do you need in GCP across East-West and different VPCs?

a)

GWLB

b)

ELB

c)

Transit Gateway

d)

Security VPC

81.

What type of deployments are available for NSX-T for east-west?

a)

bootstrap

b)

host

c)

service cluster

d)

arm template

82.

What does Prisma Cloud Compute do to block threats?

a)

Block container

b)

Change permissions

c)

Alert only

83.

What component allows to dynamically orchestrate security policy however does not force to change this policy?

a)

DAG

b)

EDL

c)

DUG

d)

API Scripts