WorksheetsSoftware NGFW Associate
Total questions: 83
Worksheet time: 50mins
What is the primary purpose of applying infrastructure tags in the public
cloud?
Increasing cloud resource visibility
Connecting security posture to CI/CD pipeline
Dynamically applying policy as the environment changes
Synchronizing native cloud security policy with the firewall
Which compliance regulation must an organization follow when storing, processing, or transmitting payment cardholder data?
Payment Card Industry (PCI)
Protected Cardholder Data (PCD)
Guaranteed Basic Livable Income (GLBI)
Health Insurance Portability and Accountability Act of 1996
What is the preferred way to analyze traffic logs generated from multiple data
center firewalls?
Use Palo Alto Networks Prisma Access console to view all firewall logs
Log in to one of the firewalls in order to request the log of the other firewalls.
Log in to each firewall and generate the log in a PDF format before analyzing it
Use Panorama for aggregated logging with central oversight for analysis and reporting.
What is used to deploy CN-Series firewalls within a Kubernetes cluster?
YAML files
Docker images
License authorization codes
Kubernetes plugin for Panorama
What is the unit of autoscaling for CN-Series and VM-Series firewalls?
Nodes
VCPUs
Clusters
Gigabytes
Which plugin is required to enable Panorama to connect to and manage a
cluster running CN-Series?
Docker
vCluster
Kubernetes
Amazon ECS
What is used to apply policies that can track public/private cloud resources?
URLS
IP addresses
Access Control Lists
Dynamic address groups
Which technology allows for granular control of east-west traffic in a
software-defined network?
Routing
Virtualization
Microsegmentation
MAC Access Control List
Which Palo Alto Networks product provides centralized security, control, and visibility for a multicloud environment?
WildFire
Panorama
DNS security
GlobalProtect
What is Palo Alto Networks software firewall credit licensing is based on?
VCPU
Memory
Storage
Throughput
Where are sample automation templates for VM-Series and CN-Series located?
Marketplace
Palo Alto Networks support center
Palo Alto Networks public github repo
Palo Alto Networks public documentation
How can the Palo Alto Networks Next-Generation Firewall (NGFW) simplify
security deployments for software-defined networks (SDNs) in a data center?
By applying the data center version of PAN-OS
By using the Palo Alto Networks SDN controller
By deploying the Palo Alto Networks Cortex XDR SDN feature
By integrating with the leading virtualization and SDN solutions
Which tool should be used to estimate the number of credits required for a VM-Series or CN-Series deployment?
Software NGFW Credit Estimator
Customer service portal
TechDocs
Salesforce
Which security subscription provides an inline web protection engine powered by deep learning to stop unknown web-based attacks in real time?
DNS Security
GlobalProtect
Intelligent traffic offload
Advanced URL Filtering (AURLF)
With which three private cloud environments does Palo Alto Networks have
deep integrations? (Choose three.)
Nutanix
Cisco ACI
Dell APEX
HPE Synergy
VMware NSX-T
Which third-party tool allows customers to easily deploy and manage CN-
Series?
AWS Marketplace
Alicloud Marketplace
IBM Cloud Marketplace
Digital Ocean Marketplace
What are two functions of CN-Series next-generation firewalls (NGFWs) in Kubernetes environments? (Choose two.)
Replacing the CI/CD pipeline security tools
Providing Layer 7 visibility into container traffic
Replacing VM-Series firewalls for network security in the data center
Enforcing security policies with threat prevention profiles between namespaces
Which two CN-Series deployment options provide visibility into Kubernetes
clusters? (Choose two.)
CNF
Hybrid
Daemonset
Kubernetes service
Which portal allows management and monitoring of flex credits?
Olive.paloaltonetworks.com
sales.paloaltonetworks.com
beacon.paloaltonetworks.com
customersupport.paloaltonetworks.com
Which three subscriptions should be recommended to a customer who is
deploying VM-Series firewalls to a private data center, but is concerned with
protecting data center resources from malware and lateral movement?
(Choose three.)
WildFire
SD-WAN
GlobalProtect
Threat Prevention
Intelligent Traffic Offload
Which VM-Series deployment model within vSphere allows for firewall
insertion into an existing network and will also require additional VLANs for
each tenant or application boundary?
Layer 2
Layer 3
Layer 7
Virtual wire (vwire)
In which two locations can information pertaining to Palo Alto Networks software firewalls be located? (Choose two.)
TechDocs
StackOverflow
Product landing pages
Google Container Registry
Which two pieces of information are needed prior to estimating the number of
software next-generation firewall (NGFW) credits that a VM-Series or CN-
Series deployment requires? (Choose two.)
Number of nodes
Scaling requirements
Deployment environment
Number of availability zones
Which level of abstraction allows definition of common policy across multiple next-generation firewalls (NGFWs) in Panorama?
Zones
Interfaces
Zone profiles
Security profiles
What is the maximum number of application pods that a CN-Series can secure on a single node?
12
18
30
36
Why are dynamic address groups critical to modern network security?
They enable DNS port forwarding
They create a pool of IP addresses that can be used for security purposes.
They provide a way to consistently apply policies to a set of dynamically changing resources.
They allow customers to apply cloud delivered security subscriptions to their VM-Series or CN-Series deployments.
Which two configuration objects will allow servers from different operating system (OS) types to get package updates from a given domain? (Choose two.)
Static IP address objects for every server, grouped together by OS type
A single external dynamic list that maintains a list of all of the update domains
One custom URL category for each list of update domains needed for a particular OS type
A dynamic address group mapped to an NSX-T inventory group that groups virtual machines (VMs) and bare metal servers together based on OS type
What are two reasons network security is important for containerized
applications? (Choose two.)
Shift-left products are designed to provide end-to-end security
It provides protection against unpatched and unknown vulnerabilities.
Containers are ephemeral and therefore do not require network security.
Containers run on the same networking stack as virtual or bare metal applications and are
vulnerable to the same network-based attacks.
What type of firewalls are used in the data center as segmentation gateways to provide visibility into data center traffic?
Segment and secure non-virtualized servers with physical firewalls and the virtual network with VM-
Series firewalls
Physical firewalls should be used for all data center traffic.
Data centers are mostly virtualized and only VM-Series firewalls need to be used
Segment users with Prisma access
What are two environments supported by the CN-Series firewall? (Choose
two.)
OpenStack
OpenShift
Native K8
PositiveK
Which component of a public cloud is used to simplify security deployment?
Security Center
Elastic Load Balancer
Elastic Block Storage (EBS)
Gateway Load Balancer (GWLB)
Panorama has a plugin for which three integrations in a data center? (Choose
three.)
Cisco APIC
VMware NSX Manager
OpenShift orchestration controller
Hyperconvergence solutions
Nutanix
Which tool can be used to automate the process of deploying CN-Series?
Puppet
Ansible
Operator
Postman
Which two elements can be used to deploy VM-Series in a public cloud?
(Choose two.)
RedHat Operator Hub
Manual deployment from Marketplace
Azure Resource Manager (ARM) templates
Palo Alto Networks customer support portal
Which VM-Series deployment model within vSphere simplifies segmentation, provides flexibility by participating in the routing infrastructure, and does not
require changes to the default virtual switch (vSwitch) and port-group security
settings?
Layer 2
Layer 3
Layer 7
Virtual wire (vwire)
What is the correct path to get the YAML files from GitHub?
Deployment\Environment\Kubernetes
Kubernetes\Environment\Deployment
Environment\Deployment\Kubernetes
Deployment\Kubernetes\Environment
Kubernetes\Deployment\Environment
How do you upgrade a container?
in the registry
delete and redeploy
modify the YAML file
run a script
In a CNF Deployment, what is used to direct traffic to the data plane?
L3 Policy Based Routing (PBR)
Default Route
Proxy Arp
Static Routes
How is traffic forwarded in Cisco ACI fabrics?
Static Routes
Layer 2 Vlan
Vwire
Layer 3 policy-based redirect
How is VM-Series deployed in Cisco ACI?
Policy based redirect. (north-south)
Layer 4 to Layer 7 services (east-west)
Layer 3 overlay
Layer 2
What is required to use Terraform in Cloud NGFW?
API access
AWS credentials
CLI access
AWS STS role
What are the beneifts of deploying CN-Series?
Layer7 visibility
cost efficient
runtime security
autoscaling
What file format does Terraform Use?
JSON
YAML
BAT
HTML
What does Prisma Cloud Compute provide?
vulnerability mgmt in the CI process
Identify and prevent compliance
Runtime Defense
Web App/API security
What does Prisma Cloud Compute protect?
CI process
Docker registry
code repository
Production
Windows Registry
In order for NSX-T Manager to deploy VM-Series, what is required?
Panorama connects to Palo Alto Networks Update Server
Panorma connects to NsX-T Manager
NSX-T Manager
License installed on NSX-T Manager
If DAGs are not showing up in Panorama, what is missing from NSX or needs to be done?
Push the updated configuration from NSX-T Manager
Delete the DG, template, svc mgr, and svc definition on Panorama. Delete the security group and redirect rule on NSX. Recreate the configuration
Commit the configuration in Panorama
Reboot Panorama
What needs to be done to prevent HA split brain?
Configure MGMT port as backup HA1
Configure HA3 as backup link to HA2
Configure any other data plane port as HA1 backup
Configure HA2 as backup link.
What is used in HA as the IP address when a failover occurs?
IP address of the active interface.
Floating IP
HSRP
Changes to the IP address of the new active firewall.
What determines the primary firewall in an active/active HA pair?
First one online
Firewall controllling route table
Device ID
Lowest IP address
What triggers a HA failover?
ping monitoring
path monitoring
link monitoring
heartbeat
Why are CN-Series good for whitelisting?
Operations has visibility into the app-scripts that should run
The docker file contains a list of application that should be running.
Compares to known CVEs
microservices are intended by the developer to only execute certain applications.
What protocol is used for communication between vm series and GWLB in AWS?
Geneve
GRE
VRLAN
VXLAN
Where are containers typically patched?
In registry
At Instantiation
in CI/CD
At Shutdown
What entity does Cloud Workload protection protect?
Hosts
Virtual Machines
API Scripts
Registry
Why are cn-series beneficial for inspecting traffic between pods and other workloads?
Ensures overall consistent security
Protection against known and unknown Malware
Protect east-west traffic
Because I said so
What does Prisma Cloud Compute protect?
Hosts
Virtual Machines
api scripts
web apps
When deploying terraform for cloud NGFW in AWS, what needs to be enabled?
Access to support portal
access to cloud NGFW for AWS console
access to AWS firewall manager
access to cloud NGFW AWS CLI
Cloud NGFW for AWS API
Who is the session owner in a HA firewall deployment?
the one routing all traffic
the one that receives the first packet
the one with the most resources to identify packets
the first one on
What can you implement to avoid split brain in a A/A HA deployment?
heartbeat backup
ha1 backup
enable preemption
ha3 backup
what entity provides internal network security for outbound traffic
AURL
DLP
APP-ID
WILDFIRE
what provides inspection and protection against encrypted traffic?
TLS INSPECTION
WILDFIRE
THREAT PREVENTION
AURL
what provides inspection of a web server encrypted communication?
APP-ID
SSL INBOUND INSPECTION
DNS security
SSH INSPECTION
what file format does kubernetes use?
JSON
XML
EXE
YAML
NSX manager and vm-series firewall. What is needed for auto service deployment?
The deployed vm-series connected to Panorama
Panorama connection to NSX Manager
Panorama connected to update server
licenses added to NSX Manager
Ansible is beneficial because?
It is cloud-agnostic to all cloud platforms
It provides easy orchestration across all platforms
It does not require complex coding
It is free
What entity provides real-time analysis and ML to protect against attacks?
TP
ANTI-SPYWARE
DNS
AURL
what can be funded with VM flex credits?
DNS SECURITY
VIRTUAL PANORAMA INSTANCE
MIGRATION FROM PAYG TO FLEX CREDITS
Support
What type of group makes it easier to define cloud-based tags on on-prem firewalls?
Address
Notify
Device
Template
User case question about one VM group and you want to insert a VM-series firewall without having to change IP addresses or edit anything.
move vms to another vswitch and enable v-wire between vSwitches
add layer 3 interface on the firewall and enable Address Resolution Protocol (ARP)
Steer traffic to an on-prem Palo Alto firewall
Change the default gateway
What two openstack components are used in the creation of VM-series firewall?
Openstack Heat template
VM-series VHD image
VM-series qsow2 image
VM-Series bootstrap files
In Pan-OS which three NSX features can be pushed from Panorama?
User IP mapping to User
Steering Rules
Multiple Authorization codes
Security group assignments of VMs
Security Groups
What features are required to integrate VM-series and NSX?
User-id agent on windows controller
NSX plugin
vCenter
NSX Manager
VM-Series Plugin
Where do you go to change a default route for an internet route?
Network>Virtual Router
Click on static tab and add static route
Network> Interfaces
Routing>Add Route
AWS requIres what?
A/P
A/A
3 INTERFACES
GWLB
What is required to connect to Azure Orchestration?
API Key
Azure OE agent
Azure Active Directory
Service Principal
What does the VM-series plug-in provide?
Manages the physical the same as vm-series
Must match PAN-OS to the Plug-IN
updating the cloud specific features
management of the vm-series
Does ACI require the VM-Series firewall as a gateway?
TRUE
FALSE
Steps to deploy GWLB in AWS
AWS Transit Gateway
Security VPC
VNET peering
What do you need in GCP across East-West and different VPCs?
GWLB
ELB
Transit Gateway
Security VPC
What type of deployments are available for NSX-T for east-west?
bootstrap
host
service cluster
arm template
What does Prisma Cloud Compute do to block threats?
Block container
Change permissions
Alert only
What component allows to dynamically orchestrate security policy however does not force to change this policy?
DAG
EDL
DUG
API Scripts
