wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Mock P C N S E Exam 5

Total questions: 75

Worksheet time: 3hrs 30mins

Name
Class
Date
1.

An administrator connects four new remote offices to the corporate data center. The administrator decides to use the Large Scale VPN (LSVPN) feature on the Palo Alto Networks next-generation firewall.

What should the administrator configure in order to connect the sites?

a)

Generic Routing Encapsulation (GRE) Tunnels

b)

GlobalProtect Satellite

c)

SD-WAN

d)

IKE Gateways

2.

A customer wants to set up a site-to-site VPN using tunnel interfaces.

What format is the correct naming convention for tunnel interfaces?

a)

tun.1025

b)

tunnel.50

c)

vpn.1024

d)

gre1/2

3.

An engineer notices that the tunnel monitoring has been failing for a day and the VPN should have failed over to a backup path.

What part of the network profile configuration should the engineer verify?

a)

Destination IP

b)

Threshold

c)

Action

d)

Interval

4.

Which three multi-factor authentication methods can be used to authenticate access to the firewall? (Choose three.)

a)

One-time password

b)

User certificate

c)

SMS

d)

Voice

e)

Fingerprint

5.

Which two profiles should be configured when sharing tags from threat logs with a remote User-ID agent? (Choose two.)

a)

LDAP

b)

Log Ingestion

c)

HTTP

d)

Log Forwarding

6.

What is the PAN-OS NPTv6 feature based on RFC 6296 used for?

a)

Application port number translation

b)

IPv6-to-IPv6 network prefix translation

c)

Stateful translation to provide better security

d)

IPv6-to-IPv6 host portion translation

7.

An administrator has been tasked with deploying SSL Forward Proxy.

Which two types of certificates are used to decrypt the traffic? (Choose two.)

a)

Device certificate

b)

Subordinate CA from the administrator’s own PKI infrastructure

c)

Self-signed root CA

d)

External CA certificate

8.

An engineer is deploying multiple firewalls with common configuration in Panorama.

What are two benefits of using nested device groups? (Choose two.)

a)

Inherit all Security policy rules and objects

b)

Inherit settings from the Shared group

c)

Inherit IPSec crypto profiles

d)

Inherit parent Security policy rules and objects

9.

A network security administrator wants to inspect HTTPS traffic from users as it egresses through a firewall to the Internet/Untrust zone from trusted network zones. The security admin wishes to ensure that if users are presented with invalid or untrusted security certificates, the user will see an untrusted certificate warning.

What is the best choice for an SSL Forward Untrust certificate?

a)

A self-signed certificate generated on the firewall

b)

A web server certificate signed by the organization’s PKI

c)

A web server certificate signed by an external Certificate Authority

d)

A subordinate Certificate Authority certificate signed by the organization’s PKI

10.

After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall. After troubleshooting, the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports.

What can the engineer do to solve the VoIP traffic issue?

a)

Disable ALG under H.323 application

b)

Increase the TCP timeout under H.323 application

c)

Increase the TCP timeout under SIP application

d)

Disable ALG under SIP application

11.

After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?

a)

Ensure Force Template Values is checked when pushing configuration.

b)

Push the Template first, then push Device Group to the newly managed firewall.

c)

Push the Device Group first, then push Template to the newly managed firewall.

d)

Perform the Export or push Device Config Bundle to the newly managed firewall.

12.

Which new PAN-OS 11.0 feature supports IPv6 traffic?

a)

OSPF

b)

IKEv1

c)

DHCP Server

d)

DHCPv6 Client with Prefix Delegation

13.

If a URL is in multiple custom URL categories with different actions, which action will take priority?

a)

Block

b)

Allow

c)

Alert

d)

Override

14.

An engineer is reviewing the following high availability (HA) settings to understand a recent HA failover event.
Which timer determines the frequency between packets sent to verify that the HA functionality on the other HA firewall is operational?

a)

Hello Interval

b)

Monitor Fail Hold Up Time

c)

Heartbeat Interval

d)

Promotion Hold Time

15.

Which three items must be configured to implement application override? (Choose three.)

a)

Application filter

b)

Application override policy rule

c)

Custom app

d)

Decryption policy rule

e)

Security policy rule

16.

Which three items must be configured to implement application override? (Choose three.)

a)

Application filter

b)

Application override policy rule

c)

Custom app

d)

Decryption policy rule

e)

Security policy rule

17.

An engineer is configuring a firewall with three interfaces:

• MGT connects to a switch with internet access.

• Ethernet1/1 connects to an edge router.

• Ethernet1/2 connects to a virtualization network.

The engineer needs to configure dynamic updates to use a dataplane interface for internet traffic.

What should be configured in Setup > Services > Service Route Configuration to allow this traffic?

a)

Set DNS and Palo Alto Networks Services to use the MGT source interface.

b)

Set DNS and Palo Alto Networks Services to use the ethernet1/1 source interface.

c)

Set DNS and Palo Alto Networks Services to use the ethernet1/2 source interface.

d)

Set DDNS and Palo Alto Networks Services to use the MGT source interface.

18.

An organization conducts research on the benefits of leveraging the Web Proxy feature of PAN-OS 11.0.

What are two benefits of using an explicit proxy method versus a transparent proxy method? (Choose two.)

a)

No client configuration is required for explicit proxy, which simplifies the deployment complexity.

b)

Explicit proxy supports interception of traffic using non-standard HTTPS ports.

c)

It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request.

d)

Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy.

19.

Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)

a)

TACACS+

b)

Kerberos

c)

SAML

d)

RADIUS

e)

LDAP

20.

With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?

a)

insufficient-data

b)

incomplete

c)

not-applicable

d)

unknown-tcp

21.

To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?

a)

Clone the security policy and add it to the other device groups.

b)

Add the policy to the target device group and apply a master device to the device group.

c)

Reference the targeted device’s templates in the target device group.

d)

Add the policy in the shared device group as a pre-rule.

22.

Based on the graphic, which statement accurately describes the output shown in the Server Monitoring panel?

a)

The User-ID agent is connected to a domain controller labeled lab-client.

b)

The host lab-client has been found by the User-ID agent.

c)

The host lab-client has been found by a domain controller.

d)

The User-ID agent is connected to the firewall labeled lab-client.

23.

What can be used as an Action when creating a Policy-Based Forwarding (PBF) policy?

a)

Deny

b)

Allow

c)

Discard

d)

Next VR

24.

An engineer manages a high availability network and requires fast failover of the routing protocols. The engineer decides to implement BFD.

Which three dynamic routing protocols support BFD? (Choose three.)

a)

OSPF

b)

IGRP

c)

OSPFv3 virtual link

d)

BGP

e)

RIP

25.

A company has recently migrated their branch office’s PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template configuration is managed solely within Panorama.

They notice that commit times have drastically increased for the PA-220s after the migration.

What can they do to reduce commit times?

a)

Disable “Share Unused Address and Service Objects with Devices” in Panorama Settings.

b)

Perform a device group push using the “merge with device candidate config” option.

c)

Update the apps and threat version using device-deployment.

d)

Use “export or push device config bundle” to ensure that the firewall is integrated with the Panorama config.

26.

An administrator is troubleshooting why video traffic is not being properly classified.

If this traffic does not match any QoS classes, what default class is assigned?

a)

1

b)

2

c)

3

d)

4

27.

An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.

What is one way the administrator can meet this requirement?

a)

Reload the running configuration and perform a Firewall local commit.

b)

Perform a commit force from the CLI of the firewall.

c)

Perform a template commit push from Panorama using the “Force Template Values” option.

d)

Perform a device-group commit push from Panorama using the “Include Device and Network Templates” option.

28.

Where can a service route be configured for a specific destination IP?

a)

Use Network > Virtual Routers, select the Virtual Router > Static Routes > IPv4

b)

Use Device > Setup > Services > Services

c)

Use Device > Setup > Services > Service Route Configuration > Customize > IPv4

d)

Use Device > Setup > Services > Service Route Configuration > Customize > Destination

29.

Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration.

What part of the configuration should the engineer verify?

a)

IKE Crypto Profile

b)

Security policy

c)

Proxy-IDs

d)

PAN-OS versions

30.

Information Security is enforcing group-based policies by using security-event monitoring on Windows User-ID agents for IP-to-User mapping in the network. During the rollout, Information Security identified a gap for users authenticating to their VPN and wireless networks.

Root cause analysis showed that users were authenticating via RADIUS and that authentication events were not captured on the domain controllers that were being monitored. Information Security found that authentication events existed on the Identity Management solution (IDM).

There did not appear to be direct integration between PAN-OS and the IDM solution.

How can Information Security extract and learn IP-to-user mapping information from authentication events for VPN and wireless users?

a)

Configure the integrated User-ID agent on PAN-OS to accept Syslog messages over TLS.

b)

Configure the User-ID XML API on PAN-OS firewalls to pull the authentication events directly from the IDM solution.

c)

Add domain controllers that might be missing to perform security-event monitoring for VPN and wireless users.

d)

Configure the Windows User-ID agents to monitor the VPN concentrators and wireless controllers for IP-to-User mapping.

31.

An administrator troubleshoots an issue that causes packet drops.

Which log type will help the engineer verify whether packet buffer protection was activated?

a)

Configuration

b)

Data Filtering

c)

Traffic

d)

Threat

32.

An engineer creates a set of rules in a Device Group (Panorama) to permit traffic to various services for a specific LDAP user group.

What needs to be configured to ensure Panorama can retrieve user and group information for use in these rules?

a)

A service route to the LDAP server

b)

A User-ID agent on the LDAP server

c)

A Master Device

d)

Authentication Portal

33.

Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.

Given the rule below, what change should be made to make sure the NAT works as expected?

a)

Change destination NAT zone to Trust_L3.

b)

Change destination translation to Dynamic IP (with session distribution) using firewall eth1/2 address.

c)

Change Source NAT zone to Untrust_L3.

d)

Add source Translation to translate original source IP to the firewall eth1/2 interface translation.

34.

An engineer is configuring a template in Panorama which will contain settings that need to be applied to all firewalls in production.

Which three parts of a template an engineer can configure? (Choose three.)

a)

Service Route Configuration

b)

Dynamic Address Groups

c)

NTP Server Address

d)

Antivirus Profile

e)

Authentication Profile

35.

A firewall engineer reviews the PAN-OS GlobalProtect application and sees that it implicitly uses web-browsing and depends on SSL.

When creating a new rule, what is needed to allow the application to resolve dependencies?

a)

Add SSL application to the same rule.

b)

SSL and web-browsing must both be explicitly allowed.

c)

Add SSL and web-browsing applications to the same rule.

d)

Add web-browsing application to the same rule.

36.

In a security-first network, what is the recommended threshold value for apps and threats to be dynamically updated?

a)

1 to 4 hours

b)

6 to 12 hours

c)

24 hours

d)

36 hours

37.

An engineer configures a specific service route in an environment with multiple virtual systems instead of using the inherited global service route configuration.

What type of service route can be used for this configuration?

a)

Destination-Based Service Route

b)

Inherit Global Setting

c)

IPv6 Source or Destination Address

d)

IPv4 Source Interface

38.

An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of VoIP traffic.

Which three elements should the administrator configure to address this issue? (Choose three.)

a)

A QoS policy for each application

b)

An Application Override policy for the SIP traffic

c)

A QoS profile defining traffic classes

d)

QoS on the ingress interface for the traffic flows

e)

QoS on the egress interface for the traffic flows

39.

What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three.)

a)

Rename a vsys on a multi-vsys firewall

b)

Change the firewall management IP address

c)

Enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode

d)

Add administrator accounts

e)

Configure a device block list

40.

Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?

a)

shared pre-rules

DATACENTER_DG pre-rules -

rules configured locally on the firewall

DATACENTER_DG post-rules -

shared post-rules

shared default rules

b)

shared pre-rules

DATACENTER_DG pre-rules -

rules configured locally on the firewall

shared post-rules

DATACENTER_DG post-rules -

DATACENTER_DG default rules

c)

shared pre-rules

DATACENTER_DG pre-rules -

rules configured locally on the firewall

shared post-rules

DATACENTER_DG post-rules -

shared default rules

d)

shared pre-rules

DATACENTER_DG pre-rules -

rules configured locally on the firewall

DATACENTER_DG post-rules -

shared post-rules

DATACENTER_DG default rules

41.

A company wants to implement threat prevention to take action without redesigning the network routing.

What are two best practice deployment modes for the firewall? (Choose two.)

a)

Virtual Wire

b)

Layer 2

c)

Layer 3

d)

TAP

42.

Which operation will impact the performance of the management plane?

a)

Enabling DoS protection

b)

Enabling packet buffer protection

c)

Decrypting SSL sessions

d)

Generating a Saas Application report

43.

Which type of policy in Palo Alto Networks firewalls can use Device-ID as a match condition?

a)

Tunnel inspection

b)

NAT

c)

QoS

d)

DOS protection

44.

Why would a traffic log list an application as "not-applicable"?

a)

There was not enough application data after the TCP connection was established.

b)

The TCP connection terminated without identifying any application data.

c)

The firewall denied the traffic before the application match could be performed.

d)

The application is not a known Palo Alto Networks App-ID.

45.

What must be configured to apply tags automatically based on User-ID logs?

a)

Device ID

b)

Log settings

c)

Group mapping

d)

Log Forwarding profile

46.

A firewall engineer creates a NAT rule to translate IP address 1.1.1.10 to 192.168.1.10. The engineer also plans to enable DNS rewrite so that the firewall rewrites the IPv4 address in a DNS response based on the original destination IP address and translated destination IP address configured for the rule. The engineer wants the firewall to rewrite a DNS response of 1.1.1.10 to 192.168.1.10.

What should the engineer do to complete the configuration?

a)

Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.

b)

Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.

c)

Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.

d)

Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53.

47.

An engineer is monitoring an active/active high availability (HA) firewall pair.

Which HA firewall state describes the firewall that is experiencing a failure of a monitored path?

a)

Initial

b)

Passive

c)

Active-secondary

d)

Tentative

48.

You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles.

For which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three.)

a)

Critical

b)

High

c)

Medium

d)

Informational

e)

Low

49.

In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?

a)

Applications configured in the rule with their dependencies

b)

The security rule with any other security rule selected

c)

Applications configured in the rule with applications seen from traffic matching the same rule

d)

The running configuration with the candidate configuration of the firewall

50.

Given the following snippet of a WildFire submission log, did the end user successfully download a file?

a)

Yes, because the final action is set to "allow."

b)

No, because the action for the wildfire-virus is "reset-both."

c)

No, because the URL generated an alert.

d)

Yes, because both the web-browsing application and the flash file have the "alert" action.

51.

Which two factors should be considered when sizing a decryption firewall deployment? (Choose two.)

a)

Number of security zones in decryption policies

b)

Encryption algorithm

c)

TLS protocol version

d)

Number of blocked sessions

52.

After switching to a different WAN connection, users have reported that various websites will not load, and timeouts are occurring. The web servers work fine from other locations.

The firewall engineer discovers that some return traffic from these web servers is not reaching the users behind the firewall. The engineer later concludes that the maximum transmission unit (MTU) on an upstream router interface is set to 1400 bytes.

The engineer reviews the following CLI output for ethernet1/1.

Which setting should be modified on ethernet1/1 to remedy this problem?

a)

Change the subnet mask from /23 to /24.

b)

Lower the interface MTU value below 1500.

c)

Adjust the TCP maximum segment size (MSS) value

d)

Enable the Ignore IPv4 Don't Fragment (DF) setting.

53.

A company requires the firewall to block expired certificates issued by internet-hosted websites. The company plans to implement decryption in the future, but it does not perform SSL Forward Proxy decryption at this time.

Without the use of SSL Forward Proxy decryption, how is the firewall still able to identify and block expired certificates issued by internet-hosted websites?

a)

By having a Certificate profile that contains the website's Root CA assigned to the respective Security policy rule

b)

By using SSL Forward Proxy to decrypt SSL and TLS handshake communication and the server/client session keys in order to validate a certificate's authenticity and expiration

c)

By using SSL Forward Proxy to decrypt SSL and TLS handshake communication in order to validate a certificates authenticity and expiration

d)

By having a Decryption profile that blocks sessions with expired certificates in the No Decryption section and assigning it to a No Decrypt policy rule

54.

A company is looking to increase redundancy in their network.

Which interface type could help accomplish this?

a)

Tap

b)

Layer 2

c)

Virtual wire

d)

Aggregate ethernet

55.

An engineer is deploying VoIP and needs to ensure that voice traffic is treated with the highest priority on the network.

Which QoS priority should be assigned to such an application?

a)

Medium

b)

Low

c)

High

d)

Real-time

56.

The decision to upgrade to PAN-OS 10.2 has been approved. The engineer begins the process by upgrading the Panorama servers, but gets an error when trying to install.

When performing an upgrade on Panorama to PAN-OS 10.2, what is the potential cause of a failed install?

a)

GlobalProtect agent version

b)

Outdated plugins

c)

Management only mode

d)

Expired certificates

57.

How can Panorama help with troubleshooting problems such as high CPU or resource exhaustion on a managed firewall?

a)

Firewalls send SNMP traps to Panorama when resource exhaustion is detected. Panorama generates a system log and can send email alerts.

b)

Panorama provides visibility into all the system and traffic logs received from firewalls. It does not offer any ability to see or monitor resource utilization on managed firewalls.

c)

Panorama provides information about system resources of the managed devices in the Managed Devices > Health menu.

d)

Panorama monitors all firewalls using SNMP. It generates a system log and can send email alerts when resource exhaustion is detected on a managed firewall.

58.

An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall.

When certificates are being imported to the firewall for these purposes, which three certificates require a private key? (Choose three.)

a)

Forward Untrust certificate

b)

Enterprise Root CA certificate

c)

Forward Trust certificate

d)

End-entity (leaf) certificate

e)

Intermediate certificate(s)

59.

An administrator would like to determine which action the firewall will take for a specific CVE.

Given the screenshot below, where should the administrator navigate to view this information?

a)

The profile rule action

b)

CVE column

c)

The profile rule threat name

d)

Exceptions tab

60.

In an HA failover scenario what happens with sessions decrypted by a SSL Forward Proxy Decryption policy?

a)

The existing session is transferred to the active firewall.

b)

The firewall drops the session.

c)

The session is sent to fastpath.

d)

The firewall allows the session but does not decrypt the session.

61.

An administrator just enabled HA Heartbeat Backup on two devices. However, the status on the firewall's dashboard is showing as down.

What could an administrator do to troubleshoot the issue?

a)

Go to Device > High Availability > General > HA Pair Settings > Setup and configuring the peer IP for heartbeat backup

b)

Go to Device > High Availability > HA Communications > General > and check the Heartbeat Backup under Election Settings

c)

Check peer IP address for heartbeat backup to Device > High Availability > HA Communications > Packet Forwarding settings

d)

Check peer IP address in the permit list in Device > Setup > Management > Interfaces > Management Interface Settings

62.

An engineer troubleshoots an issue that causes packet drops.

Which command should the engineer run in the CLI to see if packet buffer protection is enabled and activated?

a)

show session id

b)

show system state | match packet-buffer-protection

c)

show session packet-buffer- protection

d)

show running resource-monitor

63.

An engineer configures SSL decryption in order to have more visibility to the internal users’ traffic when it is egressing the firewall.

Which three types of interfaces support SSL Forward Proxy? (Choose three.)

a)

High availability (HA)

b)

Layer 3

c)

Layer 2

d)

Tap

e)

Virtual Wire

64.

If an administrator wants to apply QoS to traffic based on source, what must be specified in a QoS policy rule?

a)

Post-NAT destination address

b)

Pre-NAT destination address

c)

Pre-NAT source address

d)

Post-NAT source address

65.

An engineer reviews high availability (HA) settings to understand a recent HA failover event. Review the screenshot below.

Which timer determines how long the passive firewall will wait before taking over as the active firewall after losing communications with the HA peer?

a)

Heartbeat Interval

b)

Promotion Hold Time

c)

Additional Master Hold Up Time

d)

Monitor Fail Hold Up Time

66.

A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below.

What should the NAT rule destination zone be set to?

a)

None

b)

Inside

c)

DMZ

d)

Outside

67.

A consultant deploys a PAN-OS 11.0 VM-Series firewall with the Web Proxy feature in Transparent Proxy mode.

Which three elements must be in place before a transparent web proxy can function? (Choose three.)

a)

User-ID for the proxy zone

b)

DNS Security license

c)

Prisma Access explicit proxy license

d)

Cortex Data Lake license

e)

Authentication Policy Rule set to default-web-form

68.

Which source is the most reliable for collecting User-ID user mapping?

a)

Microsoft Active Directory

b)

Microsoft Exchange

c)

GlobalProtect

d)

Syslog Listener

69.

Which type of zone will allow different virtual systems to communicate with each other?

a)

Tap

b)

Tunnel

c)

Virtual Wire

d)

External

70.

An organization is interested in migrating from their existing web proxy architecture to the Web Proxy feature of their PAN-OS 11.0 firewalls. Currently, HTTP and SSL requests contain the destination IP address of the web server and the client browser is redirected to the proxy.

Which PAN-OS proxy method should be configured to maintain this type of traffic flow?

a)

SSL forward proxy

b)

Explicit proxy

c)

Transparent proxy

d)

DNS proxy

71.

An engineer discovers the management interface is not routable to the User-ID agent.

What configuration is needed to allow the firewall to communicate to the User-ID agent?

a)

Add a Policy Based Forwarding (PBF) policy to the User-ID agent IP

b)

Create a NAT policy for the User-ID agent server

c)

Create a custom service route for the UID Agent

d)

Add a static route to the virtual router

72.

An engineer receives reports from users that applications are not working and that websites are only partially loading in an asymmetric environment. After investigating, the engineer observes the flow_tcp_non_syn_drop counter increasing in the show counters global output.

Which troubleshooting command should the engineer use to work around this issue?

a)

set deviceconfig setting tcp asymmetric-path drop

b)

set session tcp-reject-non-syn yes

c)

set deviceconfig setting tcp asymmetric-path bypass

d)

set deviceconfig setting session tcp-reject-non-syn no

73.

Where is Palo Alto Networks Device Telemetry data stored on a firewall with a device certificate installed?

a)

Panorama

b)

M600 Log Collectors

c)

Cortex Data Lake

d)

On Palo Alto Networks Update Servers

74.

Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?

a)

Satellite mode

b)

Tunnel mode

c)

No Direct Access to local networks

d)

IPSec mode

75.

A superuser is tasked with creating administrator accounts for three contractors. For compliance purposes, all three contractors will be working with different device-groups in their hierarchy to deploy policies and objects.

Which type of role-based access is most appropriate for this project?

a)

Create a Dynamic Admin with the Panorama Administrator role.

b)

Create a Dynamic Read only superuser.

c)

Create a Device Group and Template Admin.

d)

Create a Custom Panorama Admin.