wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 1 Question 161 to 180

Total questions: 20

Worksheet time: 12mins

Name
Class
Date
1.

Which two events trigger the operation of automatic commit recovery? (Choose two.)

a)

when an aggregate Ethernet interface component fails

b)

when Panorama pushes a configuration

c)

when a firewall performs a local commi

d)

when a firewall HA pair fails over

2.

Panorama provides which two SD-WAN functions? (Choose two.)

a)

network monitoring

b)

control plane

c)

data plane

d)

physical network links

3.

Updates to dynamic user group membership are automatic therefore using dynamic user groups instead of static group objects allows you to:

a)

respond to changes in user behaviour or potential threats using manual policy changes

b)

respond to changes in user behaviour or potential threats without manual policy changes

c)

respond to changes in user behaviour or potential threats without automatic policy changes

d)

respond to changes in user behaviour and confirmed threats with manual policy changes

4.

How can an administrator configure the firewall to automatically quarantine a device using GlobalProtect?

a)

by adding the device's Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device

b)

by exporting the list of quarantined devices to a pdf or csv file by selecting PDF/CSV at the bottom of the Device Quarantine page and leveraging the appropriate XSOAR playbook

c)

by using security policies, log forwarding profiles, and log settings

d)

there is no native auto-quarantine feature so a custom script would need to be leveraged

5.

To protect your firewall and network from single source denial of service (DoS) attacks that can overwhelm its packet buffer and cause legitimate traffic to drop, you can configure:

a)

PBP (Protocol Based Protection)

b)

BGP (Border Gateway Protocol)

c)

PGP (Packet Gateway Protocol)

d)

PBP (Packet Buffer Protection)

6.

A bootstrap USB flash drive has been prepared using a Windows workstation to load the initial configuration of a firewall that was previously being used in a lab.
The USB flash drive was formatted using file system FAT32 and the initial configuration is stored in a file named init-cfg.txt. The firewall is currently running PAN-
OS 10.0 and using a lab config. The contents of init-cfg.txt in the USB flash drive are as follows:

The USB flash drive has been inserted in the firewalls' USB port, and the firewall has been restarted using command: > request restart system
Upon restart, the firewall fails to begin the bootstrapping process. The failure is caused because:

a)

The bootstrap.xml file is a required file, but it is missing

b)

Firewall must be in factory default state or have all private data deleted for bootstrapping

c)

The hostname is a required parameter, but it is missing in init-cfg.txt

d)

The USB must be formatted using the ext3 file system. FAT32 is not supported

7.

An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object should they select?

a)

default-no-captive-portal

b)

default-authentication-bypass

c)

default-browser-challenge

d)

default-web-form

8.

A bootstrap USB flash drive has been prepared using a Linux workstation to load the initial configuration of a Palo Alto Networks firewall. The USB flash drive was formatted using file system ntfs and the initial configuration is stored in a file named init-cfg.txt.
The contents of init-cfg.txt in the USB flash drive are as follows:

The USB flash drive has been inserted in the firewalls' USB port, and the firewall has been powered on. Upon boot, the firewall fails to begin the bootstrapping process. The failure is caused because:

a)

the bootstrap.xml file is a required file, but it is missing

b)

nit-cfg.txt is an incorrect filename, the correct filename should be init-cfg.xml

c)

The USB must be formatted using the ext4 file system

d)

There must be commas between the parameter names and their values instead of the equal symbols

e)

The USB drive has been formatted with an unsupported file system

9.

To more easily reuse templates and template stacks, you can create template variables in place of firewall-specific and appliance-specific IP literals in your configurations.
Which one is the correct configuration?

a)

&Panorama

b)

@Panorama

c)

$Panorama

d)

#Panorama

10.

On the NGFW, how can you generate and block a private key from export and thus harden your security posture and prevent rogue administrators or other bad actors from misusing keys?

a)

1. Select Device > Certificate Management > Certificates > Device > Certificates 2. Import the certificate 3. Select Import Private key 4. Click Generate to generate the new certificate

b)

1. Select Device > Certificates 2. Select Certificate Profile 3. Generate the certificate 4. Select Block Private Key Export

c)

1. Select Device > Certificate Management > Certificates > Device > Certificates 2. Generate the certificate 3. Select Block Private Key Export 4. Click Generate to generate the new certificate

d)

1. Select Device > Certificates 2. Select Certificate Profile 3. Generate the certificate 4. Select Block Private Key Export

11.

What is the maximum number of samples that can be submitted to WildFire manually per day?

a)

1,000

b)

2,000

c)

5,000

d)

15,000

12.

What file type upload is supported as part of the basic WildFire service?

a)

ELF

b)

BAT

c)

PE

d)

VBS

13.

An administrator accidentally closed the commit window/screen before the commit was finished.
Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)

a)

Task Manager

b)

System Logs

c)

Traffic Logs

d)

Configuration Logs

14.

Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?

a)

Create a zone protection profile with flood protection configured to defend an entire egress zone against SYN, ICMP, ICMPv6, UDP, and other IP flood attacks.

b)

Add a WildFire subscription to activate DoS and zone protection features.

c)

Replace the hardware firewall, because DoS and zone protection are not available with VM-Series systems.

d)

Measure and monitor the CPU consumption of the firewall data plane to ensure that each firewall is properly sized to support DoS and zone protection

15.

DRAG DROP -
Please match the terms to their corresponding definitions.
Select and Place:

-

a)

1.

management plane

b)

2.

signature matching

c)

3.

security processing

d)

4.

network processing

16.

An organization has recently migrated its infrastructure and configuration to NGFWs, for which Panorama manages the devices. The organization is coming from a
L2-L4 firewall vendor, but wants to use App-ID while identifying policies that are no longer needed.
Which Panorama tool can help this organization?

a)

Test Policy Match

b)

Application Groups

c)

Policy Optimizer

d)

Config Audit

17.

An organization is building a Bootstrap Package to deploy Palo Alto Networks VM-Series firewalls into their AWS tenant. Which two statements are correct regarding the bootstrap package contents? (Choose two.)

a)

The bootstrap package is stored on an AFS share or a discrete container file bucket.

b)

The bootstrap.xml file allows for automated deployment of VM-Series firewalls with full network and policy configurations

c)

The /config, /content and /software folders are mandatory while the /license and /plugin folders are optional.

d)

The init-cfg.txt and bootstrap.xml files are both optional configuration items for the /config folder.

e)

The directory structure must include a /config, /content, /software and /license folders

18.

Which Panorama objects restrict administrative access to specific device-groups?

a)

admin roles

b)

authentication profiles

c)

templates

d)

access domains

19.

An engineer is planning an SSL decryption implementation.
Which of the following statements is a best practice for SSL decryption?

a)

Obtain an enterprise CA-signed certificate for the Forward Trust certificate.

b)

Use an enterprise CA-signed certificate for the Forward Untrust certificate.

c)

Use the same Forward Trust certificate on all firewalls in the network.

d)

Obtain a certificate from a publicly trusted root CA for the Forward Trust certificate.

20.

An administrator receives the following error message:
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id
172.16.33.33/24 type IPv4 address protocol 0 port 0."
How should the administrator identify the root cause of this error message?

a)

Verify that the IP addresses can be pinged and that routing issues are not causing the connection fa

b)

Check whether the VPN peer on one end is set up correctly using policy-based VPN.

c)

In the IKE Gateway configuration, verify that the IP address for each VPN peer is accurate

d)

In the IPSec Crypto profile configuration, verify that PFS is either enabled on both VPN peers or disabled on both VPN peers.