WorksheetsTopic 1 Question 180 to 200
Total questions: 20
Worksheet time: 14mins
The following objects and policies are defined in a device group hierarchy.
Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group
NYC-DC has NYC-FW as a member of the NYC-DC device-group
What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?
Address Objects -Shared Address1 -Branch Address1 Policies -Shared Policy1 -Branch Policy1
Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1
Address Objects -Shared Address1 -Shared Address2 -Branch Address1 -DC Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1
Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Branch Policy1
An administrator has purchased WildFire subscriptions for 90 firewalls globally.
What should the administrator consider with regards to the WildFire infrastructure?
To comply with data privacy regulations, WildFire signatures and verdicts are not shared globally
Palo Alto Networks owns and maintains one global cloud and four WildFire regional clouds.
Each WildFire cloud analyzes samples and generates malware signatures and verdicts independently of the other WildFire clouds.
The WildFire Global Cloud only provides bare metal analysis.
A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (CAs): i. Enterprise-Trusted-CA, which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system.) ii. Enterprise-Untrusted-CA, which is verified as Forward Untrust Certificate iii. Enterprise-Intermediate-CA iv. Enterprise-Root-CA, which is verified only as Trusted Root CA
An end-user visits https://www.example-website.com/ with a server certificate Common Name (CN): www.example-website.com. The firewall does the SSL
Forward Proxy decryption for the website and the server certificate is not trusted by the firewall.
The end-user's browser will show that the certificate for www. example-website.com was issued by which of the following?
Enterprise-Trusted-CA which is a self-signed CA
Enterprise-Root-CA which is a self-signed CA
Enterprise-Intermediate-CA which was, in turn, issued by Enterprise-Root-CA
Enterprise-Untrusted-CA which is a self-signed CA
What are three reasons for excluding a site from SSL decryption? (Choose three.)
the website is not present in English
unsupported ciphers
certificate pinning
unsupported browser version
mutual authentication
Match each SD-WAN configuration element to the description of that element.
Select and Place:
SD-WAN Interface Profile
Traffic Distribution Profile
Path Quality Profile
SD-WAN Interface Profile
When overriding a template configuration locally on a firewall, what should you consider?
Panorama will update the template with the overridden value.
The firewall template will show that it is out of sync within Panorama
Only Panorama can revert the override.
Panorama will lose visibility into the overridden configuration.
When setting up a security profile, which three items can you use? (Choose three.)
Wildfire analysis
anti-ransomware
antivirus
URL filtering
decryption profile
An administrator wants to upgrade a firewall HA pair to PAN-OS 10.1. The firewalls are currently running PAN-OS 8.1.17. Which upgrade path maintains synchronization of the HA session (and prevents network outage)?
Upgrade directly to the target major version.
Upgrade the HA pair to a base image.
Upgrade one major version at a time.
Upgrade two major versions at a time.
What are three types of Decryption Policy rules? (Choose three.)
SSL Inbound Inspection
SSH Proxy
SSL Forward Proxy
Decryption Broker
Decryption Mirror
During SSL decryption, which three factors affect resource consumption? (Choose three.)
key exchange algorithm
transaction size
TLS protocol version
applications ta non-standard ports
certificate issuer
An engineer must configure a new SSL decryption deployment.
Which profile or certificate is required before any traffic that matches an SSL decryption rule is decrypted?
A Decryption profile must be attached to the Decryption policy that the traffic matches.
There must be a certificate with both the Forward Trust option and Forward Untrust option selected.
A Decryption profile must be attached to the Security policy that the traffic matches.
There must be a certificate with only the Forward Trust option selected.
Which two features require another license on the NGFW? (Choose two.)
SSL Inbound Inspection
SSL Forward Proxy
Decryption Mirror
Decryption Broker
An administrator has a PA-820 firewall with an active Threat Prevention subscription. The administrator is considering adding a WildFire subscription.
How does adding the WildFire subscription improve the security posture of the organization?
WildFire and Threat Prevention combine to minimize the attack surface.
After 24 hours, WildFire signatures are included in the antivirus update
Protection against unknown malware can be provided in near real-time.
WildFire and Threat Prevention combine to provide the utmost security posture for the firewall
What are two characteristic types that can be defined for a variable? (Choose two.)
zone
FQDN
IP netmask
path group
A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)
Permitted IP Addresses
SSH
https
User-ID
HTTP
An administrator needs to troubleshoot a User-ID deployment. The administrator believes that there is an issue related to LDAP authentication. The administrator wants to create a packet capture on the management plane.
Which CLI command should the administrator use to obtain the packet capture for validating the configuration?
>scp export mgmt-pcap from mgmt.pcap to (username@host:path)
>scp export poap-mgmt from poap.mgmt to (username@host:path)
> ftp export mgmt-pcap from mgmt.pcap to <FTF host>
> scp export pcap from pcap to (username@host:path)
When you configure an active/active high availability pair, which two links can you use? (Choose two.)
3II (HA3)
Console Backup
HSCI-C
HA2 backup
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
the web server requires mutual authentication
the website matches a category that is not allowed for most users
the website matches a high-risk category
the website matches a sensitive category
PBF can address which two scenarios? (Choose two.)
routing FTP to a backup ISP link to save bandwidth on the primary ISP link
providing application connectivity the primary circuit fails
enabling the firewall to bypass Layer 7 inspection
forwarding all traffic by using source port 78249 to a specific egress interface
A firewall should be advertising the static route 10.2.0.0/24 into OSPF. The configuration on the neighbour is correct, but the route is not in the neighbour's routing table.
Which two configurations should you check on the firewall? (Choose two.)
Ensure that the OSPF neighbour state is "2-Way"
In the OSPF configuration, ensure that the correct redistribution profile is selected in the OSPF Export Rules section.
Within the redistribution profile ensure that Redist is selected.
In the redistribution profile check that the source type is set to "ospf."
