wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 1 Question 180 to 200

Total questions: 20

Worksheet time: 14mins

Name
Class
Date
1.

The following objects and policies are defined in a device group hierarchy.

Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group
NYC-DC has NYC-FW as a member of the NYC-DC device-group
What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?

a)

Address Objects -Shared Address1 -Branch Address1 Policies -Shared Policy1 -Branch Policy1

b)

Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1

c)

Address Objects -Shared Address1 -Shared Address2 -Branch Address1 -DC Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1

d)

Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Branch Policy1

2.

An administrator has purchased WildFire subscriptions for 90 firewalls globally.
What should the administrator consider with regards to the WildFire infrastructure?

a)

To comply with data privacy regulations, WildFire signatures and verdicts are not shared globally

b)

Palo Alto Networks owns and maintains one global cloud and four WildFire regional clouds.

c)

Each WildFire cloud analyzes samples and generates malware signatures and verdicts independently of the other WildFire clouds.

d)

The WildFire Global Cloud only provides bare metal analysis.

3.

A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (CAs): i. Enterprise-Trusted-CA, which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system.) ii. Enterprise-Untrusted-CA, which is verified as Forward Untrust Certificate iii. Enterprise-Intermediate-CA iv. Enterprise-Root-CA, which is verified only as Trusted Root CA
An end-user visits https://www.example-website.com/ with a server certificate Common Name (CN): www.example-website.com. The firewall does the SSL
Forward Proxy decryption for the website and the server certificate is not trusted by the firewall.
The end-user's browser will show that the certificate for www. example-website.com was issued by which of the following?

a)

Enterprise-Trusted-CA which is a self-signed CA

b)

Enterprise-Root-CA which is a self-signed CA

c)

Enterprise-Intermediate-CA which was, in turn, issued by Enterprise-Root-CA

d)

Enterprise-Untrusted-CA which is a self-signed CA

4.

What are three reasons for excluding a site from SSL decryption? (Choose three.)

a)

the website is not present in English

b)

unsupported ciphers

c)

certificate pinning

d)

unsupported browser version

e)

mutual authentication

5.

Match each SD-WAN configuration element to the description of that element.
Select and Place:

a)

1.

SD-WAN Interface Profile

b)

2.

Traffic Distribution Profile

c)

3.

Path Quality Profile

d)

4.

SD-WAN Interface Profile

6.

When overriding a template configuration locally on a firewall, what should you consider?

a)

Panorama will update the template with the overridden value.

b)

The firewall template will show that it is out of sync within Panorama

c)

Only Panorama can revert the override.

d)

Panorama will lose visibility into the overridden configuration.

7.

When setting up a security profile, which three items can you use? (Choose three.)

a)

Wildfire analysis

b)

anti-ransomware

c)

antivirus

d)

URL filtering

e)

decryption profile

8.

An administrator wants to upgrade a firewall HA pair to PAN-OS 10.1. The firewalls are currently running PAN-OS 8.1.17. Which upgrade path maintains synchronization of the HA session (and prevents network outage)?

a)

Upgrade directly to the target major version.

b)

Upgrade the HA pair to a base image.

c)

Upgrade one major version at a time.

d)

Upgrade two major versions at a time.

9.

What are three types of Decryption Policy rules? (Choose three.)

a)

SSL Inbound Inspection

b)

SSH Proxy

c)

SSL Forward Proxy

d)

Decryption Broker

e)

Decryption Mirror

10.

During SSL decryption, which three factors affect resource consumption? (Choose three.)

a)

key exchange algorithm

b)

transaction size

c)

TLS protocol version

d)

applications ta non-standard ports

e)

certificate issuer

11.

An engineer must configure a new SSL decryption deployment.
Which profile or certificate is required before any traffic that matches an SSL decryption rule is decrypted?

a)

A Decryption profile must be attached to the Decryption policy that the traffic matches.

b)

There must be a certificate with both the Forward Trust option and Forward Untrust option selected.

c)

A Decryption profile must be attached to the Security policy that the traffic matches.

d)

There must be a certificate with only the Forward Trust option selected.

12.

Which two features require another license on the NGFW? (Choose two.)

a)

SSL Inbound Inspection

b)

SSL Forward Proxy

c)

Decryption Mirror

d)

Decryption Broker

13.

An administrator has a PA-820 firewall with an active Threat Prevention subscription. The administrator is considering adding a WildFire subscription.
How does adding the WildFire subscription improve the security posture of the organization?

a)

WildFire and Threat Prevention combine to minimize the attack surface.

b)

After 24 hours, WildFire signatures are included in the antivirus update

c)

Protection against unknown malware can be provided in near real-time.

d)

WildFire and Threat Prevention combine to provide the utmost security posture for the firewall

14.

What are two characteristic types that can be defined for a variable? (Choose two.)

a)

zone

b)

FQDN

c)

IP netmask

d)

path group

15.

A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)

a)

Permitted IP Addresses

b)

SSH

c)

https

d)

User-ID

e)

HTTP

16.

An administrator needs to troubleshoot a User-ID deployment. The administrator believes that there is an issue related to LDAP authentication. The administrator wants to create a packet capture on the management plane.
Which CLI command should the administrator use to obtain the packet capture for validating the configuration?

a)

>scp export mgmt-pcap from mgmt.pcap to (username@host:path)

b)

>scp export poap-mgmt from poap.mgmt to (username@host:path)

c)

> ftp export mgmt-pcap from mgmt.pcap to <FTF host>

d)

> scp export pcap from pcap to (username@host:path)

17.

When you configure an active/active high availability pair, which two links can you use? (Choose two.)


a)

3II (HA3)

b)

Console Backup

c)

HSCI-C

d)

HA2 backup

18.

What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)

a)

the web server requires mutual authentication

b)

the website matches a category that is not allowed for most users

c)

the website matches a high-risk category

d)

the website matches a sensitive category

19.

PBF can address which two scenarios? (Choose two.)

a)

routing FTP to a backup ISP link to save bandwidth on the primary ISP link

b)

providing application connectivity the primary circuit fails

c)

enabling the firewall to bypass Layer 7 inspection

d)

forwarding all traffic by using source port 78249 to a specific egress interface

20.

A firewall should be advertising the static route 10.2.0.0/24 into OSPF. The configuration on the neighbour is correct, but the route is not in the neighbour's routing table.
Which two configurations should you check on the firewall? (Choose two.)

a)

Ensure that the OSPF neighbour state is "2-Way"

b)

In the OSPF configuration, ensure that the correct redistribution profile is selected in the OSPF Export Rules section.

c)

Within the redistribution profile ensure that Redist is selected.

d)

In the redistribution profile check that the source type is set to "ospf."