Font size
WorksheetsTopic 1 Question 500 to 520
Total questions: 20
Worksheet time: 11mins
A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below.
What should the NAT rule destination zone be set to?
None
Inside
DMZ
Outside
A consultant deploys a PAN-OS 11.0 VM-Series firewall with the Web Proxy feature in Transparent Proxy mode.
Which three elements must be in place before a transparent web proxy can function? (Choose three.)
User-ID for the proxy zone
DNS Security license
Prisma Access explicit proxy license
Cortex Data Lake license
Authentication Policy Rule set to default-web-form
Which source is the most reliable for collecting User-ID user mapping?
Microsoft Active Directory
Microsoft Exchange
GlobalProtect
Syslog Listener
Which type of zone will allow different virtual systems to communicate with each other?
Tap
Tunnel
Virtual Wire
External
An organization is interested in migrating from their existing web proxy architecture to the Web Proxy feature of their PAN-OS 11.0 firewalls. Currently, HTTP and SSL requests contain the destination IP address of the web server and the client browser is redirected to the proxy.
Which PAN-OS proxy method should be configured to maintain this type of traffic flow?
SSL forward proxy
Explicit proxy
Transparent proxy
DNS proxy
An engineer discovers the management interface is not routable to the User-ID agent.
What configuration is needed to allow the firewall to communicate to the User-ID agent?
Add a Policy Based Forwarding (PBF) policy to the User-ID agent IP
Create a NAT policy for the User-ID agent server
Create a custom service route for the UID Agent
Add a static route to the virtual router
An engineer receives reports from users that applications are not working and that websites are only partially loading in an asymmetric environment. After investigating, the engineer observes the flow_tcp_non_syn_drop counter increasing in the show counters global output.
Which troubleshooting command should the engineer use to work around this issue?
set deviceconfig setting tcp asymmetric-path drop
set session tcp-reject-non-syn yes
set deviceconfig setting tcp asymmetric-path bypass
set deviceconfig setting session tcp-reject-non-syn no
Where is Palo Alto Networks Device Telemetry data stored on a firewall with a device certificate installed?
Panorama
M600 Log Collectors
Cortex Data Lake
On Palo Alto Networks Update Servers
Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?
Satellite mode
Tunnel mode
No Direct Access to local networks
IPSec mode
A superuser is tasked with creating administrator accounts for three contractors. For compliance purposes, all three contractors will be working with different device-groups in their hierarchy to deploy policies and objects.
Which type of role-based access is most appropriate for this project?
Create a Dynamic Admin with the Panorama Administrator role.
Create a Dynamic Read only superuser.
Create a Device Group and Template Admin
Create a Custom Panorama Admin.
An administrator connects four new remote offices to the corporate data center. The administrator decides to use the Large Scale VPN (LSVPN) feature on the Palo Alto Networks next-generation firewall.
What should the administrator configure in order to connect the sites?
Generic Routing Encapsulation (GRE) Tunnels
GlobalProtect Satellite
SD-WAN
IKE Gateways
A customer wants to set up a site-to-site VPN using tunnel interfaces.
What format is the correct naming convention for tunnel interfaces?
tun.1025
tunnel.50
vpn.1024
gre1/2
An engineer notices that the tunnel monitoring has been failing for a day and the VPN should have failed over to a backup path.
What part of the network profile configuration should the engineer verify?
Destination IP
Threshold
Action
Interval
Which three multi-factor authentication methods can be used to authenticate access to the firewall? (Choose three.)
One-time password
User certificate
SMS
Fingerprint
Voice
Which two profiles should be configured when sharing tags from threat logs with a remote User-ID agent? (Choose two.)
LDAP
Log Ingestion
HTTP
Log Forwarding
What is the PAN-OS NPTv6 feature based on RFC 6296 used for?
Application port number translation
IPv6-to-IPv6 network prefix translation
Stateful translation to provide better security
IPv6-to-IPv6 host portion translation
An administrator has been tasked with deploying SSL Forward Proxy.
Which two types of certificates are used to decrypt the traffic? (Choose two.)
Device certificate
Subordinate CA from the administrator’s own PKI infrastructure
Self-signed root CA
External CA certificate
An engineer is deploying multiple firewalls with common configuration in Panorama.
What are two benefits of using nested device groups? (Choose two.)
Inherit all Security policy rules and objects
Inherit settings from the Shared group
Inherit IPSec crypto profiles
Inherit parent Security policy rules and objects
A network security administrator wants to inspect HTTPS traffic from users as it egresses through a firewall to the Internet/Untrust zone from trusted network zones. The security admin wishes to ensure that if users are presented with invalid or untrusted security certificates, the user will see an untrusted certificate warning.
What is the best choice for an SSL Forward Untrust certificate?
A self-signed certificate generated on the firewall
A web server certificate signed by the organization’s PKI
A web server certificate signed by an external Certificate Authority
A subordinate Certificate Authority certificate signed by the organization’s PKI
After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall. After troubleshooting, the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports.
What can the engineer do to solve the VoIP traffic issue?
Disable ALG under H.323 application
Increase the TCP timeout under H.323 application
Increase the TCP timeout under SIP application
Disable ALG under SIP application
