WorksheetsTopic 1 Question 521 to 540
Total questions: 20
Worksheet time: 11mins
After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?
Ensure Force Template Values is checked when pushing configuration.
Push the Template first, then push Device Group to the newly managed firewall.
Push the Device Group first, then push Template to the newly managed firewall.
Perform the Export or push Device Config Bundle to the newly managed firewall
Which new PAN-OS 11.0 feature supports IPv6 traffic?
OSPF
IKEv1
DHCP Server
DHCPv6 Client with Prefix Delegation
a URL is in multiple custom URL categories with different actions, which action will take priority?
Block
Allow
Alert
Override
An engineer is reviewing the following high availability (HA) settings to understand a recent HA failover event
Which timer determines the frequency between packets sent to verify that the HA functionality on the other HA firewall is operational?
Hello Interval
Monitor Fail Hold Up Time
Heartbeat Interval
Promotion Hold Time
Which three items must be configured to implement application override? (Choose three.)
Application filter
Application override policy rule
Custom app
Decryption policy rule
Security policy rule
An engineer is configuring a firewall with three interfaces:
• MGT connects to a switch with internet access.
• Ethernet1/1 connects to an edge router.
• Ethernet1/2 connects to a virtualization network.
The engineer needs to configure dynamic updates to use a dataplane interface for internet traffic.
What should be configured in Setup > Services > Service Route Configuration to allow this traffic?
Set DNS and Palo Alto Networks Services to use the MGT source interface.
Set DNS and Palo Alto Networks Services to use the ethernet1/1 source interface.
Set DNS and Palo Alto Networks Services to use the ethernet1/2 source interface.
Set DDNS and Palo Alto Networks Services to use the MGT source interface.
An organization conducts research on the benefits of leveraging the Web Proxy feature of PAN-OS 11.0.
What are two benefits of using an explicit proxy method versus a transparent proxy method? (Choose two.)
No client configuration is required for explicit proxy, which simplifies the deployment complexity.
Explicit proxy supports interception of traffic using non-standard HTTPS ports.
It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request
Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy.
Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)
TACACS+
Kerberos
SAML
RADIUS
LDAP
With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?
insufficient-data
incomplete
not-applicable
unknown-tcp
To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?
Clone the security policy and add it to the other device groups.
Add the policy to the target device group and apply a master device to the device group.
Reference the targeted device’s templates in the target device group.
Add the policy in the shared device group as a pre-rule.
Based on the graphic, which statement accurately describes the output shown in the Server Monitoring panel?
The User-ID agent is connected to a domain controller labeled lab-client
The host lab-client has been found by the User-ID agent.
The host lab-client has been found by a domain controller.
The User-ID agent is connected to the firewall labeled lab-client.
What can be used as an Action when creating a Policy-Based Forwarding (PBF) policy?
Deny
Allow
Discard
Next VR
An engineer manages a high availability network and requires fast failover of the routing protocols. The engineer decides to implement BFD.
Which three dynamic routing protocols support BFD? (Choose three.)
OSPF
IGRP
OSPFv3 virtual link
BGP
RIP
A company has recently migrated their branch office’s PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template configuration is managed solely within Panorama.
They notice that commit times have drastically increased for the PA-220s after the migration.
What can they do to reduce commit times?
Disable “Share Unused Address and Service Objects with Devices” in Panorama Settings
Perform a device group push using the “merge with device candidate config” option
Update the apps and threat version using device-deployment.
Use “export or push device config bundle” to ensure that the firewall is integrated with the Panorama config.
An administrator is troubleshooting why video traffic is not being properly classified.
If this traffic does not match any QoS classes, what default class is assigned?
1
2
3
4
An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.
What is one way the administrator can meet this requireme
Reload the running configuration and perform a Firewall local commit.
Perform a commit force from the CLI of the firewall.
Perform a template commit push from Panorama using the “Force Template Values” option.
Perform a device-group commit push from Panorama using the “Include Device and Network Templates” option.
Perform a device-group commit push from Panorama using the “Include Device and Network Templates” option.
Use Network > Virtual Routers, select the Virtual Router > Static Routes > IPv4
Use Device > Setup > Services > Services
Use Device > Setup > Services > Service Route Configuration > Customize > IPv4
Use Device > Setup > Services > Service Route Configuration > Customize > Destination
Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration.
What part of the configuration should the engineer verify?
IKE Crypto Profile
Security policy
Proxy-IDs
PAN-OS versions
Information Security is enforcing group-based policies by using security-event monitoring on Windows User-ID agents for IP-to-User mapping in the network. During the rollout, Information Security identified a gap for users authenticating to their VPN and wireless networks.
Root cause analysis showed that users were authenticating via RADIUS and that authentication events were not captured on the domain controllers that were being monitored. Information Security found that authentication events existed on the Identity Management solution (IDM).
There did not appear to be direct integration between PAN-OS and the IDM solution.
How can Information Security extract and learn IP-to-user mapping information from authentication events for VPN and wireless users?
Configure the integrated User-ID agent on PAN-OS to accept Syslog messages over TLS
Configure the User-ID XML API on PAN-OS firewalls to pull the authentication events directly from the IDM solution.
Add domain controllers that might be missing to perform security-event monitoring for VPN and wireless users
Configure the Windows User-ID agents to monitor the VPN concentrators and wireless controllers for IP-to-User mapping.
An administrator troubleshoots an issue that causes packet drops.
Which log type will help the engineer verify whether packet buffer protection was activated?
Configuration
Data Filtering
Traffic
Threat
