wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 1 Question 201 to 220

Total questions: 20

Worksheet time: 14mins

Name
Class
Date
1.

Which value in the Application column indicates UDP traffic that did not match an App-ID signature?

a)

unknown-udp

b)

unknown-ip

c)

incomplete

d)

not-applicable

2.

What are three valid qualifiers for a Decryption Policy Rule match? (Choose three.)

a)

App-ID

b)

Custom URL Category

c)

User-ID

d)

Destination Zone

e)

Source Interface

3.

An administrator needs to gather information about the CPU utilization on both the management plane and the data plane.
Where does the administrator view the desired data?

a)

Resources Widget on the Dashboard

b)

Monitor > Utilization

c)

Support > Resources

d)

Application Command and Control Center

4.

Which CLI command displays the physical media that are connected to ethernet1/8?

a)

> show system state filter-pretty sys.s1.p8.stats

b)

> show system state filter-pretty sys.s1.p8.med

c)

> show interface ethernet1/8

d)

> show system state filter-pretty sys.s1.p8.phy

5.

A variable name must start with which symbol?

a)

$

b)

!

c)

#

d)

&

6.

Given the following configuration, which route is used for destination 10.10.0.4? set network virtual-router 2 routing-table ip static-route "Route 1" nexthop ip-address 192.168.1.2 set network virtual-router 2 routing-table ip static-route "Route 1" metric 30 set network virtual-router 2 routing-table ip static-route "Route 1" destination 10.10.0.0/24 set network virtual-router 2 routing-table ip static-route "Route 1" re route-table unicast set network virtual-router 2 routing-table ip static-route "Route 2" nexthop ip-address 192.168.1.2 set network virtual-router 2 routing-table ip static-route "Route 2" metric 20 set network virtual-router 2 routing-table ip static-route "Route 2" destination 10.10.0.0/24 set network virtual-router 2 routing-table ip static-route "Route 2" route-table unicast set network virtual-router 2 routing-table ip static-route "Route 3" nexthop ip-address 10.10.20.1 set network virtual-router 2 routing-table ip static-route "Route 3" metric 5 set network virtual-router 2 routing-table ip static-route "Route 3" destination 0.0.0.0/0 set network virtual-router 2 routing-table ip static-route "Route 3" route-table unicast set network virtual-router 2 routing-table ip static-route "Route 4" nexthop ip-address 192.168.1.2 set network virtual-router 2 routing-table ip static-route "Route 4" metric 10 set network virtual-router 2 routing-table ip static-route "Route 4" destination 10.10.1.0/25 set network virtual-router 2 routing-table ip static-route "Route 4" route-table unicast

a)

Route 1

b)

Route 3

c)

Route 2

d)

Route 4

7.

In SSL Forward Proxy decryption, which two certificates can be used for certificate signing? (Choose two.)

a)

self-signed CA certificate

b)

server certificate

c)

wildcard server certificate

d)

client certificate

e)

enterprise CA certificate

8.

An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world. Panorama will manage the firewalls.
The firewalls will provide access to mobile users and act as edge locations to on-premises infrastructure. The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration.
Which two solutions can the administrator use to scale this configuration? (Choose two.)

a)

virtual systems

b)

template stacks

c)

variables

d)
  • collector groups

Hide Answer

9.

Which three statements accurately describe Decryption Mirror? (Choose three.)

a)

Decryption, storage, inspection, and use of SSL traffic regulated in certain countries.

b)

You should consult with your corporate counsel before activating and using Decryption Mirror in a production environment.

c)

Decryption Mirror requires a tap interface on the firewall.

d)

Only management consent is required to use the Decryption Mirror future.

e)

Use of Decryption Mirror might enable malicious users with administrative access to the firewall to harvest sensitive information that is submitted via an encrypted channel.

10.

As a best practice, which URL category should you target first for SSL decryption?

a)

Health and Medicine

b)

High Risk

c)

Online Storage and Backup

d)

Financial Services

11.

Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?

a)

LDAP Server Profile configuration

b)

GlobalProtect

c)

Windows-based User-ID agent

d)

PAN-OS integrated User-ID agent

12.

DRAG DROP -
Below are the steps in the workflow for creating a Best Practice Assessment in a firewall and Panorama configuration. Place the steps in order.
Select and Place:

a)

1.

STEP 1

b)

2.

STEP 2

c)

3.

STEP 3

d)

4.

STEP 4

e)

5.

STEP 5

13.

DRAG DROP -
Place the steps in the WildFire process workflow in their correct order.
Select and Place:

a)

1.

FIRST

b)

2.

SECOND

c)

3.

THIRD

d)

4.

FOURTH

14.

In a Panorama template, which three types of objects are configurable? (Choose three.)

a)

certificate profiles

b)

HIP objects

c)

QoS profiles

d)

security profiles

e)

interface management profiles

15.

An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used. After looking at the configuration, the administrator believes that the firewall is not using a static route.
What are two reasons why the firewall might not use a static route? (Choose two.)

a)

duplicate static route

b)

no install on the route

c)

disabling of the static route

d)

path monitoring on the static route

16.

A customer is replacing its legacy remote-access VPN solution. Prisma Access has been selected as the replacement. During onboarding, the following options and licenses were selected and enabled:
- Prisma Access for Remote Networks: 300Mbps
- Prisma Access for Mobile Users: 1500 Users
- Cortex Data Lake: 2TB
- Trusted Zones: trust
- Untrusted Zones: untrust
- Parent Device Group: shared
The customer wants to forward to a Splunk SIEM the logs that are generated by users that are connected to Prisma Access for Mobile Users. Which two settings must the customer configure? (Choose two.)

a)

Configure Panorama Collector group device log forwarding to send logs to the Splunk syslog server.

b)

Configure Cortex Data Lake log forwarding and add the Splunk syslog server.

c)

Configure a log forwarding profile and select the Panorama/Cortex Data Lake checkbox. Apply the Log Forwarding profile to all of the security policy rules in Mobile_User_Device_Group.

d)

Configure a log forwarding profile and select the Panorama/Cortex Data Lake checkbox. Apply the Log Forwarding profile to all of the security policy rules in Mobile_User_Device_Group.

17.

A network administrator wants to use a certificate for the SSL/TLS Service Profile. Which type of certificate should the administrator use?

a)

  • machine certificate

b)

server certificate

c)

certificate authority (CA) certificate

d)

client certificate

18.

In a security-first network, what is the recommended threshold value for content updates to be dynamically updated?

a)

1 to 4 hours

b)

6 to 12 hours

c)

24 hours

d)

36 hours

19.

A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket.
The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system.
Where is the best place to validate if the firewall is blocking the user's TAR file?

a)

Threat log

b)

Data Filtering log

c)

WildFire Submissions log

d)

URL Filtering log

20.

In a firewall, which three decryption methods are valid? (Choose three.)

a)

SSL Outbound Proxyless Inspection

b)

SSL Inbound Inspection M

c)

SSH Proxy

d)

SSL Inbound Proxy

e)

Decryption Mirror