Font size
WorksheetsTopic 1 Question 540 to 560
Total questions: 20
Worksheet time: 12mins
An engineer creates a set of rules in a Device Group (Panorama) to permit traffic to various services for a specific LDAP user group.
What needs to be configured to ensure Panorama can retrieve user and group information for use in these rules?
A service route to the LDAP server
A User-ID agent on the LDAP server
A Master Device
Authentication Portal
Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.
Given the rule below, what change should be made to make sure the NAT works as expected?
Change destination NAT zone to Trust_L3.
Change destination translation to Dynamic IP (with session distribution) using firewall eth1/2 address.
Change Source NAT zone to Untrust_L3.
Add source Translation to translate original source IP to the firewall eth1/2 interface translation.
An engineer is configuring a template in Panorama which will contain settings that need to be applied to all firewalls in production.
Which three parts of a template an engineer can configure? (Choose three.)
Service Route Configuration
Dynamic Address Groups
NTP Server Address
Antivirus Profile
Authentication Profile
A firewall engineer reviews the PAN-OS GlobalProtect application and sees that it implicitly uses web-browsing and depends on SSL.
When creating a new rule, what is needed to allow the application to resolve dependencies?
Add SSL application to the same rule
SSL and web-browsing must both be explicitly allowed.
Add SSL and web-browsing applications to the same rule
Add web-browsing application to the same rule
In a security-first network, what is the recommended threshold value for apps and threats to be dynamically updated?
1 to 4 hours
6 to 12 hours
24 hours
36 hours
An engineer configures a specific service route in an environment with multiple virtual systems instead of using the inherited global service route configuration.
What type of service route can be used for this configuration?
Destination-Based Service Route
Inherit Global Setting
IPv6 Source or Destination Address
IPv4 Source Interface
An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of VoIP traffic.
Which three elements should the administrator configure to address this issue? (Choose three.)
A QoS policy for each application
An Application Override policy for the SIP traffic
A QoS profile defining traffic classes
QoS on the ingress interface for the traffic flows
QoS on the egress interface for the traffic flows
What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three.)
Rename a vsys on a multi-vsys firewall
Change the firewall management IP address
Enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode
Add administrator accounts
Configure a device block list
Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?
.
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
DATACENTER_DG post-rules -
shared post-rules
shared default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules
DATACENTER_DG post-rules -
DATACENTER_DG default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules
DATACENTER_DG post-rules -
shared default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
DATACENTER_DG post-rules -
shared post-rules
DATACENTER_DG default rules
A company wants to implement threat prevention to take action without redesigning the network routing.
What are two best practice deployment modes for the firewall? (Choose two.)
Virtual Wire
Layer 2
Layer 3
TAP
Which operation will impact the performance of the management plane?
Enabling DoS protection
Enabling packet buffer protection
Decrypting SSL sessions
Generating a Saas Application report
Which type of policy in Palo Alto Networks firewalls can use Device-ID as a match condition?
Tunnel inspection
NAT
QoS
DOS protection
Why would a traffic log list an application as "not-applicable"?
There was not enough application data after the TCP connection was established.
The TCP connection terminated without identifying any application data
The firewall denied the traffic before the application match could be performed
The application is not a known Palo Alto Networks App-ID.
What must be configured to apply tags automatically based on User-ID logs?
Device ID
Log settings
Group mapping
Log Forwarding profile
A firewall engineer creates a NAT rule to translate IP address 1.1.1.10 to 192.168.1.10. The engineer also plans to enable DNS rewrite so that the firewall rewrites the IPv4 address in a DNS response based on the original destination IP address and translated destination IP address configured for the rule. The engineer wants the firewall to rewrite a DNS response of 1.1.1.10 to 192.168.1.10.
What should the engineer do to complete the configuration?
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.
Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.
Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53
An engineer is monitoring an active/active high availability (HA) firewall pair.
Which HA firewall state describes the firewall that is experiencing a failure of a monitored path?
Initial
Passive
Active-secondary
Tentative
You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles.
For which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three.)
Critical
High
Medium
Informational
Low
In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?
Applications configured in the rule with their dependencies
The security rule with any other security rule selected
Applications configured in the rule with applications seen from traffic matching the same rule
The running configuration with the candidate configuration of the firewall
Given the following snippet of a WildFire submission log, did the end user successfully download a file?Given the following snippet of a WildFire submission log, did the end user successfully download a file?
Yes, because the final action is set to "allow."
No, because the action for the wildfire-virus is "reset-both."
No, because the URL generated an alert.
Yes, because both the web-browsing application and the flash file have the "alert" action
Which two factors should be considered when sizing a decryption firewall deployment? (Choose two.)
Number of security zones in decryption policies
Encryption algorithm
TLS protocol version
Number of blocked sessions
