wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 1 Question 540 to 560

Total questions: 20

Worksheet time: 12mins

Name
Class
Date
1.

An engineer creates a set of rules in a Device Group (Panorama) to permit traffic to various services for a specific LDAP user group.

What needs to be configured to ensure Panorama can retrieve user and group information for use in these rules?

a)

A service route to the LDAP server

b)

A User-ID agent on the LDAP server

c)

A Master Device

d)

Authentication Portal

2.

Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.

Given the rule below, what change should be made to make sure the NAT works as expected?

a)

Change destination NAT zone to Trust_L3.

b)

Change destination translation to Dynamic IP (with session distribution) using firewall eth1/2 address.

c)

Change Source NAT zone to Untrust_L3.

d)

Add source Translation to translate original source IP to the firewall eth1/2 interface translation.

3.

An engineer is configuring a template in Panorama which will contain settings that need to be applied to all firewalls in production.

Which three parts of a template an engineer can configure? (Choose three.)

a)

Service Route Configuration

b)

Dynamic Address Groups

c)

NTP Server Address

d)

Antivirus Profile

e)

Authentication Profile

4.

A firewall engineer reviews the PAN-OS GlobalProtect application and sees that it implicitly uses web-browsing and depends on SSL.

When creating a new rule, what is needed to allow the application to resolve dependencies?

a)

Add SSL application to the same rule

b)

SSL and web-browsing must both be explicitly allowed.

c)

Add SSL and web-browsing applications to the same rule

d)

Add web-browsing application to the same rule

5.

In a security-first network, what is the recommended threshold value for apps and threats to be dynamically updated?

a)

1 to 4 hours

b)

6 to 12 hours

c)

24 hours

d)

36 hours

6.

An engineer configures a specific service route in an environment with multiple virtual systems instead of using the inherited global service route configuration.

What type of service route can be used for this configuration?

a)

Destination-Based Service Route

b)

Inherit Global Setting

c)

IPv6 Source or Destination Address

d)

IPv4 Source Interface

7.

An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of VoIP traffic.

Which three elements should the administrator configure to address this issue? (Choose three.)

a)

A QoS policy for each application

b)

An Application Override policy for the SIP traffic

c)

A QoS profile defining traffic classes

d)

QoS on the ingress interface for the traffic flows

e)

QoS on the egress interface for the traffic flows

8.

What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three.)

a)

Rename a vsys on a multi-vsys firewall

b)

Change the firewall management IP address

c)

Enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode

d)

Add administrator accounts

e)

Configure a device block list

9.

Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?


a)

.

shared pre-rules

DATACENTER_DG pre-rules -
rules configured locally on the firewall

DATACENTER_DG post-rules -
shared post-rules
shared default rules

b)

shared pre-rules

DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules

DATACENTER_DG post-rules -
DATACENTER_DG default rules

c)

shared pre-rules

DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules

DATACENTER_DG post-rules -
shared default rules

d)

shared pre-rules

DATACENTER_DG pre-rules -
rules configured locally on the firewall

DATACENTER_DG post-rules -
shared post-rules
DATACENTER_DG default rules

10.

A company wants to implement threat prevention to take action without redesigning the network routing.

What are two best practice deployment modes for the firewall? (Choose two.)

a)

Virtual Wire

b)

Layer 2

c)

Layer 3

d)

TAP

11.

Which operation will impact the performance of the management plane?

a)

Enabling DoS protection

b)

Enabling packet buffer protection

c)

Decrypting SSL sessions

d)

Generating a Saas Application report

12.

Which type of policy in Palo Alto Networks firewalls can use Device-ID as a match condition?

a)

Tunnel inspection

b)

NAT

c)

QoS

d)

DOS protection

13.

Why would a traffic log list an application as "not-applicable"?

a)

There was not enough application data after the TCP connection was established.

b)

The TCP connection terminated without identifying any application data

c)

The firewall denied the traffic before the application match could be performed

d)

The application is not a known Palo Alto Networks App-ID.

14.

What must be configured to apply tags automatically based on User-ID logs?

a)

Device ID

b)

Log settings

c)

Group mapping

d)

Log Forwarding profile

15.

A firewall engineer creates a NAT rule to translate IP address 1.1.1.10 to 192.168.1.10. The engineer also plans to enable DNS rewrite so that the firewall rewrites the IPv4 address in a DNS response based on the original destination IP address and translated destination IP address configured for the rule. The engineer wants the firewall to rewrite a DNS response of 1.1.1.10 to 192.168.1.10.

What should the engineer do to complete the configuration?

a)

Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.

b)

Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.

c)

Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.

d)

Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53

16.

An engineer is monitoring an active/active high availability (HA) firewall pair.

Which HA firewall state describes the firewall that is experiencing a failure of a monitored path?

a)

Initial

b)

Passive

c)

Active-secondary

d)

Tentative

17.

You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles.

For which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three.)

a)

Critical

b)

High

c)

Medium

d)

Informational

e)

Low

18.

In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?

a)

Applications configured in the rule with their dependencies

b)

The security rule with any other security rule selected

c)

Applications configured in the rule with applications seen from traffic matching the same rule

d)

The running configuration with the candidate configuration of the firewall

19.

Given the following snippet of a WildFire submission log, did the end user successfully download a file?Given the following snippet of a WildFire submission log, did the end user successfully download a file?

a)

Yes, because the final action is set to "allow."

b)

No, because the action for the wildfire-virus is "reset-both."

c)

No, because the URL generated an alert.

d)

Yes, because both the web-browsing application and the flash file have the "alert" action

20.

Which two factors should be considered when sizing a decryption firewall deployment? (Choose two.)

a)

Number of security zones in decryption policies

b)

Encryption algorithm

c)

TLS protocol version

d)

Number of blocked sessions