WorksheetsTopic 1 Question 601 to 619
Total questions: 19
Worksheet time: 11mins
A root cause analysis investigation into a recent security incident reveals that several decryption rules have been disabled. The security team wants to generate email alerts when decryption rules are changed.
How should email log forwarding be configured to achieve this goal?
With the relevant system log filter inside Device > Log Settings
With the relevant configuration log filter inside Device > Log Settings
With the relevant configuration log filter inside Objects > Log Forwarding
With the relevant system log filter inside Objects > Log Forwarding
An engineer has been given approval to upgrade their environment to the latest of PAN-OS.
The environment consists of both physical and virtual firewalls, a virtual Panorama HA pair, and virtual log collectors.
What is the recommended order of operational steps when upgrading?
Upgrade the firewalls, upgrade log collectors, upgrade Panorama
Upgrade the firewalls, upgrade Panorama, upgrade the log collectors
Upgrade the log collectors, upgrade the firewalls, upgrade Panorama
Upgrade Panorama, upgrade the log collectors, upgrade the firewalls
An administrator has a Palo Alto Networks NGFW. All security subscriptions and decryption are enabled and the system is running close to its resource limits.
Knowing that using decryption can be resource-intensive, how can the administrator reduce the load on the firewall?
Use SSL Forward Proxy instead of SSL Inbound Inspection for decryption.
Use RSA instead of ECDSA for traffic that isn’t sensitive or high-priority.
Use the highest TLS protocol version to maximize security.
Use ECDSA instead of RSA for traffic that isn’t sensitive or high-priority.
A firewall engineer has determined that, in an application developed by the company’s internal team, sessions often remain idle for hours before the client and server exchange any data. The application is also currently identified as unknown-tcp by the firewalls. It is determined that because of a high level of trust, the application does not require to be scanned for threats, but it needs to be properly identified in Traffic logs for reporting purposes.
Which solution will take the least time to implement and will ensure the App-ID engine is used to identify the application?
A. Create a custom application with specific timeouts and signatures based on patterns discovered in packet captures.
B. Access the Palo Alto Networks website and complete the online form to request that a new application be added to App-ID.
C. Create a custom application with specific timeouts, then create an application override rule and reference the custom application.
D. Access the Palo Alto Networks website and raise a support request through the Customer Support Portal.
Create a custom application with specific timeouts and signatures based on patterns discovered in packet captures.
Access the Palo Alto Networks website and complete the online form to request that a new application be added to App-ID.
Create a custom application with specific timeouts, then create an application override rule and reference the custom application
Access the Palo Alto Networks website and raise a support request through the Customer Support Portal.
What happens when the log forwarding built-in action with tagging is used?
Selected logs are forwarded to the Azure Security Center
Destination zones of selected unwanted traffic are blocked.
Destination IP addresses of selected unwanted traffic are blocked
Selected unwanted traffic source zones are blocked.
A firewall engineer creates a source NAT rule to allow the company’s internal private network 10.0.0.0/23 to access the internet. However, for security reasons, one server in that subnet (10.0.0.10/32) should not be allowed to access the internet, and therefore should not be translated with the NAT rule.
What are three prerequisites to enable Credential Phishing Prevention over SSL? (Choose three.)
Create a URL filtering profile
Create an anti-virus profile.
Enable User-ID.
Configure a URL profile to block the phishing category.
Create a decryption policy rule.
A company is expanding its existing log storage and alerting solutions. All company Palo Alto Networks firewalls currently forward logs to Panorama.
Which two additional log forwarding methods will PAN-OS support? (Choose two.)
HTTP
SSL
TLS
A firewall administrator has confirmed reports of a website is not displaying as expected, and wants to ensure that decryption is not causing the issue.
Which three methods can the administrator use to determine if decryption is causing the website to fail? (Choose three)
Move the policy with action decrypt to the top of the decryption policy rulebase.
Investigate decryption logs of the specific traffic to determine reasons for failure.
Temporarily disable SSL decryption for all websites to troubleshoot the issue.
Disable SSL handshake logging.
Create a policy-based "No Decrypt" rule in the decryption policy to exclude specific traffic from decryption.
After implementing a new NGFW, a firewall engineer is alerted to a VoIP traffic issue. After troubleshooting, the engineer confirms that the firewall is alerting the voice packets payload.
What can the engineer do to solve the VoIP traffic issue?
Increase the TCP timeout under SIP application
Disable ALG under SIP application
Disable ALG under H.323 application
Increase the TCP timeout under H.323 application
An administrator is considering deploying WildFire globally.
What should the administrator consider with regards to the WildFire analysis process?
Each WildFire cloud analyzes samples independently of the other WildFire clouds.
To comply with data privacy regulations, WildFire signatures and verdicts are not shared globally
Palo Alto Networks owns and maintains one global cloud and four WildFire regional clouds.
The WildFire Global Cloud only provides bare metal analysis.
Which two components are required to configure certificate-based authentication to the web UI when an administrator needs firewall access on a trusted interface? (Choose two.)
Server certificate
CA certificate
SSL/TLS Service Profile
Certificate Profile
What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?
Phase 2 SAs are synchronized over HA2 links.
Phase 1 and Phase 2 SAs are synchronized over HA2 links.
Phase 1 SAs are synchronized over HA1 links.
Phase 1 and Phase 2 SAs are synchronized over HA3 links.
Which function does the HA4 interface provide when implementing a firewall cluster which contains firewalls configured as active-passive pairs?
Perform session cache synchronization for all HA cluster members with the same cluster ID.
Perform synchronization of sessions, forwarding tables, and IPSec security associations between firewalls in an HA pair.
Perform packet forwarding to the active-passive peer during session setup and asymmetric traffic flow
Perform synchronization of routes, IPSec security associations, and User-ID information.
A security engineer has configured a GlobalProtect portal agent with four gateways.
Which GlobalProtect Gateway will users connect to based on the chart provided?
East
South
West
Central
A network security engineer needs to ensure that virtual systems can communicate with one another within a Palo Alto Networks firewall. Separate virtual routers (VRs) are created for each virtual system.
In addition to confirming security policies, which three configuration details should the engineer focus on to ensure communication between virtual systems? (Choose three.)
Add a route with next hop next-vr by using the VR configured in the virtual syste
Layer 3 zones for the virtual systems that need to communicate.
Add a route with next hop set to none, and use the interface of the virtual systems that need to communicat
Ensure the virtual systems are visible to one another.
External zones with the virtual systems added.
Se ha implementado un nuevo servidor de aplicaciones 192.168.197.40 en la DMZ. No hay direcciones IP públicas disponibles, lo que hace que el servidor comparta la IP NAT 198.51.100.88 con otro servidor DMZ que utiliza la dirección IP 192.168.197.60. Se han configurado la seguridad del firewall y las reglas NAT. El equipo de aplicaciones ha confirmado que el nuevo servidor puede establecer una conexión segura con una base de datos externa con la dirección IP 203.0.113.40.
El equipo de la base de datos informa que no puede establecer una conexión segura a 198.51.100.88 desde 203.0.113.40. Sin embargo, confirma una prueba de ping exitosa a 198.51.100.88.
En referencia a la configuración NAT y los registros de tráfico proporcionados, ¿cómo puede el ingeniero de firewall resolver la situación y garantizar que las conexiones entrantes y salientes funcionen simultáneamente para ambos servidores DMZ?
Move the NAT rule 6 DMZ server 2 above NAT rule 5 DMZ server 1
Replace the two NAT rules with a single rule that has both DMZ servers as "Source Address" both external servers as "Destination Address," and Source Translation remaining as is with bidirectional option enabled.
Configure separate source NAT and destination NAT rules for the two DMZ servers without using the bidirectional option.
Sharing a single NAT IP is possible for outbound connectivity not for inbound therefore a new public IP address must be obtained for the new DMZ server and used in the NAT rule 6 DMZ server 2.
A security team has enabled eal-time WildFire signature lookup on all its firewalls. Which additional action will further reduce the likelihood of newly discovered malware being allowed through the firewalls?
Enable the "Hold Mode" option in Objects > Security Profiles > Antivirus
Increase the frequency of the applications and threats dynamic updates
Increase the frequency of the antivirus dynamic updates
Enable the "Report Grayware Files" option in Device > Setup > WildFire
A company configures its WildFire analysis profile to forward any file type to the WildFire public cloud. A company employee receives an email containing an unknown link that downloads a malicious Portable Executable (PE) file.
What does Advanced WildFire do when the link is clicked?
Performs malicious content analysis on the linked page: but not the corresponding PE file
Performs malicious content analysis on the linked page and the corresponding PE file
Does not perform malicious content analysis on the linked page but performs it on the corresponding PE file
Does not perform malicious content analysis on either the linked page or the correspon
