Font size
WorksheetsExamen de práctica
Total questions: 60
Worksheet time: 3600secs
QUESTION 11 Which three methods may be used to deploy CN-Series firewalls? (Choose three.)
A. Terraform templates
B. Panorama plugin for Kubernetes
C. YAML file
D. Helm charts
E. Docker Swarm
QUESTION 17 Which three resources can help conduct planning and implementation of Palo Alto Networks NGFW solutions? (Choose three.)
A. Technical assistance center (TAC)
B. Partners / systems Integrators
C. Professional services
D. Proof of Concept Labs
E. QuickStart services
QUESTION 23 Why should a customer use advanced versions of Cloud-Delivered Security Services (CDSS) subscriptions compared to legacy versions when creating or editing a deployment profile? (e.g., using Advanced Threat Prevention instead of Threat Prevention.)
A. To improve firewall throughput by inspecting hashes of advanced packet headers
B. To download and install new threat-related signature databases in real-time
C. To use cloud-scale machine learning inline for detection of highly evasive and zero-day threats
D. To use external dynamic lists for blocking known malicious threat sources and destinations
QUESTION 31 Tags can be created for which three objects? (Choose three.)
A. Address groups
B. Dynamic NAT objects
C. External dynamic lists
D. Address objects
E. Service groups
QUESTION 14 Which two statements accurately describe cloud-native load balancing with Palo Alto Networks VMSeries firewalls and/or Cloud NGFW in public cloud environments? (Choose two.)
A. Cloud NGFWs distributed architecture model requires deployment of a single centralized firewall and will force all traffic to the firewall across pre-built VPN tunnels.
B. VM-Series firewall deployments in the public cloud will require the deployment of a cloud-native load balancer if high availability (HA) or redundancy is needed.
C. Cloud NGFW in AWS or Azure has load balancing built into the underlying solution and does not require the deployment of a separate load balancer.
D. VM-Series firewall load balancing is automated and is handled by the internal mechanics of the NGFW software without the need for a load balancer.
QUESTION 43 Why are VM-Series firewalls now grouped by four tiers?
A. To obscure the supported hypervisor manufacturer into generic terms
B. To simplify the portfolio and reduce the number of VM-Series models customers must choose from
C. To define the maximum limits for key criteria based on allocated memory
D. To define the priority level of support customers expect when opening a TAC case, from lowest tier 1 to highest tier 4
Which two deployment models does Cloud NGFW for AWS support? (Choose two.)
A. Hierarchical
B. Centralized
C. Distributed
D. Linear
QUESTION 18 A company wants to make its flexible-license VM-Series firewall, which runs on ESXi, process higher throughput. Which order of steps should be followed to minimize downtime?
A. Increase the vCPU within the deployment profile. Retrieve or fetch license keys on the VM-Series NGFW. Power-off the VM and increase the vCPUs within the hypervisor. Power-on the VM-Series NGFW. Confirm the correct tier level and vCPU appear on the NGFW dashboard.
B. Power-off the VM and increase the vCPUs within the hypervisor. Power-on the VM-Series NGFW. Retrieve or fetch license keys on the VM-Series NGFW. Increase the vCPU within the deployment profile. Confirm the correct tier level and vCPU appear on the NGFW dashboard.
C. Power-off the VM and increase the vCPUs within the hypervisor. Increase the vCPU within the deployment profile. Retrieve or fetch license keys on the VM-Series NGFW. Confirm the correct tier level and vCPU appear on the NGFW dashboard. Power-on the VM-Series NGFW.
D. Increase the vCPU within the deployment profile. Retrieve or fetch license keys on the VM-Series NGFW. Confirm the correct tier level and vCPU appear on the NGFW dashboard. Power-off the VM and increase the vCPUs within the hypervisor. Power-on the VM-Series NGFW.
QUESTION 5 When registering a software NGFW to the deployment profile without internet access (i.e., offline registration), what information must be provided in the customer support portal?
A. Authcode and serial number of the VM-Series firewall
B. Hypervisor installation ID and software version
C. Number of data plane and management plane interfaces
D. CPUID and UUID of the VM-Series firewall
QUESTION 16 A partner has successfully showcased and validated the efficacy of the Palo Alto Networks software firewall to a customer. Which two additional partner-delivered or Palo Alto Networks-delivered common options can the sales team offer to the customer before the sale is completed? (Choose two.)
A. Hardware collection and recycling services by Palo Alto Networks or by an approved NextWave Partner for the customers existing firewall infrastructure
B. Professional services delivered by Palo Alto Networks or by an approved Certified Professional Services Partner (CPSP) for deployment assistance or QuickStart
C. Network encryption services (NES) delivered by an approved NES partner to ensure none of the data traversed is readable by third-party entities
D. Managed services delivered by an approved Managed Security Services Program (MSSP) partner for dayto-day management of the environment
QUESTION 28 Which tool facilitates a customer's migration from existing legacy firewalls to Palo Alto Networks NextGeneration Firewalls (NGFWs)?
A. Expedition
B. Policy Optimizer
C. AutoFocus
D. IronSkillet
QUESTION 37 When using VM-Series firewall bootstrapping, which three methods can be used to install licensed content, including antivirus, applications, and threats? (Choose three.)
A. Panorama 10.2 or later to use the content auto push feature
B. Complete bootstrapping and either Azure Blob storage or Amazon S3 bucket
C. Content-Security-Policy update URL in the init-cfg.txt file
D. Custom-AMI or Azure VM image, with content preloaded
E. Panorama software licensing plugin
QUESTION 3 What are three benefits of Palo Alto Networks VM-Series firewalls as they relate to direct integration with thirdparty network virtualization solution providers? (Choose three.)
A. Integration with Cisco ACI allows insertion of a virtual firewall and enforcement of dynamic policies between endpoint groups without the need for manual policy adjustments.
B. Integration with a third-party network virtualization solution allows management and deployment of the entire virtual network and hosts directly from Panorama.
C. Integration with Nutanix AHV allows the firewall to be dynamically informed of changes in the environment and ensures policy is applied to virtual machines (VMs) as they join the network.
D. Integration with VMware NSX provides comprehensive visibility and security of all virtualized data center traffic including intra-host ESXi virtual machine (VM) communications.
E. Integration with network virtualization solution providers allows manual deployment and management of firewall rules through multiple interfaces and front ends specific to each technology.
QUESTION 51 What can a firewall use to automatically update Security policies with new IP address information for a virtual machine (VM) when it has moved from host-A to host-B because host-A is down or undergoing periodic maintenance?
A. Dynamic Address Groups
B. Dynamic User Groups
C. Dynamic Host Groups
D. Dynamic IP Groups
QUESTION 20 Which three statements describe benefits of Palo Alto Networks Cloud-Delivered Security Services (CDSS) over other vendor solutions? (Choose three.)
A. Individually targeted products provide better security than platform solutions.
B. Multi-vendor best-of-breed products provide security coverage on a per-use-case basis.
C. It requires no additional performance overhead when enabling additional features.
D. It provides simplified management through fewer consoles for more effective security coverage.
E. It significantly reduces the total cost of ownership for the customer.
QUESTION 9 Which use case is valid for Strata Cloud Manager (SCM)?
A. Provisioning and licensing new CN-Series firewall deployments
B. Providing AI-Powered ADEM for all Prisma Access users
C. Supporting pre PAN-OS 10.1 SD-WAN migrations to SCM
D. Providing API-driven plugin framework for integration with third-party ecosystems
QUESTION 2 A company has created a custom application that collects URLs from various websites and then lists bad sites. They want to update a custom URL category on the firewall with the URLs collected. Which tool can automate these updates?
A. Dynamic User Groups
B. SNMP SET
C. Dynamic Address Groups
D. XMLAPI
QUESTION 40 Which three statements describe benefits of the memory scaling feature introduced in PAN-OS 10.2? (Choose three.)
A. Increased maximum throughput with additional memory
B. Increased maximum sessions with additional memory
C. Increased maximum number of Dynamic Address Groups with additional memory
D. Increased number of tags per IP address with additional memory
E. Increased maximum security rule count with additional memory
QUESTION 49 A company has used software NGFW credits to deploy several VM-Series firewalls with Advanced URL Filtering in the company's deployment profiles. The IT department has determined that the firewalls no longer need the Advanced URL Filtering license. How can this license be removed from the hosts?
A. Edit the current deployment profile to remove the Advanced URL Filtering license.
B. On the firewall, issue this command: > delete url subscription license.
C. Add a new deployment profile with all the licenses selected except Advanced URL Filtering.
D. Delete the current deployment profile from the cloud service provider.
QUESTION 55 What are three Palo Alto Networks VM-Series firewall reference architecture deployment models? (Choose three.)
A. Cloud NGFW for AWS: Combined Model
B. AWS VM-Series: Isolated Transit Gateway
C. Cloud NGFW for Azure: Virtual WAN integration
D. GCP VM-Series: VPC network peering model with Shared VPC
E. Azure VM-Series: Distributed VCN - common firewall
QUESTION 29 Which statement describes a benefit of using automation tools like Ansible, Terraform, or pan-ospython to manage PAN-OS firewalls and Panorama?
A. It will automatically optimize PAN-OS device performance without requiring any input from the administrator.
B. It will completely replace the PAN-OS web interface for all management tasks.
C. It eliminates the need to understand PAN-OS configuration concepts and best practices.
D. It maintains consistency and reduces the risk of human error when managing multiple PAN-OS devices.
QUESTION 13 Which three tools are available to customers to facilitate the simplified and/or best-practice configuration of Palo Alto Networks Next-Generation Firewalls (NGFWs)? (Choose three.)
A. Telemetry to ensure that Palo Alto Networks has full visibility into the firewall configuration
B. Day 1 Configuration through the customer support portal (CSP)
C. Policy Optimizer to help identify and recommend Layer 7 policy changes
D. Expedition to enable the creation of custom threat signatures
E. Best Practice Assessment (BPA) in Strata Cloud Manager (SCM)
QUESTION 58 Which three features are supported by CN-Series firewalls? (Choose three.)
A. App-ID
B. Decryption
C. GlobalProtect
D. Content-ID
E. IPSec
QUESTION 19 A Cloud NGFW for Azure can be deployed to which two environments? (Choose two.)
A. Azure Kubernetes Service (AKS)
B. Azure Virtual WAN
C. Azure DevOps
D. Azure VNET
Which three solutions does Strata Cloud Manager (SCM) support? (Choose three.)
A. Prisma Cloud
B. CN-Series firewalls
A. Prisma Access
A. PA-Series firewalls
A. VM-Series firewalls
Which three statements describe common characteristics of Cloud NGFW and VM-Series offerings? (Choose three.)
A. In Azure, both offerings can be integrated directly into Virtual WAN hubs.
A. In Azure and AWS, both offerings can be managed by Panorama.
A. In AWS, both offerings can be managed by AWS Firewall Manager.
A. In Azure, inbound destination NAT configuration also requires source NAT to maintain flow symmetry.
A. In Azure and AWS, internal (east-west) flows can be inspected without any NAT.
Which capability, as described in the Securing Applications series of design guides for VM-Series firewalls, is common across Azure, GCP, and AWS?
A. BGP dynamic routing to peer with cloud and on-premises routers
A. GlobalProtect portal and gateway services
Horizontal scalability through cloud-native load balancers
A. Site-to-site VPN
A company that purchased software NGFW credits from Palo Alto Networks has made a decision on the number of virtual machines (VMs) and licenses they wish to deploy in AWS cloud. How are the VM licenses created?
A. Access the AWS Marketplace and use the software NGFW credits to purchase the VMs.
A. Access the Palo Alto Networks Application Hub and create a new VM profile.
A. Access the Palo Alto Networks Customer Support Portal and request the creation of a new software NGFWserial number.
Access the Palo Alto Networks Customer Support Portal and create a software NGFW credits deploymentprofile.
What is the primary purpose of the pan-os-python SDK?
A. To create a Python-based firewall that is compatible with the latest PAN-OS
A. To replace the PAN-OS web interface with a Python-based interface
A. To automate the deployment of PAN-OS firewalls by using Python
A. To provide a Python interface to interact with PAN-OS firewalls and Panorama
What are three components of Cloud NGFW for AWS? (Choose three.)
A. Cloud NGFW Resource
A. Local or Global Rulestacks
Cloud NGFW Inspector
A. Amazon S3 bucket
A. Cloud NGFW Tenant
What are two benefits of using a Palo Alto Networks NGFW in a public cloud environment? (Choose two.)
A. Complete security solution for the public cloud provider's physical host regardless of security measures
Automatic scaling of NGFWs to meet the security needs of growing applications and public cloudenvironments
Ability to manage the public cloud provider's physical hosts
A. Consistent Security policy to inbound, outbound, and east-west network traffic throughout the multi-cloudenvironment
What three benefits does flex licensing for VM-Series firewalls offer? (Choose three.)
A. Licensing additional memory resources to increase session capacity
A. Licensing Strata Cloud Manager, Panorama with Dedicated Log Collectors, and CDSS per deploymentprofile
A. Using a pool of credits for both CN-Series firewall and VM-Series firewall deployment profiles
A. Moving credits between public and private cloud VM-Series firewall deployments
A. Vertically scaling the number of licensed cores in an existing fixed deployment profile
A company is sponsoring a cybersecurity conference for attendees interested in a range of cybersecurity products that include malware protection, SASE, automation products, and firewalls.
The company will deliver a single 3"4 hour conference workshop.
Which cybersecurity portfolio tool will give workshop attendees the appropriate exposure to the widest variety of Palo Alto Networks products?
A. Capture the Flag
Ultimate Lab Environment
A. Demo Environment
A. Ultimate Test Drive
Which three tools or methods automate VM-Series firewall deployment? (Choose three.)
A. Panorama Software Firewall License plugin
A. Palo Alto Networks GitHub repository
A. Bootstrap the VM-Series firewall
A. Shared Disk Software Library folder
A. Panorama Software Library image
Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)
A. Its update requires "Commit" to enforce membership mapping.
A. It allows creation and enforcement of consistent Security policy across multiple cloud environments.
A. Tags cannot be defined statically on the firewall.
A. It uses tags as filtering criteria to determine IP address mapping to a group.
A. Its maximum number of registered IP addresses is dependent on the firewall platform.
A systems engineer (SE) is informed by the primary contact at a bank of an unused balance of 15,000 software NGFW flexible credits the bank does not want to lose when they expire in 1.5 years. The SE is told that the bank's new risk and compliance officer is concerned that its operation is too permissive when allowing its servers to send traffic to SaaS vendors. Currently, its AWS and Azure VM-Series firewalls only use Advanced Threat Prevention.
What should the SE recommend to address the customer's concerns?
A. Activate Advanced WildFire within the software NGFW deployment profiles, starting with the largest vCPUmodels and working down to the smallest to protect their biggest workloads.
A. Subscribe to DNS Security, Advanced URL Filtering, and Advanced WildFire across all software NGFWdeployment profiles until all the credits are used.
A. Verify conformance to standards and regulations, the risk of failure, and the criticality of each workload to be protected, then determine which deployment profile subscriptions address the needs.
A. Activate Advanced WildFire within the software NGFW deployment profiles, starting with the smallest vCPUmodels and working up to the largest to provide coverage for more VPCs and VNets with their current credit balance.
Which three presales methods will help secure the technical win of software firewalls? (Choose three.)
A. Provide link to PAYG Cloud NGFW in the Azure Marketplace
A. Unsolicited proposals that disregard customer needs
Network Security Design workshops
A. Proof of Value (POV) product evaluations
What are three benefits of using Palo Alto Networks software firewalls in public cloud, private cloud, and hybrid cloud environments? (Choose three.)
A. They allow for centralized management of all firewalls, regardless of where or how they are deployed.
A. They allow for complex management of per-use case security needs through multiple point products.
A. They provide consistent policy enforcement across all architectures, whether on-premises or in the cloud.
A. They allow management of underlying public cloud architecture without needing to leave the firewall itself.
A. They create a simplified consumption and deployment model throughout the production environment.
Which three statements describe restrictions or characteristics of Firewall flex credit profiles of a credit pool in the Palo Alto Networks customer support portal? (Choose three.)
The number of licensed cores must match the number of provisioned CPU cores per instance.
Allocate credits for use with Cloud NGFW for AWS and Azure.
Each VM-Series firewall deployment profile is either fixed or flexible.
All firewalls activated to a deployment profile will have the same Cloud-Delivered Security Services (CDSS).
Each deployment profile is either CN-Series firewall or VM-Series firewall.
A company has purchased Palo Alto Networks Software NGFW credits and wants to run PAN-OS 11.x virtual machines (VMs).
Which two types of VMs can be selected when creating the deployment profile? (Choose two.)
A. VM-100
A. Fixed vCPU models
A. Flexible model of working memory
A. Flexible vCPUs
Per reference architecture, which default PAN-OS configuration should be overridden to make VMSeries firewall deployments in the public cloud more secure?
A. Intrazone-default rule action and logging
B. Interzone-default rule service
C. Interzone-default rule action and logging
C. Intrazone-default rule service
Which two products are deployed with Terraform for high levels of automation and integration? (Choose two.)
A. Cloud NGFW
A. VM-Series firewall
A. Cortex XSOAR
Prisma Access
CN-Series firewalls offer threat protection for which three use cases? (Choose three.)
A. Prevention of sensitive data exfiltration from Kubernetes environments
A. All Kubernetes workloads in the public and private cloud
A. Inbound, outbound, and east-west traffic between containers
A. All workloads deployed on-premises or in the public cloud
A. Enforcement of segmentation policies that prevent lateral movement of threats
Which statement correctly describes behavior when using Ansible to automate configuration changes on a PAN-OS firewall or in Panorama?
A. Ansible can only be used to automate configuration changes on physical firewalls but not virtual firewalls.
Ansible requires direct access to the firewalls CLI to make changes.
A. Ansible uses the XML API to make configuration changes to PAN-OS.
A. Ansible requires the use of Python to create playbooks.
Which three statements describe the functionality of Dynamic Address Groups and tags? (Choose three.)
A. Static tags are part of the configuration on the firewall, while dynamic tags are part of the runtimeconfiguration.
A. Dynamic Address Groups that are referenced in Security policies must be committed on the firewall.
A. To dynamically register tags, use either the XML API or the VM Monitoring agent on the firewall or on theUser-ID agent.
A. IP-Tag registrations to Dynamic Address Groups must be committed on the firewall after each change.
A. Dynamic Address Groups use tags as filtering criteria to determine their members, and filters do not uselogical operators.
Which two statements describe the functionality of the VM-Series firewall plugin? (Choose two.)
A. The installed VM-Series firewall plugin on the VM-Series firewall can only be upgraded or deleted.
A. The Panorama plugin must be installed on the VM-Series firewall to enable communication with Panorama.
A. To use Panorama to configure public cloud VM-Series firewall integrations, the VM-Series firewall pluginmust be installed on Panorama.
A. The VM-Series firewall plugin on Panorama is not built in and must be installed to enable communicationand manage the environment.
Which three capabilities and characteristics are shared by the deployments of Cloud NGFW for Azure and VM-
Series firewalls? (Choose three.)
A. Panorama management
A. Inter-VNet inspection through Virtual WAN hub
A. Transparent inspection of private-to-private east-west traffic that preserves client source IP address
A. Inter-VNet inspection through a transit VNet
A. Use of routing intent policies to apply security policies
Which three statements describe the functionality of Panorama plugins? (Choose three.)
A. Limited to one plugin installation on Panorama
A. Supports other Palo Alto Networks products and configurations with NGFWs
A. May be installed on Panorama from the Palo Alto Networks customer support portal
A. Complies with third-party product/platform integration and configuration with NGFWs
A. Expands capabilities of hardware and software NGFWs
A company needs a repeatable process to streamline the deployment of new VM-Series firewalls on its network by using the complete bootstrap method.
Which file is used in the bootstrap package to configure the management interface of the firewall?
A. init-mgmt-cfg.txt
B. init-cfg.txt
C. init-cfg.bat
D. bootstrap.bat
Which three Cloud NGFW management tasks are inherently performed by the service within AWS and Azure?
(Choose three.)
A. Horizontally scaling out to meet increased traffic demand
B. Installing new content (applications and threats)
C. Installing new PAN-OS software updates
D. Blocking high-risk S2C threats in accordance with SOC2 compliance
E. Decrypting high-risk SSL traffic
Which statement applies when identifying the appropriate Palo Alto Networks firewall platform for virtualized as well as cloud environments?
A. VM-Series firewalls cannot be used to protect container environments.
B. All NGFW platforms support API integration.
C. Panorama is the only unified management console for all NGFWs.
D. CN-Series firewalls are used to protect virtualized environments.
What are three valid methods that use firewall flex credits to activate VM-Series firewall licenses by specifying authcode? (Choose three.)
A. /config/bootstrap.xml file of complete bootstrapping package
B. /license/authcodes file of complete bootstrap package
C. Panorama device group in Panorama SW Licensing Plugin
D. authcodes= key value pair of Azure Vault configuration
E. authcodes= key value pair of basic bootstrapping configuration
Which two software firewall types can protect egress traffic from workloads attached to an Azure vWAN hub?
(Choose two.)
A. Cloud NGFW
B. PA-Series
C. CN-Series
D. VM-Series
Which two public cloud service provider (CSP) environments offer, through their marketplace, a Cloud NGFW under the CSP's own brand name? (Choose two.)
A. Oracle Cloud Infrastructure (OCI)
B. IBM Cloud (previously Softlayer)
C. Alibaba Cloud
D. Google Cloud Platform (GCP)
Which three presales resources are available to field systems engineers for technical assistance, innovation consultation, and industry differentiation insights? (Choose three.)
A. Palo Alto Networks consulting engineers
B. Professional services delivery
C. Technical account managers
D. Reference architectures
E. Palo Alto Networks principal solutions architects
Which three statements describe functionality of NGFW inline placement for Layer 2 implementation? (Choose three.)
A. VMs on VMware ESXi hypervisors can be segregated from one another on the network by the VMSeries NGFW by IP addressing and Layer 3 gateways.
B. VMs on VMware ESXi hypervisors can be segregated from each other by the VM-Series NGFW using VLAN tags while preserving existing Layer 3 gateways.
C. VM-Series next-generation firewalls cannot be positioned between the physical datacenter network and guest VM workloads.
.
D. VM-Series next-generation firewalls do not support VMware vMotion or guest VM workloads.
E. A next-generation firewall VLAN interface can function as a Layer 3 interface
What are two methods or tools to directly automate the deployment of VM-Series NGFWs into supported public clouds? (Choose two.)
A. GitHub PaloAltoNetworks Terraform SWFW modules
B. Deployment configuration in the public cloud Panorama plugins
C. paloaltonetworks.panos Ansible collection
D. panos Terraform provider
What are two benefits of credit-based flexible licensing for software firewalls? (Choose two.)
A. Create virtual Panoramas.
B. Add Cloud-Delivered Security Services (CDSS) subscriptions to CN-Series firewalls.
C. Create Cloud NGFWs.
D. Add Cloud-Delivered Security Services (CDSS) subscriptions to PA-Series firewalls.
Which public cloud provider requires the creation of subnets that are dedicated to Cloud NGFW endpoints?
A. Google Cloud Platform (GCP)
B. Alibaba Cloud
C. Amazon Web Services (AWS)
D. Microsoft Azure
Which element protects and hides an internal network in an outbound flow?
A. DNS sinkholing
B. User-ID
C. App-ID
D. NAT
