لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?
A. Create an Application Filter and name it Office Programs, the filter it on the business-systems category, office-programs subcategory
B. Create an Application Group and add business-systems to it
C. Create an Application Filter and name it Office Programs, then filter it on the business-systems category
D. Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office
عرض الإجابة
اجابة صحيحة: A
السؤال #2
Which administrator type provides more granular options to determine what the administrator can view and modify when creating an administrator account?
A. Root
B. Dynamic
C. Role-based
D. Superuser
عرض الإجابة
اجابة صحيحة: C
السؤال #3
Which action ensures that sensitive information such as medical records, financial transactions, and legal communications are not decrypted and that they maintain strong security?
A. reate a log forwarding filter to exclude sensitive information
B. isable decryption globally to avoid exposing sensitive data
C. reate an SSL Inbound Inspection policy to identify users sending sensitive information
D. reate a no-decrypt policy for traffic matching specific URL categories
عرض الإجابة
اجابة صحيحة: D
السؤال #4
Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that matches new application signatures?
A. Review Policies
B. Review Apps
C. Pre-analyze
D. Review App Matches
عرض الإجابة
اجابة صحيحة: A
السؤال #5
Which two App-ID applications will need to be allowed to use Facebook-chat? (Choose two.)
A. facebook
B. facebook-chat
C. facebook-base
D. facebook-email
عرض الإجابة
اجابة صحيحة: BC
السؤال #6
What must be configured for the firewall to access multiple authentication profiles for external services to authenticate a non-local account?
A. authentication sequence
B. LDAP server profile
C. authentication server list
D. authentication list profile
عرض الإجابة
اجابة صحيحة: A
السؤال #7
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?
A. Policies> Security> Rule Usage> No App Specified
B. Policies> Security> Rule Usage> Port only specified
C. Policies> Security> Rule Usage> Port-based Rules
D. Policies> Security> Rule Usage> Unused Apps
عرض الإجابة
اجابة صحيحة: A
السؤال #8
Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?
A. Windows session monitoring via a domain controller
B. passive server monitoring using the Windows-based agent
C. Captive Portal
D. passive server monitoring using a PAN-OS integrated User-ID agent
عرض الإجابة
اجابة صحيحة: C
السؤال #9
Users from the internal zone need to be allowed to Telnet into a server in the DMZ zone.Complete the security policy to ensure only Telnet is allowed.Security Policy: Source Zone: Internal to DMZ Zone __________services "Application defaults", and action = Allow
A. Destination IP: 192
B. Application = `Telnet'
C. Log Forwarding
D. USER-ID = `Allow users in Trusted'
عرض الإجابة
اجابة صحيحة: B
السؤال #10
Which license must an Administrator acquire prior to downloading Antivirus Updates for use with the firewall?
A. Threat Prevention License
B. Threat Implementation License
C. Threat Environment License
D. Threat Protection License
عرض الإجابة
اجابة صحيحة: A
السؤال #11
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?
A. Policies> Security> Rule Usage> No App Specified
B. Policies> Security> Rule Usage> Port only specified
C. Policies> Security> Rule Usage> Port-based Rules
D. Policies> Security> Rule Usage> Unused Apps
عرض الإجابة
اجابة صحيحة: A
السؤال #12
Which option lists the attributes that are selectable when setting up an Application filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology
عرض الإجابة
اجابة صحيحة: B
السؤال #13
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
A. Device>Setup>Services
B. Device>Setup>Management
C. Device>Setup>Operations
D. Device>Setup>Interfaces
عرض الإجابة
اجابة صحيحة: C
السؤال #14
Which update option is not available to administrators?
A. New Spyware Notifications
B. New URLs
C. New Application Signatures
D. New Malicious Domains
E. New Antivirus Signatures
عرض الإجابة
اجابة صحيحة: B
السؤال #15
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
A. Device>Setup>Services
B. Device>Setup>Management
C. Device>Setup>Operations
D. Device>Setup>Interfaces
عرض الإجابة
اجابة صحيحة: C
السؤال #16
In the example security policy shown, which two websites fcked? (Choose two.)
A. LinkedIn
B. Facebook
C. YouTube
D. Amazon
عرض الإجابة
اجابة صحيحة: AB
السؤال #17
A network has 10 domain controllers, multiple WAN links, and a network infrastructure with bandwidth needed to support mission-critical applications. Given the scenario, which type of User-ID agent is considered a best practice by Palo Alto Networks?
A. Windows-based agent on a domain controller
B. Captive Portal
C. Citrix terminal server with adequate data-plane resources
D. PAN-OS integrated agent
عرض الإجابة
اجابة صحيحة: A
السؤال #18
Which firewall plane provides configuration, logging, and reporting functions on a separate processor?
A. control
B. network processing
C. data
D. security processing
عرض الإجابة
اجابة صحيحة: A
السؤال #19
The PowerBall Lottery has reached a high payout amount and a company has decided to help employee morale by allowing employees to check the number, but doesn't want to unblock the gambling URL category.Which two methods will allow the employees to get to the PowerBall Lottery site without the company unlocking the gambling URL category? (Choose two.)
A. Add all the URLs from the gambling category except powerball
B. Manually remove powerball
C. Add *
D. Create a custom URL category called PowerBall and add *
عرض الإجابة
اجابة صحيحة: CD
السؤال #20
How often does WildFire release dynamic updates?
A. every 5 minutes
B. every 15 minutes
C. every 60 minutes
D. every 30 minutes
عرض الإجابة
اجابة صحيحة: A
السؤال #21
Which two configuration settings shown are not the default? (Choose two.)
A. Enable Security Log
B. Server Log Monitor Frequency (sec)
C. Enable Session
D. Enable Probing
عرض الإجابة
اجابة صحيحة: BC
السؤال #22
Which prevention technique will prevent attacks based on packet count?
A. zone protection profile
B. URL filtering profile
C. antivirus profile
D. vulnerability profile
عرض الإجابة
اجابة صحيحة: A
السؤال #23
Recently changes were made to the firewall to optimize the policies and the security team wants to see if those changes are helping.What is the quickest way to reset the hit counter to zero in all the security policy rules?
A. At the CLI enter the command reset rules and press Enter
B. Highlight a rule and use the Reset Rule Hit Counter > Selected Rules for each rule
C. Reboot the firewall
D. Use the Reset Rule Hit Counter > All Rules option
عرض الإجابة
اجابة صحيحة: D
السؤال #24
When pushing a configuration from Panorama to multiple firewalls, an analyst wants to ensure that a specific local interface setting on one firewall is not overwritten by the template value. Which feature should be used?
A. emplate Stack
B. emplate Variable
C. olicy Optimizer
D. evice Group Override
عرض الإجابة
اجابة صحيحة: B
السؤال #25
Which Strata Cloud Manager (SCM) feature provides a consolidated view of all high-priority security incidents across a global network, including those from firewalls and Prisma Access?
A. AActivity Insights
B. BCommand Center
C. CPolicy Optimizer
D. DDevice Health Dashboard
عرض الإجابة
اجابة صحيحة: B
السؤال #26
An analyst wants to create a custom application for an internal tool that uses a specific proprietary protocol.Which information is required to ensure the firewall correctly identifies this application using App-ID?
A. he MAC address of the server
B. ignature patterns found in the packet payload
C. ource and Destination IP addresses
D. he URL category of the server
عرض الإجابة
اجابة صحيحة: B
السؤال #27
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)
A. Layer-ID
B. User-ID
C. QoS-ID
D. App-ID
عرض الإجابة
اجابة صحيحة: BD
السؤال #28
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
A. Device>Setup>Services
B. Device>Setup>Management
C. Device>Setup>Operations
D. Device>Setup>Interfaces
عرض الإجابة
اجابة صحيحة: C
السؤال #29
When performing a "Push to Devices" from Panorama, an analyst wants to ensure that the push only affects a specific firewall in a shared Device Group. Which option in the push window allows this granular selection?
A. erge with Device Candidate Config
B. nclude Device and Network Templates
C. dit Selections
D. orce Template Values
عرض الإجابة
اجابة صحيحة: C
السؤال #30
An analyst is investigating why an App-ID for a custom application is showing as "unknown-tcp" in the Traffic logs. The application is running on port 8080. What is the most likely cause of this identification failure?
A. The firewall does not have a signature for the proprietary application
B. The Security policy is set to 'application-default
C. The traffic is being decrypted by an SSL Forward Proxy
D. The URL category is 'private-ip-addresses
عرض الإجابة
اجابة صحيحة: A
السؤال #31
Which statement is true regarding a Best Practice Assessment?
A. The BPA tool can be run only on firewalls
B. It provides a percentage of adoption for each assessment data
C. The assessment, guided by an experienced sales engineer, helps determine the areas of greatest risk where you should focus prevention activities
D. It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture
عرض الإجابة
اجابة صحيحة: C
السؤال #32
In Panorama, which feature allows an analyst to group multiple Template Stacks together to push a common set of network configurations to a large number of firewalls simultaneously?
A. ariables
B. emplate Groups
C. evice Groups
D. anaged Collectors
عرض الإجابة
اجابة صحيحة: A
السؤال #33
The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.Which security profile feature could have been used to prevent the communication with the CnC server?
A. Create an anti-spyware profile and enable DNS Sinkhole
B. Create an antivirus profile and enable DNS Sinkhole
C. Create a URL filtering profile and block the DNS Sinkhole category
D. Create a security policy and enable DNS Sinkhole
عرض الإجابة
اجابة صحيحة: A
السؤال #34
Given the image, which two options are true about the Security policy rules. (Choose two.)
A. The Allow Office Programs rule is using an Application Filter
B. In the Allow FTP to web server rule, FTP is allowed using App-ID
C. The Allow Office Programs rule is using an Application Group
D. In the Allow Social Networking rule, allows all of Facebook's functions
عرض الإجابة
اجابة صحيحة: AD
السؤال #35
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server.Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)
A. vulnerability protection profile applied to outbound security policies
B. anti-spyware profile applied to outbound security policies
C. antivirus profile applied to outbound security policies
D. URL filtering profile applied to outbound security policies
عرض الإجابة
اجابة صحيحة: BD
السؤال #36
Which Palo Alto Networks firewall security platform provides network security for mobile endpoints by inspecting traffic deployed as internet gateways?
A. GlobalProtect
B. AutoFocus
C. Aperture
D. Panorama
عرض الإجابة
اجابة صحيحة: A
السؤال #37
Given the scenario, which two statements are correct regarding multiple static default routes? (Choose two.)
A. Path monitoring does not determine if route is useable
B. Route with highest metric is actively used
C. Path monitoring determines if route is useable
D. Route with lowest metric is actively used
عرض الإجابة
اجابة صحيحة: CD
السؤال #38
A security administrator is creating an internet of things (IoT) Security policy and needs to select behaviors for the trafficюWhich characteristic has the greatest impact to the risk level of applications?
A. Used by Malware
B. Pervasive
C. Tunnels Other Apps
D. Known Vulnerabilities
عرض الإجابة
اجابة صحيحة: A
السؤال #39
A security administrator wants to determine which action a URL Filtering profile will take on the URL "www.chatgpt.com." The firewall has a custom URL object with "www.chatgpt.com/" as a member called "Permitted-AI." The URL "www.chatgpt.com" is also categorized as "Artificial-Intelligence, " "Computer-and-Internet-Info," and "Low-Risk." The URL Filtering profile has thefollowing in descending order:• Artificial-Intelligence set to continue• Computer-and-Internet-Info set to block• Low-Risk set to alert• Permitted-AI set to allowWhich action will the URL Filtering profile take when traffic matches the "www.chatgpt.com" URL on a rule with this profile attached?
A. Continue
B. Alert
C. Allow
D. Block
عرض الإجابة
اجابة صحيحة: C

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us