لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
A. t acts as a logging service for NGFW performance metrics
B. t orchestrates real-time traffic inspection for network segments
C. t provides Infrastructure-as-Code (IaC) to automate NGFW deployment
D. t manages threat intelligence data synchronization with NGFWs
عرض الإجابة
اجابة صحيحة: C
السؤال #2
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA - Series, and VM - Series devices used in physical data centers. Resources exist on AWS and Azure The AWS deployment is architected with AWS Transit Gateway, to which all resources connect The Azure deployment is architected with each application independently routing traffic The engineer deploying Cloud NGFW in these two cloud environments must account for the following Minimize changes to the two cloud environments Scale to the demands of the applications while using the least amount of compute resources Allow the company to unify the Security policies across all protected areas Which two implementations will meet these requirements? (Choose two.)
A. Deploy a VM - Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and Azure, and manage the policy with Panorama
B. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the deployed NGFWs, and manage the policy with Panorama
C. Deploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the Cloud NGFW attached to the vWAN, and manage the policy with local rules
D. Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route all appropriate traffic through the Security VPC, and manage the policy with Panorama
عرض الإجابة
اجابة صحيحة: BD
السؤال #3
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish.Which of the following actions will resolve this issue?
A. Ensure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel interface
B. Configure the Proxy IDs to match the Cisco ASA configuration
C. Check that IPSec is enabled in the management profile on the external interface
D. Validate the tunnel interface VLAN against the peer's configuration
عرض الإجابة
اجابة صحيحة: B
السؤال #4
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
عرض الإجابة
اجابة صحيحة: D
السؤال #5
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
A. It does not accept the configuration
B. It accepts the configuration but throws a warning message
C. It removes the static route because 0 is a NULL value
D. It reinstalls the route into the routing information base (RIB) as soon as the path comes up
عرض الإجابة
اجابة صحيحة: D
السؤال #6
An NGFW engineer is configuring multiple Layer 2 interfaces on a Palo Alto Networks firewall, and all interfaces must be assigned to the same VLAN. During initial testing, it is reported that clients located behind the various interfaces cannot communicate with each other.Which action taken by the engineer will resolve this issue?
A. Configure each interface to belong to the same Layer 2 zone and enable IP routing between them
B. Assign each interface to the appropriate Layer 2 zone and configure a policy that allows traffic within the VLAN
C. Assign each interface to the appropriate Layer 2 zone and configure Security policies for interfaces not assigned to the same zone
D. Enable IP routing between the interfaces and configure a Security policy to allow traffic between interfaces within the VLAN
عرض الإجابة
اجابة صحيحة: B
السؤال #7
By default, which type of traffic is configured by service route configuration to use the management interface?
A. Security zone
B. IPSec tunnel
C. Virtual system (VSYS)
D. Autonomous Digital Experience Manager (ADEM)
عرض الإجابة
اجابة صحيحة: D
السؤال #8
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
A. It does not accept the configuration
B. It accepts the configuration but throws a warning message
C. It removes the static route because 0 is a NULL value
D. It reinstalls the route into the routing information base (RIB) as soon as the path comes up
عرض الإجابة
اجابة صحيحة: D
السؤال #9
After a recent security audit, a company is required to enforce more strict validation for all certificate-based authentication, including for GlobalProtect clients. An engineer observes the firewall accepting certificates from a recently compromised intermediate certificate authority (CA). The engineer needs to update the firewall configuration to use an Online Certificate Status Protocol (OCSP) responder to check for revoked certificates in real time.In which configuration object would the engineer enable OCSP verification for the CAs used in the authentication process?
A. Authentication sequence
B. Decryption profile
C. SSL/TLS service profile
D. Certificate profile
عرض الإجابة
اجابة صحيحة: D
السؤال #10
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
A. Flood Protection
B. Protocol Protection
C. Packet-Based Attack Protection
D. Reconnaissance Protection
عرض الإجابة
اجابة صحيحة: B
السؤال #11
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers.Resources exist on AWS and Azure:The AWS deployment is architected with AWS Transit Gateway, to which all resources connectThe Azure deployment is architected with each application independently routing trafficThe engineer deploying Cloud NGFW in these two cloud environments must account for the following:Minimize changes to the two cloud environmentsScale to the demands of the applications while using the least amount of compute resourcesAllow the company to unify the Security policies across all protected areasWhich two implementations will meet these requirements? (Choose two.)
A. Deploy a VM-Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and Azure, and manage the policy with Panorama
B. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the deployed NGFWs, and manage the policy with Panorama
C. Deploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the Cloud NGFW attached to the vWAN, and manage the policy with local rules
D. Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route all appropriate traffic through the Security VPC, and manage the policy with Panorama
عرض الإجابة
اجابة صحيحة: BD
السؤال #12
During an upgrade to the routing infrastructure in a customer environment, the network administrator wants to implement Advanced Routing Engine (ARE) on a Palo Alto Networks firewall.Which firewall models support this configuration?
A. PA-5280, PA-7080, PA-3250, VM-Series
B. PA-455, VM-Series, PA-1410, PA-5450
C. PA-3260, PA-5410, PA-850, PA-460
D. PA-7050, PA-1420, VM-Series, CN-Series
عرض الإجابة
اجابة صحيحة: C
السؤال #13
An organization must secure its AWS and Azure environments using a managed Palo Alto Networks solution, and all policies must be synchronized from an existing Panorama deployment. The organization wants to insert security with the least possible impact on its application teams and use existing hub-and-spoke network designs. * The AWS environment uses a centralized AWS Transit Gateway (TGW) architecture. * The Azure environment uses a Virtual WAN (vWAN) hub. Which two actions are the most appropriate in this use case? (Choose two.)
A. ADeploy Cloud NGFW endpoints in every application virtual private cloud (VPC), ignoring the TGW
B. BDeploy Cloud NGFW into the vWAN hub as a trusted security partner, and update routing policies to secure traffic
C. CDeploy individual VM-Series firewalls in each spoke virtual network (VNet) and manage them as a device group in Panorama
D. DDeploy Cloud NGFW endpoints into a security virtual private cloud (VPC), and adjust the TGW route tables to inspect traffic flowing though the hub
عرض الإجابة
اجابة صحيحة: BD
السؤال #14
A firewall administrator uses Panorama to manage a fleet of firewalls. After successfully onboarding the firewalls to Strata Logging Service and enabling cloud logging via a template, the security operations team reports that they can no longer see new logs on the on-premises Panorama log collectors. Logs are appearing correctly in Strata Logging Service. Which setting was likely missed in the Panorama template configuration?
A. AThe device certificates for the Panorama log collectors were not renewed after enabling the cloud logging connection
B. BDuplicate logging (cloud and on-premises) is disabled under Device --> Setup --> Management
C. CThe Log Forwarding profile was modified to send logs only to the Strata Logging Service and no longer includes the on-premises Panorama log collectors
D. DThe Panorama log collectors were not defined as primary destinations within the collector group configuration for the managed firewalls
عرض الإجابة
اجابة صحيحة: B
السؤال #15
Which interface types should be used to configure link monitoring for a high availability (HA) deployment on a Palo Alto Networks NGFW?
A. HA, Virtual Wire, and Layer 2
B. Tap, Virtual Wire, and Layer 3
C. Virtual Wire, Layer 2, and Layer 3
D. HA, Layer 2
عرض الإجابة
اجابة صحيحة: C
السؤال #16
In regard to the Advanced Routing Engine (ARE), what must be enabled first when configuring a logical router on a PAN-OS firewall?
A. License
B. Plugin
C. Content update
D. General setting
عرض الإجابة
اجابة صحيحة: A
السؤال #17
Which configuration step is required when implementing a new self-signed root certificate authority (CA) certificate for SSL decryption on a Palo Alto Networks firewall?
A. Import the new subordinate CA certificate into the trust stores of all client devices
B. Set the subordinate CA certificate as the default routing certificate for all network traffic
C. Configure the subordinate CA to issue certificates with indefinite validity periods
D. Disable all existing SSL decryption rules until the new certificate is fully propagated
عرض الإجابة
اجابة صحيحة: A
السؤال #18
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
A. Flood Protection
B. Protocol Protection
C. Packet-Based Attack Protection
D. Reconnaissance Protection
عرض الإجابة
اجابة صحيحة: B
السؤال #19
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
عرض الإجابة
اجابة صحيحة: D
السؤال #20
An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service.Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?
A. Modify all active Log Forwarding profiles to select the "Cloud Logging" option in each profile match list in the appropriate device groups
B. Enable the "Panorama/Cloud Logging" option in the Logging and Reporting Settings section under Device -- > Setup --> Management in the appropriate templates
C. Select the "Enable Duplicate Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
D. Select the "Enable Cloud Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
عرض الإجابة
اجابة صحيحة: D
السؤال #21
A cloud security team wants to extend its existing Palo Alto Networks Security policies into the organization's Kubernetes environments. The team requires an NGFW solution that can be deployed natively as a container and managed by Panorama.Which firewall form factor meets these requirements?
A. Cloud NGFW
B. PA-5400 Series
C. VM-Series
D. CN-Series
عرض الإجابة
اجابة صحيحة: D
السؤال #22
Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
A. It acts as a logging service for NGFW performance metrics
B. It orchestrates real-time traffic inspection for network segments
C. It provides Infrastructure-as-Code (IaC) to automate NGFW deployment
D. It manages threat intelligence data synchronization with NGFWs
عرض الإجابة
اجابة صحيحة: C
السؤال #23
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
عرض الإجابة
اجابة صحيحة: D
السؤال #24
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish.Which of the following actions will resolve this issue?
A. Ensure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel interface
B. Configure the Proxy IDs to match the Cisco ASA configuration
C. Check that IPSec is enabled in the management profile on the external interface
D. Validate the tunnel interface VLAN against the peer's configuration
عرض الإجابة
اجابة صحيحة: B
السؤال #25
An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service.Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?
A. Modify all active Log Forwarding profiles to select the "Cloud Logging" option in each profile match list in the appropriate device groups
B. Enable the "Panorama/Cloud Logging" option in the Logging and Reporting Settings section under Device -- > Setup --> Management in the appropriate templates
C. Select the "Enable Duplicate Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
D. Select the "Enable Cloud Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
عرض الإجابة
اجابة صحيحة: D
السؤال #26
An organization has configured GlobalProtect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user logon.How does the GlobalProtect agent process the authentication flow on Windows endpoints?
A. The GlobalProtect agent uses the machine certificate to establish a pre-logon tunnel; upon user sign-in, it prompts for SAML-based MFA credentials, ensuring both device and user identities are validated before granting full access
B. The GlobalProtect agent uses the machine certificate during pre-logon for initial tunnel establishment, and then seamlessly reuses the same machine certificate for user-based authentication without requiring MFA
C. Once the machine certificate is validated at pre-logon, the Windows endpoint completes MFA on behalf of the user by passing existing Windows Credential Provider details to the GlobalProtect gateway without prompting the user
D. GlobalProtect requires the user to log in first for SAML-based MFA before establishing the pre-logon tunnel, rendering the pre-logon certificate authentication (CA) flow redundant
عرض الإجابة
اجابة صحيحة: A
السؤال #27
In a Palo Alto Networks environment, GlobalProtect has been enabled using certificate-based authentication for both users and devices. To ensure proper validation of certificates, one or more certificate profiles are configured.What function do certificate profiles serve in this context?
A. They store private keys for users and devices, effectively allowing the firewall to issue or reissue certificates if the primary Certificate Authority (CA) becomes unavailable, providing a built-in fallback CA to maintain continuous certificate issuance and authentication
B. They define trust anchors (root / intermediate Certificate Authorities (CAs)), specify revocation checks (CRL/OCSP), and map certificate attributes (e
C. They allow the firewall to bypass certificate validation entirely, focusing only on username / password-based authentication
D. They provide a one-click mechanism to distribute certificates to all endpoints without relying on external enrollment methods
عرض الإجابة
اجابة صحيحة: B
السؤال #28
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
A. Flood Protection
B. Protocol Protection
C. Packet-Based Attack Protection
D. Reconnaissance Protection
عرض الإجابة
اجابة صحيحة: B
السؤال #29
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers.Resources exist on AWS and Azure:The AWS deployment is architected with AWS Transit Gateway, to which all resources connectThe Azure deployment is architected with each application independently routing trafficThe engineer deploying Cloud NGFW in these two cloud environments must account for the following:Minimize changes to the two cloud environmentsScale to the demands of the applications while using the least amount of compute resourcesAllow the company to unify the Security policies across all protected areasWhich two implementations will meet these requirements? (Choose two.)
A. Deploy a VM-Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and Azure, and manage the policy with Panorama
B. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the deployed NGFWs, and manage the policy with Panorama
C. Deploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the Cloud NGFW attached to the vWAN, and manage the policy with local rules
D. Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route all appropriate traffic through the Security VPC, and manage the policy with Panorama
عرض الإجابة
اجابة صحيحة: BD
السؤال #30
An organization has configured GlobalProtect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user logon.How does the GlobalProtect agent process the authentication flow on Windows endpoints?
A. The GlobalProtect agent uses the machine certificate to establish a pre-logon tunnel; upon user sign-in, it prompts for SAML-based MFA credentials, ensuring both device and user identities are validated before granting full access
B. The GlobalProtect agent uses the machine certificate during pre-logon for initial tunnel establishment, and then seamlessly reuses the same machine certificate for user-based authentication without requiring MFA
C. Once the machine certificate is validated at pre-logon, the Windows endpoint completes MFA on behalf of the user by passing existing Windows Credential Provider details to the GlobalProtect gateway without prompting the user
D. GlobalProtect requires the user to log in first for SAML-based MFA before establishing the pre-logon tunnel, rendering the pre-logon certificate authentication (CA) flow redundant
عرض الإجابة
اجابة صحيحة: A
السؤال #31
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
A. It does not accept the configuration
B. It accepts the configuration but throws a warning message
C. It removes the static route because 0 is a NULL value
D. It reinstalls the route into the routing information base (RIB) as soon as the path comes up
عرض الإجابة
اجابة صحيحة: D
السؤال #32
Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?
A. Set Transmission Rate to "fast
B. Set passive link state to "Auto
C. Set "Enable in HA Passive State
D. Set LACP mode to "Active
عرض الإجابة
اجابة صحيحة: C
السؤال #33
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
A. Flood Protection
B. Protocol Protection
C. Packet-Based Attack Protection
D. Reconnaissance Protection
عرض الإجابة
اجابة صحيحة: B
السؤال #34
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
عرض الإجابة
اجابة صحيحة: D
السؤال #35
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third - party gateway? (Choose two.)
A. For incoming and outgoing traffic through the tunnel, creating separate rules for each direction is optional
B. The IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow policy
C. For incoming and outgoing traffic through the tunnel, separate rules must be created for each direction
D. The IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny policy
عرض الإجابة
اجابة صحيحة: CD
السؤال #36
An NGFW engineer is configuring multiple Layer 2 interfaces on a Palo Alto Networks firewall, and all interfaces must be assigned to the same VLAN. During initial testing, it is reported that clients located behind the various interfaces cannot communicate with each other.Which action taken by the engineer will resolve this issue?
A. Configure each interface to belong to the same Layer 2 zone and enable IP routing between them
B. Assign each interface to the appropriate Layer 2 zone and configure a policy that allows traffic within the VLAN
C. Assign each interface to the appropriate Layer 2 zone and configure Security policies for interfaces not assigned to the same zone
D. Enable IP routing between the interfaces and configure a Security policy to allow traffic between interfaces within the VLAN
عرض الإجابة
اجابة صحيحة: B
السؤال #37
An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy.Which approach ensures continuous, secure connectivity and consistent policy enforcement?
A. se a wildcard certificate from a public CA, disable all revocation checks to reduce latency, and manage certificate renewals manually on each firewall
B. eploy self-signed certificates on each firewall, allow IP-based authentication to override certificate checks, and use default GlobalProtect settings for user / machine identification
C. istribute root and intermediate CAs via Panorama template, use distinct certificate profiles for user versus machine certs, reference an internal OCSP responder, and automate certificate deployment with Group Policy
D. onfigure a single certificate profile for both user and machine certificates
عرض الإجابة
اجابة صحيحة: C
السؤال #38
Which type of firewall resource can be assigned when configuring a new firewall virtual system (VSYS)?
A. ecurity profile limit
B. essions limit
C. emory
D. PU
عرض الإجابة
اجابة صحيحة: B
السؤال #39
By default, which type of traffic is configured by service route configuration to use the management interface?
A. Security zone
B. IPSec tunnel
C. Virtual system (VSYS)
D. Autonomous Digital Experience Manager (ADEM)
عرض الإجابة
اجابة صحيحة: D
السؤال #40
An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The requirement is to route DNS queries for "https://www.google.com/search?q=corp.internal.com" to the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's locally configured DNS.What is the effect of configuring this split DNS policy?
A. It provides selective DNS resolution, with specified domains resolved through the tunnel, optimizing performance for other lookups
B. It blocks access to all domains that are not explicitly listed in the split tunnel configuration
C. It forces all applications to use the corporate DNS servers, regardless of the split tunnel settings for IP traffic
D. It creates a DNS proxy on the client endpoint that forwards all queries to the firewall for inspection
عرض الإجابة
اجابة صحيحة: A
السؤال #41
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
A. It does not accept the configuration
B. It accepts the configuration but throws a warning message
C. It removes the static route because 0 is a NULL value
D. It reinstalls the route into the routing information base (RIB) as soon as the path comes up
عرض الإجابة
اجابة صحيحة: D
السؤال #42
By default, which type of traffic is configured by service route configuration to use the management interface?
A. irtual system (VSYS)
B. PSec tunnel
C. utonomous Digital Experience Manager (ADEM)
D. ecurity zone
عرض الإجابة
اجابة صحيحة: C
السؤال #43
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
عرض الإجابة
اجابة صحيحة: D
السؤال #44
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish.Which of the following actions will resolve this issue?
A. Ensure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel interface
B. Configure the Proxy IDs to match the Cisco ASA configuration
C. Check that IPSec is enabled in the management profile on the external interface
D. Validate the tunnel interface VLAN against the peer's configuration
عرض الإجابة
اجابة صحيحة: B
السؤال #45
When creating a Log Forwarding profile on a PAN-OS firewall to direct logs to various external and internal systems, which set of methods is available?
A. Syslog, Panorama, SD-WAN
B. Panorama/Cloud logging, email, Syslog
C. Email, Syslog, NetFlow
D. HTTP, RADIUS, SNMP
عرض الإجابة
اجابة صحيحة: B
السؤال #46
Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
A. It acts as a logging service for NGFW performance metrics
B. It orchestrates real-time traffic inspection for network segments
C. It provides Infrastructure-as-Code (IaC) to automate NGFW deployment
D. It manages threat intelligence data synchronization with NGFWs
عرض الإجابة
اجابة صحيحة: C
السؤال #47
By default, which type of traffic is configured by service route configuration to use the management interface?
A. Security zone
B. IPSec tunnel
C. Virtual system (VSYS)
D. Autonomous Digital Experience Manager (ADEM)
عرض الإجابة
اجابة صحيحة: D
السؤال #48
What are the phases of the Palo Alto Networks AI Runtime Security: Network Intercept solution?
A. Scanning, Isolation, Whitelisting, Logging
B. Discovery, Deployment, Detection, Prevention
C. Policy Generation, Discovery, Enforcement, Logging
D. Profiling, Policy Generation, Enforcement, Reporting
عرض الإجابة
اجابة صحيحة: B
السؤال #49
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
A. Flood Protection
B. Protocol Protection
C. Packet-Based Attack Protection
D. Reconnaissance Protection
عرض الإجابة
اجابة صحيحة: B
السؤال #50
During an upgrade to the routing infrastructure in a customer environment, the network administrator wants to implement Advanced Routing Engine (ARE) on a Palo Alto Networks firewall.Which firewall models support this configuration?
A. PA-5280, PA-7080, PA-3250, VM-Series
B. PA-455, VM-Series, PA-1410, PA-5450
C. PA-3260, PA-5410, PA-850, PA-460
D. PA-7050, PA-1420, VM-Series, CN-Series
عرض الإجابة
اجابة صحيحة: A
السؤال #51
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)
A. or incoming and outgoing traffic through the tunnel, creating separate rules for each direction is optional
B. he IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow policy
C. or incoming and outgoing traffic through the tunnel, separate rules must be created for each direction
D. he IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny policy
عرض الإجابة
اجابة صحيحة: AB
السؤال #52
An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service.Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?
A. Modify all active Log Forwarding profiles to select the "Cloud Logging" option in each profile match list in the appropriate device groups
B. Enable the "Panorama/Cloud Logging" option in the Logging and Reporting Settings section under Device -- > Setup --> Management in the appropriate templates
C. Select the "Enable Duplicate Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
D. Select the "Enable Cloud Logging" option in the Cloud Logging section under Device --> Setup --> Management in the appropriate templates
عرض الإجابة
اجابة صحيحة: D
السؤال #53
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)
A. For incoming and outgoing traffic through the tunnel, creating separate rules for each direction is optional
B. The IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow policy
C. For incoming and outgoing traffic through the tunnel, separate rules must be created for each direction
D. The IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny policy
عرض الإجابة
اجابة صحيحة: CD

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us