Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator NetSec-Pro Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which GlobalProtect configuration is recommended for granular security enforcement of remote user device posture?

Options:

A.

Configuring host information profile (HIP) checks for all mobile users


B.

Configuring a rule that blocks the ability of users to disable GlobalProtect while accessing internal applications


C.

Implementing multi-factor authentication (MFA) for all users attempting to access internal applications


D.

Applying log at session end to all GlobalProtect Security policies


Expert Solution
Questions # 12:

Which action allows an engineer to collectively update VM-Series firewalls with Strata Cloud Manager (SCM)?

Options:

A.

Creating an update grouping rule


B.

Scheduling software update


C.

Creating a device grouping rule


D.

Setting a target OS version


Expert Solution
Questions # 13:

Which two types of logs must be forwarded to Strata Logging Service for IoT Security to function? (Choose two.)

Options:

A.

WildFire


B.

Enhanced application


C.

Threat


D.

URL Filtering


Expert Solution
Questions # 14:

What must be configured to successfully onboard a Prisma Access remote network using Strata Cloud Manager (SCM)?

Options:

A.

Cloud Identity Engine


B.

Autonomous Digital Experience Manager (ADEM)


C.

GlobalProtect agent


D.

IPSec termination node


Expert Solution
Questions # 15:

In a distributed enterprise implementing Prisma SD-WAN, which configuration element should be implemented first to ensure optimal traffic flow between remote sites and headquarters?

Options:

A.

Deploy redundant ION devices at each location.


B.

Implement dynamic path selection using real-time performance metrics.


C.

Configure static routes between all the branch offices.


D.

Enable split tunneling for all branch locations.


Expert Solution
Questions # 16:

Which two security services are required for configuration of NGFW Security policies to protect against malicious and misconfigured domains? (Choose two.)

Options:

A.

Advanced Threat Prevention


B.

SaaS Security


C.

Advanced WildFire


D.

Advanced DNS Security


Expert Solution
Questions # 17:

Which two features can a network administrator use to troubleshoot the issue of a Prisma Access mobile user who is unable to access SaaS applications? (Choose two.)

Options:

A.

SaaS Application Risk Portal


B.

Capacity Analyzer


C.

GlobalProtect logs


D.

Autonomous Digital Experience Manager (ADEM) console


Expert Solution
Questions # 18:

Where can you view the block logs when upload of a PE file is restricted?

Options:

A.

Traffic logs


B.

WildFire logs


C.

Data Filtering logs


D.

System logs


Expert Solution
Questions # 19:

Which two content updates can be pushed to next-generation firewalls from Panorama? (Choose two.)

Options:

A.

Advanced URL Filtering


B.

Applications and threats


C.

WildFire


D.

GlobalProtect data file


Expert Solution
Questions # 20:

An NGFW administrator is updating PAN-OS on company data center firewalls managed by Panorama. Prior to installing the update, what must the administrator verify to ensure the devices will continue to be supported by Panorama?

Options:

A.

Device telemetry is enabled.


B.

Panorama is configured as the primary device in the log collecting group for the data center firewalls.


C.

All devices are in the same template stack.


D.

Panorama is running the same or newer PAN-OS release as the one being installed.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions