Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Network Security Administrator NGFW-Engineer Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An organization has configured GlobalProtect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user logon.

How does the GlobalProtect agent process the authentication flow on Windows endpoints?

Options:

A.

The GlobalProtect agent uses the machine certificate to establish a pre-logon tunnel; upon user sign-in, it prompts for SAML-based MFA credentials, ensuring both device and user identities are validated before granting full access.


B.

The GlobalProtect agent uses the machine certificate during pre-logon for initial tunnel establishment, and then seamlessly reuses the same machine certificate for user-based authentication without requiring MFA.


C.

Once the machine certificate is validated at pre-logon, the Windows endpoint completes MFA on behalf of the user by passing existing Windows Credential Provider details to the GlobalProtect gateway without prompting the user.


D.

GlobalProtect requires the user to log in first for SAML-based MFA before establishing the pre-logon tunnel, rendering the pre-logon certificate authentication (CA) flow redundant.


Expert Solution
Questions # 2:

By default, which type of traffic is configured by service route configuration to use the management interface?

Options:

A.

Security zone


B.

IPSec tunnel


C.

Virtual system (VSYS)


D.

Autonomous Digital Experience Manager (ADEM)


Expert Solution
Questions # 3:

For which two purposes is an IP address configured on a tunnel interface? (Choose two.)

Options:

A.

Use of dynamic routing protocols


B.

Tunnel monitoring


C.

Use of peer IP


D.

Redistribution of User-ID


Expert Solution
Questions # 4:

When deploying Palo Alto Networks NGFWs in a cloud service provider (CSP) environment, which method ensures high availability (HA) across multiple availability zones?

Options:

A.

Deploying Ansible scripts for zone-specific scaling


B.

Implementing Terraform templates for redundancy within one availability zone


C.

Using load balancer and health probes


D.

Configuring active/active HA


Expert Solution
Questions # 5:

To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers. Resources exist on AWS and Azure:

The AWS deployment is architected with AWS Transit Gateway, to which all resources connect

The Azure deployment is architected with each application independently routing traffic

The engineer deploying Cloud NGFW in these two cloud environments must account for the following:

Minimize changes to the two cloud environments

Scale to the demands of the applications while using the least amount of compute resources

Allow the company to unify the Security policies across all protected areas

Which two implementations will meet these requirements? (Choose two.)

Options:

A.

Deploy a VM-Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and Azure, and manage the policy with Panorama.


B.

Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the deployed NGFWs, and manage the policy with Panorama.


C.

Deploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the Cloud NGFW attached to the vWAN, and manage the policy with local rules.


D.

Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route all appropriate traffic through the Security VPC, and manage the policy with Panorama.


Expert Solution
Questions # 6:

When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?

Options:

A.

Service graph


B.

Ansible automation modules


C.

Panorama role-based access control


D.

CN-Series firewalls


Expert Solution
Questions # 7:

What is the purpose of assigning an Admin Role Profile to a user in a Palo Alto Networks NGFW?

Options:

A.

Allow access to all resources without restrictions.


B.

Enable multi-factor authentication (MFA) for administrator access.


C.

Define granular permissions for management tasks.


D.

Restrict access to sensitive report data.


Expert Solution
Questions # 8:

Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?

Options:

A.

When a policy match is found in a local firewall policy, if any Panorama shared post-rule is configured, it will still be evaluated.


B.

Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules.


C.

Panorama post-rules can be configured to be evaluated before local firewall policy for the purpose of troubleshooting.


D.

The order of policy evaluation can be configured differently in different device groups.


Expert Solution
Questions # 9:

Which interface types should be used to configure link monitoring for a high availability (HA) deployment on a Palo Alto Networks NGFW?

Options:

A.

HA, Virtual Wire, and Layer 2


B.

Tap, Virtual Wire, and Layer 3


C.

Virtual Wire, Layer 2, and Layer 3


D.

HA, Layer 2. and Layer 3


Expert Solution
Questions # 10:

What are the phases of the Palo Alto Networks AI Runtime Security: Network Intercept solution?

Options:

A.

Scanning, Isolation, Whitelisting, Logging


B.

Discovery, Deployment, Detection, Prevention


C.

Policy Generation, Discovery, Enforcement, Logging


D.

Profiling, Policy Generation, Enforcement, Reporting


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions