Pass the Paloalto Networks Network Security Administrator NGFW-Engineer Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which CLI command is used to configure the management interface as a DHCP client?

Options:

A.

set network dhcp interface management


B.

set network dhcp type management-interface


C.

set deviceconfig system type dhcp-client


D.

set deviceconfig management type dhcp-client


Questions # 2:

Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)

Options:

A.

For incoming and outgoing traffic through the tunnel, creating separate rules for each direction is optional.


B.

The IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow policy.


C.

For incoming and outgoing traffic through the tunnel, separate rules must be created for each direction.


D.

The IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny policy.


Questions # 3:

By default, which type of traffic is configured by service route configuration to use the management interface?

Options:

A.

Security zone


B.

IPSec tunnel


C.

Virtual system (VSYS)


D.

Autonomous Digital Experience Manager (ADEM)


Questions # 4:

What are the phases of the Palo Alto Networks AI Runtime Security: Network Intercept solution?

Options:

A.

Scanning, Isolation, Whitelisting, Logging


B.

Discovery, Deployment, Detection, Prevention


C.

Policy Generation, Discovery, Enforcement, Logging


D.

Profiling, Policy Generation, Enforcement, Reporting


Questions # 5:

Which interface types should be used to configure link monitoring for a high availability (HA) deployment on a Palo Alto Networks NGFW?

Options:

A.

HA, Virtual Wire, and Layer 2


B.

Tap, Virtual Wire, and Layer 3


C.

Virtual Wire, Layer 2, and Layer 3


D.

HA, Layer 2. and Layer 3


Questions # 6:

Which two actions in the IKE Gateways will allow implementation of post-quantum cryptography when building VPNs between multiple Palo Alto Networks NGFWs? (Choose two.)

Options:

A.

Select IKE v2, enable the Advanced Options • PQ PPK, then set a 64+ character string for the post-quantum pre shared key.


B.

Ensure Authentication is set to “certificate,” then import a post-quantum derived certificate.


C.

Select IKE v2 Preferred, enable the Advanced Options • PQ KEM, then add one or more “Rounds.”


D.

Select IKE v2, enable the Advanced Options • PQ KEM, then create an IKE Crypto Profile with Advanced Options adding one or more “Rounds.”


Questions # 7:

In a Palo Alto Networks environment, GlobalProtect has been enabled using certificate-based authentication for both users and devices. To ensure proper validation of certificates, one or more certificate profiles are configured.

What function do certificate profiles serve in this context?

Options:

A.

They store private keys for users and devices, effectively allowing the firewall to issue or reissue certificates if the primary Certificate Authority (CA) becomes unavailable, providing a built-in fallback CA to maintain continuous certificate issuance and authentication.


B.

They define trust anchors (root / intermediate Certificate Authorities (CAs)), specify revocation checks (CRL/OCSP), and map certificate attributes (e.g., CN) for user or device authentication.


C.

They allow the firewall to bypass certificate validation entirely, focusing only on username / password-based authentication.


D.

They provide a one-click mechanism to distribute certificates to all endpoints without relying on external enrollment methods.


Questions # 8:

An NGFW engineer is configuring multiple Layer 2 interfaces on a Palo Alto Networks firewall, and all interfaces must be assigned to the same VLAN. During initial testing, it is reported that clients located behind the various interfaces cannot communicate with each other.

Which action taken by the engineer will resolve this issue?

Options:

A.

Configure each interface to belong to the same Layer 2 zone and enable IP routing between them.


B.

Assign each interface to the appropriate Layer 2 zone and configure a policy that allows traffic within the VLAN.


C.

Assign each interface to the appropriate Layer 2 zone and configure Security policies for interfaces not assigned to the same zone.


D.

Enable IP routing between the interfaces and configure a Security policy to allow traffic between interfaces within the VLAN.


Questions # 9:

An administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized.

What is the recommended upgrade process for minimal disruption in this high availability (HA) scenario?

Options:

A.

Suspend the active firewall to trigger a failover to the passive firewall. With traffic now running on the former passive unit, upgrade the suspended (now passive) firewall and confirm proper operation. Then fail traffic back and upgrade the remaining firewall.


B.

Shut down the currently active firewall and upgrade it offline, allowing the passive firewall to handle all traffic. Once the active firewall finishes upgrading, bring it back online and rejoin the HA cluster. Finally, upgrade the passive firewall while the newly upgraded unit remains active.


C.

Isolate both firewalls from the production environment and upgrade them in a separate, offline setup. Reconnect them only after validating the new software version, resuming HA functionality once both units are fully upgraded and tested.


D.

Push the new PAN-OS version simultaneously to both firewalls, having them upgrade and reboot in parallel. Rely on automated HA reconvergence to restore normal operations without manually failing over traffic.


Questions # 10:

Which PAN-OS method of mapping users to IP addresses is the most reliable?

Options:

A.

Port mapping


B.

GlobalProtect


C.

Syslog


D.

Server monitoring


Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions