Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator NGFW-Engineer Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

A company is enabling SSL Forward Proxy to inspect encrypted traffic. A security engineer generates a new certificate on the firewall and flags it with the "Forward Trust" certificate property.

What is the critical next step that must be performed for decryption to function correctly without causing security warnings for end users?

Options:

A.

Set the forward trust certificate as the SSL/TLS Service profile for the management interface.


B.

Create a Security policy rule that allows traffic from the certificate of the firewall to all the zones.


C.

Import the private key of the forward trust certificate onto the domain controller.


D.

Install the public portion of the forward trust certificate into the trust store of all client machines.


Expert Solution
Questions # 12:

When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?

Options:

A.

Flood Protection


B.

Protocol Protection


C.

Packet-Based Attack Protection


D.

Reconnaissance Protection


Expert Solution
Questions # 13:

A network security engineer at a 24/7 online retailer is upgrading an active/passive high availability (HA) cluster of PAN-OS firewalls. The primary goal is to perform the upgrade with no service interruption to online transactions. The engineer has already downloaded the new software to both devices.

Which sequence of actions will meet this requirement?

Options:

A.

From Panorama, create a scheduled software update job targeting both firewalls in the HA pair to run at the same time, then rely on the HA election process to manage the failover automatically.


B.

Upgrade the passive firewall first while it is still in the passive state. Once it reboots and is operational, suspend the active firewall to fail over to the newly upgraded device. Then, upgrade the remaining firewall.


C.

Force the active firewall into a suspended state to trigger a failover, then upgrade and reboot it. Suspend the currently active firewall to fail traffic back to the upgraded unit. Upgrade the remaining firewall.


D.

Disable HA synchronization on the active firewall, upgrade the passive firewall, and then re-enable synchronization. Once synchronized, repeat the process on the other firewall.


Expert Solution
Questions # 14:

An organization is migrating its data center to Amazon Web Services (AWS) and needs to deploy VM-Series firewalls to inspect all ingress and egress traffic. The solution must provide both resilience across multiple Availability Zones and the ability to scale horizontally.

Which combination of AWS services and Palo Alto Networks components is required for this use case?

Options:

A.

AWS Lambda function that monitors the firewall's health and re-routes traffic using the AWS API


B.

PAN-OS active/active high availability (HA) pair with an AWS Transit Gateway


C.

Amazon EC2 Auto Scaling group with VM-Series firewalls and an Amazon Gateway Load Balancer


D.

Single VM-Series firewall with an Elastic IP address that can be re-associated upon failure


Expert Solution
Questions # 15:

What is the correct sequence of evaluation for Security policy rulebases?

Options:

A.

Panorama Pre-Rules -- > Local Firewall Rules -- > Panorama Post-Rules


B.

Panorama Post-Rules -- > Panorama Pre-Rules -- > Local Firewall Rules


C.

Panorama Shared Rules -- > Local Firewall Rules -- > Device Group Rules


D.

Local Firewall Rules -- > Panorama Pre-Rules -- > Panorama Post-Rules


Expert Solution
Questions # 16:

Which type of firewall resource can be assigned when configuring a new firewall virtual system (VSYS)?

Options:

A.

CPU


B.

Sessions limit


C.

Memory


D.

Security profile limit


Expert Solution
Questions # 17:

An automation engineer is developing a Python script to standardize SD-WAN deployments across multiple customer tenants in Panorama. A key requirement is to programmatically create path quality profiles to monitor link performance based on latency, jitter, and packet loss.

Which API call is required for this task?

Options:

A.

XML API command with an xpath of config/devices/entry/vsys/entry/path-quality-profiles on Panorama


B.

XML API command with an xpath of sdwan/path-quality-profiles on a managed firewall


C.

POST request to the SDWanPathQualityProfiles object endpoint via the REST API on Panorama


D.

POST request to the pathMonitoringProfiles object endpoint via the REST API on a managed firewall


Expert Solution
Questions # 18:

A network engineer has configured a PAN-OS firewall for client certificate authentication. The firewall has the corporate root CA certificate loaded. Client certificates are issued by an intermediate certificate authority (CA), which is signed by the root CA. However, when users attempt to connect, the authentication fails, and system logs indicate an "invalid certificate" error.

What is the most likely cause of this authentication failure?

Options:

A.

Intermediate CA certificate has not been imported onto the firewall and added to the trust chain.


B.

Client certificates were generated with an insecure key length (e.g., 1024-bit RSA).


C.

Firewall clock is out of sync with the CA server by more than five minutes.


D.

Online Certificate Status Protocol (OCSP) responder is unreachable, and no certificate revocation list (CRL) fallback is configured.


Expert Solution
Questions # 19:

An engineer at a managed services provider is updating an application that allows its customers to request firewall changes to also manage SD-WAN. The application will be able to make any approved changes directly to devices via API.

What is a requirement for the application to create SD-WAN interfaces?

Options:

A.

REST API’s “sdwanInterfaceprofiles” parameter on a Panorama device


B.

REST API’s “sdwanInterfaces” parameter on a firewall device


C.

XML API’s “sdwanprofiles/interfaces” parameter on a Panorama device


D.

XML API’s “InterfaceProfiles/sdwan” parameter on a firewall device


Expert Solution
Questions # 20:

A Palo Alto Networks firewall has the following interfaces configured:

• ethernet1/1 (Layer 3)

• ethernet1/2 (TAP)

• ethernet1/3 (Layer 2)

• ethernet1/4 (virtual wire)

An administrator needs to create a link group to monitor upstream connectivity for high availability (HA) failover.

Which set of interfaces can be added to the link group?

Options:

A.

ethernet1/1, ethernet1/2, ethernet1/4


B.

ethernet1/1, ethernet1/2, ethernet1/3


C.

ethernet1/2, ethernet1/3, ethernet1/4


D.

ethernet1/1, ethernet1/3, ethernet1/4


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions