Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator NGFW-Engineer Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

An engineer is creating an automation workflow. The first step is to deploy a new VM-Series firewall into a VMware vSphere environment, including its virtual machine (VM) configuration and network interfaces. The second step is to connect to the firewall and configure a complex set of Security policies and objects. The team uses both Terraform and Ansible.

For which part of this workflow would Terraform typically be used?

Options:

A.

Pushing threat intelligence updates to the new firewall


B.

Deploying the VM and associated network interfaces


C.

Storing the credentials needed to access the vSphere environment


D.

Applying the detailed Security policies and objects


Expert Solution
Questions # 22:

Which configuration step is required when implementing a new self-signed root certificate authority (CA) certificate for SSL decryption on a Palo Alto Networks firewall?

Options:

A.

Import the new subordinate CA certificate into the trust stores of all client devices.


B.

Set the subordinate CA certificate as the default routing certificate for all network traffic.


C.

Configure the subordinate CA to issue certificates with indefinite validity periods.


D.

Disable all existing SSL decryption rules until the new certificate is fully propagated.


Expert Solution
Questions # 23:

A network administrator is configuring an Aggregate Ethernet (AE) interface on an active/passive high availability (HA) pair. To reduce network downtime during a failover, the administrator wants the passive firewall's AE interface to be fully negotiated with the switch before it becomes active.

Which Link Aggregation Control Protocol (LACP) setting achieves this administrator's goal?

Options:

A.

LACP Mode active


B.

Enable in HA passive state


C.

System Priority: 1


D.

Transmission Rate: fast


Expert Solution
Questions # 24:

What must be configured before a firewall administrator can define policy rules based on users and groups?

Options:

A.

User Mapping profile


B.

Authentication profile


C.

Group mapping settings


D.

LDAP Server profile


Expert Solution
Questions # 25:

During an upgrade to the routing infrastructure in a customer environment, the network administrator wants to implement Advanced Routing Engine (ARE) on a Palo Alto Networks firewall.

Which firewall models support this configuration?

Options:

A.

PA-5280, PA-7080, PA-3250, VM-Series


B.

PA-455, VM-Series, PA-1410, PA-5450


C.

PA-3260, PA-5410, PA-850, PA-460


D.

PA-7050, PA-1420, VM-Series, CN-Series


Expert Solution
Questions # 26:

When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?

Options:

A.

Service graph


B.

Ansible automation modules


C.

Panorama role-based access control (RBAC)


D.

CN-Series firewalls


Expert Solution
Questions # 27:

Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?

Options:

A.

When a policy match is found in a local firewall policy, if any Panorama shared post-rule is configured, it will still be evaluated.


B.

Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules.


C.

Panorama post-rules can be configured to be evaluated before local firewall policy for the purpose of troubleshooting.


D.

The order of policy evaluation can be configured differently in different device groups.


Expert Solution
Questions # 28:

A network engineer observes that after a primary link recovers, the firewall immediately switches traffic back from the backup static route to the primary static route. The engineer checks the path monitoring configuration for the primary route.

Which value is configured for the preemptive hold time to cause this behavior?

Options:

A.

Lowest possible value greater than 0


B.

0


C.

Default value


D.

Feature disabled


Expert Solution
Questions # 29:

Which two actions in the IKE Gateways will allow implementation of post-quantum cryptography when building VPNs between multiple Palo Alto Networks NGFWs? (Choose two.)

Options:

A.

Select IKE v2, enable the Advanced Options PQ PPK, then set a 64+ character string for the post-quantum pre shared key.


B.

Ensure Authentication is set to “certificate,” then import a post-quantum derived certificate.


C.

Select IKE v2 Preferred, enable the Advanced Options PQ KEM, then add one or more “Rounds.”


D.

Select IKE v2, enable the Advanced Options PQ KEM, then create an IKE Crypto Profile with Advanced Options adding one

or more “Rounds.”


Expert Solution
Questions # 30:

An administrator configures a GlobalProtect gateway with split tunneling for network traffic based on an access route. Users report that public web browsing works, but they cannot resolve the names of internal servers. The administrator determines that all DNS queries are being sent to the public DNS servers configured on the users' endpoints.

Which GlobalProtect portal setting should be configured to resolve this issue?

Options:

A.

Split tunneling for DNS and specify the internal corporate domains in the "Domain" list


B.

DNS Proxy feature on the firewall to point clients to the gateway IP for DNS


C.

"DNS Forwarding" option on the gateway's tunnel interface


D.

NAT rule to allow DNS traffic from the GlobalProtect clients to the internal DNS servers


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions