Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator NGFW-Engineer Questions and answers with CertsForce

Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
Questions # 31:

Without performing a context switch, which set of operations can be performed that will affect the operation of a connected firewall on the Panorama GUI?

Options:

A.

Restarting the local firewall, running a packet capture, accessing the firewall CLI


B.

Modification of local security rules, modification of a Layer 3 interface, modification of the firewall device hostname


C.

Modification of pre-security rules, modification of a virtual router, modification of an IKE Gateway Network Profile


D.

Modification of post NAT rules, creation of new views on the local firewall ACC tab, creation of local custom reports


Expert Solution
Questions # 32:

Which initial action is required to configure logical routers?

Options:

A.

Changing the virtual router type from "default" to "advanced"


B.

Activating an advanced routing subscription


C.

Committing a new advanced routing software module


D.

Checking "advanced routing" in general settings


Expert Solution
Questions # 33:

Which PAN-OS method of mapping users to IP addresses is the most reliable?

Options:

A.

Port mapping


B.

GlobalProtect


C.

Syslog


D.

Server monitoring


Expert Solution
Questions # 34:

After a recent high availability (HA) failover test on an active/passive cluster, an engineer noted a 30-45 second delay before traffic started flowing through a Link Aggregation Control Protocol (LACP) aggregate interface on the newly active firewall.

What should have been configured to support LACP pre-negotiation to minimize LACP convergence delay?

Options:

A.

Enable LACP fast failover.


B.

Set LACP mode to passive.


C.

Enable in HA passive state.


D.

Set HA link monitoring to aggressive.


Expert Solution
Questions # 35:

An administrator is configuring dynamic updates on a Palo Alto Networks firewall that protects a hospital's patient record system. The primary concern is ensuring maximum stability and avoiding any service disruption from a potentially problematic content update.

To align with Palo Alto Networks best practices for such environments, which threshold should the administrator set for content updates?

Options:

A.

0 hours


B.

12 hours


C.

24 hours


D.

48 hours


Expert Solution
Questions # 36:

An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The requirement is to route DNS queries for "https://www.google.com/search?q=corp.internal.com" to the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's locally configured DNS.

What is the effect of configuring this split DNS policy?

Options:

A.

It provides selective DNS resolution, with specified domains resolved through the tunnel, optimizing performance for other lookups.


B.

It blocks access to all domains that are not explicitly listed in the split tunnel configuration.


C.

It forces all applications to use the corporate DNS servers, regardless of the split tunnel settings for IP traffic.


D.

It creates a DNS proxy on the client endpoint that forwards all queries to the firewall for inspection.


Expert Solution
Questions # 37:

Which feature can be enabled on a Layer 3 interface but is not available on Layer 2 interfaces?

Options:

A.

NetFlow profile


B.

LLDP profile


C.

QoS profile


D.

DHCP client


Expert Solution
Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions