EXAM Flashcards
What is the LAST step of packet processing in the firewall?
checking Security Profiles
Which interface type requires you to configure where the next hop is for various addresses?
Layer 3
How do you enable the firewall to be managed through a data-plane interface?
You specify HTTPS in the Interface Management Profile, and then specify in the interface properties to use that profile
Some devices managed by Panorama have their external interface on ethernet1/1, some on ethernet1/2. However, the zone definitions for the external zone are identical. What is the recommended solution in this case?
Create two templates: one for the ethernet1/1 devices, one for the ethernet1/2 devices. Use the same external zone definitions in both. Apply those two templates to the appropriate devices.
In a Panorama managed environment, which two options show the correct order of policy evaluation? (Choose two.)
- ) device group pre-rules, local firewall rules, device group post-rules,shared post-rules, intrazone-default, interzone-default
- ). shared pre-rules, device group pre-rules, local firewall rules, intrazone-default, interzone-default
When you deploy the Palo Alto Networks NGFW on NSX, how many virtual network interfaces does a VM-Series firewall need?
. three, one for traffic input, one for traffic output, and one for management traffic
Which source of user information is NOT supported by the NGFW?
RACF
What is the main mechanism of packet-based vulnerability attacks?
malformed packets that trigger software bugs when they are received
Which method is not a PAN-OS software decryption method?
SSL Proxy
What type of identification does an Application Override policy override?
App-ID
Which two types of protocols can cause an insufficient data value in the Application field in the Traffic log? (Choose two.)
UDP & TCP
Which three profile types are used to prevent malware executables from entering the network?
Anti-virus
WildFire Analysis
File Blocking
Which user credential detection method does not require access to an external directory?
Certificate
When destination NAT rules are configured, the associated security rule is matched using which parameters?
pre-NAT source zone and post-NAT destination zone
What is the initial IP address for the management interface?
192.168.1.1
In a new firewall, which port provides web interface access by default?
management port
Which application requires you to import private keys?
SSL Inbound Inspection
Under which conditions can two Layer 3 interfaces have the same IP address?
This feature is not supported.
Which two protocols are supported for site-to-site VPNs? (Choose two.)
(AH) - Authentication Header
(ESP) - Encapsulating Security Payload