Exam Domain 1 - Plan Flashcards
1. Which component of the integrated Palo Alto Networks security solution limits network attached workstation access to a corporate mainframe? A. threat intelligence cloud B. advanced endpoint protection C. next-generation firewall D. tunnel inspection
C. next-generation firewall
2. Which Palo Alto Networks product is designed primarily to provide threat context with deeper information about attacks? A. Prisma Cloud B. WildFire C. AutoFocus D. Threat Prevention
C. AutoFocus
- Which Palo Alto Networks product is designed primarily to provide normalization of threat
intelligence feeds with the potential for automated response?
A. MineMeld
B. WildFire
C. AutoFocus
D. Threat Prevention
A. MineMeld
4. Which Palo Alto Networks product is designed primarily to prevent endpoints from successfully running malware programs? A. GlobalProtect B. Cortex XDR – Analytics C. Cortex XDR D. Prisma Cloud
C. Cortex XDR
5. The Palo Alto Networks Cortex Data Lake can accept logging data from which two products? (Choose two.) A. Cortex XDR B. next-generation firewalls C. Prisma SaaS D. MineMeld E. AutoFocus
A. Cortex XDR
B. next-generation firewalls
6. Which Palo Alto Networks product is a cloud-based storage service designed to hold log information? A. Prisma Cloud B. Cortex XDR C. next-generation firewall D. Cortex Data Lake
D. Cortex Data Lake
7. Which product is an example of an application designed to analyze Cortex Data Lake information? A. Cortex XDR – Analytics B. Prisma Cloud C. Cortex XDR – Automated Response D. AutoFocus
A. Cortex XDR – Analytics
8. A potential customer says it wants to maximize the threat detection capability of its next generation firewall. Which three additional services should it consider implementing to enhance its firewall’s capability to detect threats? (Choose three.) A. Cortex XDR B. WildFire C. URL Filtering D. Expedition E. DNS Security
B. WildFire
C. URL Filtering
E. DNS Security
- A VM-Series virtual firewall differs from a physical Palo Alto Networks firewall in which way?
A. A VM-Series firewall cannot be managed by Panorama.
B. A VM-Series firewall supports fewer traffic interface types.
C. A VM-Series firewall cannot terminate VPN site-to-site tunnels.
D. A VM-Series firewall cannot use dynamic routing protocols.
B. A VM-Series firewall supports fewer traffic interface types.
10. Which product would best secure east-west traffic within a public cloud implementation? A. Prisma Cloud B. MineMeld C. VM-Series firewall D. Cortex
C. VM-Series firewall
- Why would you recommend an active/active firewall pair instead of an active/passive firewall pair?
A. Active/active is the preferred solution when the firewall pair is behind a load balancer that randomizes routing, thus requiring both firewalls to be active.
B. Active/active usually is the preferred solution because it allows for more bandwidth while both firewalls are up.
C. Active/active is the preferred solution when the PA-7000 Series is used. Use active/passive with the PA-5200 Series or smaller form factors.
D. Active/active is the preferred solution when the PA-5200 Series or smaller form factors are used. Use active/passive with the PA-7000 Series.
A. Active/active is the preferred solution when the firewall pair is behind a load balancer that randomizes routing, thus requiring both firewalls to be active.
- Which two events can trigger an HA pair failover event? (Choose two.)
A. An HA1 cable is disconnected from one of the firewalls.
B. A dynamic update fails to download and install.
C. The firewall fails to ping a path-monitored destination address successfully.
D. OSPF implemented on the firewall determines that an available route is now down.
E. RIP implemented on the firewall determines that an available route is now down.
A. An HA1 cable is disconnected from one of the firewalls.
C. The firewall fails to ping a path-monitored destination address successfully.
13. Which two firewall features support floating IP addresses in an active/active HA pair? (Choose two.) A. data-plane traffic interfaces B. source NAT C. VPN endpoints D. loopback interfaces E. management port
B. source NAT
C. VPN endpoints
- How are firewalls configurations in an active/passive HA pair synchronized if the firewalls are not under Panorama control?
A. An administrator commits the changes to one, then commits them to the partner, at which time the changes are sent to the other.
B. An administrator pushes the configuration file to both firewalls, then commits them.
C. An administrator commits changes to one, which automatically synchronizes with the other.
D. An administrator schedules an automatic sync frequency in the firewall configurations.
C. An administrator commits changes to one, which automatically synchronizes with the
other.
- In which two ways is an active/passive HA pair configured in virtual firewalls deployed in any public clouds? (Choose two.)
A. The virtual firewalls are deployed in a cloud “scale set” with a cloud-supplied load
balancer in front to detect and manage failover.
B. The virtual firewalls rely on a VM-Series plugin to map appropriate cloud functions to the firewall’s HA settings.
C. Virtual firewalls use PAN-OS HA configuration combined with appropriate cloud deployments of interfaces for HA use.
D. The virtual firewalls use an HA Compatibility module for the appropriate cloud technology
A. The virtual firewalls are deployed in a cloud “scale set” with a cloud-supplied load
balancer in front to detect and manage failover.
B. The virtual firewalls rely on a VM-Series plugin to map appropriate cloud functions to
the firewall’s HA settings.
16. Without having to make network address configuration changes, you would use which type of network interface to insert a Palo Alto Networks firewall in front of a legacy port-based firewall to collect application information from incoming network traffic? A. VLAN B. tunnel C. tap D. virtual wire E. Layer 2 F. Layer 3
D. virtual wire
17. Which type of interface do you use to connect Layer 2 and Layer 3 interfaces? A. VLAN B. tunnel C. tap D. virtual wire E. Layer 2 F. Layer 3
A. VLAN
18. Which three types of interfaces can the firewall’s management web interface be bound to? (Choose three.) A. VLAN B. tunnel C. tap D. virtual wire E. Layer 2 F. Layer 3
A. VLAN
B. tunnel
F. Layer 3
19. Which three types of interfaces connect to a virtual router? (Choose three.) A. VLAN B. tunnel C. tap D. virtual wire E. Layer 2 F. Layer 3
A. VLAN
B. tunnel
F. Layer 3
20. Which dynamic routing protocol is not supported by the Palo Alto Networks firewall? A. RIP B. OSPF C. OSPFv3 D. IGRP E. BGP
D. IGRP
- Which action is not compatible with aggregate interface configuration?
A. aggregating 18 Layer 3 interfaces
B. aggregating four virtual wire interfaces
C. aggregating interfaces in an HA pair
D. aggregating two 10Gbps optical and two 10Gbps copper Ethernet ports
A. aggregating 18 Layer 3 interfaces
- In a Panorama environment, how do you create and view enterprise-wide reports that include data from all managed firewalls?
A. Run Panorama reports normally. Firewall summary reporting information is gathered
automatically once the firewalls are managed by Panorama.
B. Configure log forwarding on the managed firewalls to forward logs to Panorama using
syslog formatting.
C. Run custom Panorama reports and select remote logs as the information source.
D. Run custom Panorama reports and select log collector as the information source.
A. Run Panorama reports normally. Firewall summary reporting information is gathered automatically once the firewalls are managed by Panorama.
- What must you configure to guarantee duplication of log data on Log Collectors?
A. Log Collector settings to include “Replicate Data”
B. Panorama HA settings to include “Duplicate Logs”
C. Log Collector settings to include “Enable log redundancy”
D. log forwarding settings of firewalls for two Log Collector destinations
C. Log Collector settings to include “Enable log redundancy”
24. Which three devices can be used as Log Collectors? (Choose three.) A. Virtual Panorama B. PA-220R C. M-600 D. M-200 E. VM-300LC
A. Virtual Panorama
C. M-600
D. M-200
- Which statement is true regarding Log Collecting in a Panorama HA pair?
A. Both Panoramas cannot be configured to collect logs.
B. Log collecting is handled by the active HA Panorama until a failover occurs.
C. Both Panoramas collect independent logging traffic and are not affected by failover.
D. Both Panoramas receive the same logging traffic and synchronize in case of HA failover.
C. Both Panoramas collect independent logging traffic and are not affected by failover.
- How are log retention periods on Palo Alto Networks firewalls increased?
A. add storage to any firewall model
B. increase the allocation for overall log storage within the firewall
C. turn on log compression
D. forward logs to external Log Collectors
D. forward logs to external Log Collectors