Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

According to dynamic updates best practices, what is the recommended threshold value for content updates in a mission- critical network?

A.

8 hours

B.

16 hours

C.

32 hours

D.

48 hours

Which PAN-OS method of mapping users to IP addresses is the most reliable?

A.

Port mapping

B.

GlobalProtect

C.

Syslog

D.

Server monitoring

Which type of firewall resource can be assigned when configuring a new firewall virtual system (VSYS)?

A.

CPU

B.

Sessions limit

C.

Memory

D.

Security profile limit

How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?

A.

It does not accept the configuration.

B.

It accepts the configuration but throws a warning message.

C.

It removes the static route because 0 is a NULL value.

D.

It reinstalls the route into the routing information base (RIB) as soon as the path comes up.

Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?

A.

When a policy match is found in a local firewall policy, if any Panorama shared post-rule is configured, it will still be evaluated.

B.

Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules.

C.

Panorama post-rules can be configured to be evaluated before local firewall policy for the purpose of troubleshooting.

D.

The order of policy evaluation can be configured differently in different device groups.

Palo Alto Networks NGFWs use SSL/TLS profiles to secure which two types of connections? (Choose two.)

A.

NAT tables

B.

User Authentication

C.

GlobalProtect Gateways

D.

GlobalProtect Portal

What is the primary use case for the CN-Series NGFW?

A.

Protecting mobile users and remote branch offices (east-west)

B.

Providing security for physical data center perimeters (north-south)

C.

Securing traffic in and out of a public cloud VPC or VNet (north-south)

D.

Enforcing Security policies between pods in a Kubernetes environment (east-west)

An organization is migrating its GlobalProtect user authentication from an existing LDAP directory to a new Kerberos server. To ensure a smooth transition, the network security team needs to allow users from both directories to authenticate for a period of 90 days. The firewall should first attempt authentication against the new Kerberos server and then fall back to the legacy LDAP server if the initial attempt fails.

Which two configurations are required to implement this authentication fallback strategy? (Choose two.)

A.

Configure a new RADIUS proxy on the firewall to handle authentication requests for both Kerberos and LDAP.

B.

Implement a User-ID Group Mapping policy to link users between the LDAP and Kerberos directories.

C.

Configure an authentication sequence that lists the Kerberos authentication profile first, followed by the LDAP authentication profile.

D.

Configure a new authentication profile that references the Kerberos server profile.

An engineer is creating an automation workflow. The first step is to deploy a new VM-Series firewall into a VMware vSphere environment, including its virtual machine (VM) configuration and network interfaces. The second step is to connect to the firewall and configure a complex set of Security policies and objects. The team uses both Terraform and Ansible.

For which part of this workflow would Terraform typically be used?

A.

Pushing threat intelligence updates to the new firewall

B.

Deploying the VM and associated network interfaces

C.

Storing the credentials needed to access the vSphere environment

D.

Applying the detailed Security policies and objects

When multiple routes have the same destination prefix, which attribute does the firewall use first to determine route preference?

A.

Administrative distance

B.

Route metric

C.

Next-hop availability

D.

Longest prefix match