Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An internal host wants to connect to servers of the internet through using source NAT.

Which policy is required to enable source NAT on the firewall?

A.

NAT policy with source zone and destination zone specified

B.

post-NAT policy with external source and any destination address

C.

NAT policy with no source of destination zone selected

D.

pre-NAT policy with external source and any destination address

When creating a custom URL category object, which is a valid type?

A.

domain match

B.

host names

C.

wildcard

D.

category match

An administrator is configuring a NAT rule

At a minimum, which three forms of information are required? (Choose three.)

A.

name

B.

source zone

C.

destination interface

D.

destination address

E.

destination zone

Which statement is true regarding NAT rules?

A.

Static NAT rules have precedence over other forms of NAT.

B.

Translation of the IP address and port occurs before security processing.

C.

NAT rules are processed in order from top to bottom.

D.

Firewall supports NAT on Layer 3 interfaces only.

Based on the security policy rules shown, ssh will be allowed on which port?

A.

any port

B.

same port as ssl and snmpv3

C.

the default port

D.

only ephemeral ports

Place the steps in the correct packet-processing order of operations.

A network has 10 domain controllers, multiple WAN links, and a network infrastructure with bandwidth needed to support mission-critical applications. Given the scenario, which type of User-ID agent is considered a best practice by Palo Alto Networks?

A.

Windows-based agent on a domain controller

B.

Captive Portal

C.

Citrix terminal server with adequate data-plane resources

D.

PAN-OS integrated agent

An administrator wants to prevent access to media content websites that are risky

Which two URL categories should be combined in a custom URL category to accomplish this goal? (Choose two)

A.

streaming-media

B.

high-risk

C.

recreation-and-hobbies

D.

known-risk

Starting with PAN_OS version 9.1 which new type of object is supported for use within the user field of a security policy rule?

A.

local username

B.

dynamic user group

C.

remote username

D.

static user group

An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address. What is the most appropriate NAT policy to achieve this?

A.

Dynamic IP and Port

B.

Dynamic IP

C.

Static IP

D.

Destination