Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

A customer with multiple virtual private clouds (VPCs) in Amazon Web Services (AWS) protected by the cloud-native firewall experiences a cloud breach. As a result, malware spreads quickly across the VPCs, infecting several workloads.

Which minimum solution should be proposed to prevent similar incidents in the future?

A.

Purchase a software credit pool for flexible Cloud NGFW deployment across the VPCs.

B.

Deploy a single Cloud NGFW.

C.

Subscribe to Palo Alto Networks Advanced Threat Protection for the cloud-native firewall.

D.

Implement a Cloud NGFW for each VPC.

CN-Series firewalls offer threat protection for which three use cases? (Choose three.)

A.

Prevention of sensitive data exfiltration from Kubernetes environments

B.

All Kubernetes workloads in the public and private cloud

C.

Inbound, outbound, and east-west traffic between containers

D.

All workloads deployed on-premises or in the public cloud

E.

Enforcement of segmentation policies that prevent lateral movement of threats

Which two public cloud service provider (CSP) environments offer, through their marketplace, a Cloud NGFW under the CSP's own brand name? (Choose two.)

A.

Oracle Cloud Infrastructure (OCI)

B.

IBM Cloud (previously Softlayer)

C.

Alibaba Cloud

D.

Google Cloud Platform (GCP)

Which two products can be deployed using Terraform for automation and integration? (Choose two.)

A.

PA-Series firewall

B.

VM-Series firewall

C.

CN-Series firewall

D.

Cloud NGFW

What three benefits does flex licensing for VM-Series firewalls offer? (Choose three.)

A.

Licensing additional memory resources to increase session capacity

B.

Licensing Strata Cloud Manager, Panorama with Dedicated Log Collectors, and CDSS per deployment profile

C.

Using a pool of credits for both CN-Series firewall and VM-Series firewall deployment profiles

D.

Moving credits between public and private cloud VM-Series firewall deployments

E.

Vertically scaling the number of licensed cores in an existing fixed deployment profile

A partner has successfully showcased and validated the efficacy of the Palo Alto Networks software firewall to a customer.

Which two additional partner-delivered or Palo Alto Networks-delivered common options can the sales team offer to the customer before the sale is completed? (Choose two.)

A.

Hardware collection and recycling services by Palo Alto Networks or by an approved NextWave Partner for the customer’s existing firewall infrastructure

B.

Professional services delivered by Palo Alto Networks or by an approved Certified Professional Services Partner (CPSP) for deployment assistance or QuickStart

C.

Network encryption services (NES) delivered by an approved NES partner to ensure none of the data traversed is readable by third-party entities

D.

Managed services delivered by an approved Managed Security Services Program (MSSP) partner for day-to-day management of the environment

A prospective customer wants to deploy VM-Series firewalls in their on-premises data center, CN-Series firewalls in Azure, and Cloud NGFWs in Amazon Web Services (AWS). They also require centralized management.

Which solution meets the requirements?

A.

NGFW Software credits and Strata Cloud Manager (SCM)

B.

Fixed VM-Series firewalls, Cloud NGFW credits, and Panorama

C.

NGFW Software credits, Cloud NGFW, and Strata Cloud Manager (SCM)

D.

NGFW Software credits and Panorama

What is a benefit of credit-based flexible licensing for software firewalls?

A.

Permanently setting the capabilities of the software firewalls

B.

Adding Cloud-Delivered Security Services (CDSS) to CN-Series firewalls

C.

Adding subscriptions to PA-Series firewalls

D.

Creating Cloud NGFWs

When using VM-Series firewall bootstrapping, which three methods can be used to install licensed content, including antivirus, applications, and threats? (Choose three.)

A.

Panorama 10.2 or later to use the content auto push feature

B.

Complete bootstrapping and either Azure Blob storage or Amazon S3 bucket

C.

Content-Security-Policy update URL in the init-cfg.txt file

D.

Custom-AMI or Azure VM image, with content preloaded

E.

Panorama software licensing plugin

Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)

A.

Its update requires "Commit" to enforce membership mapping.

B.

It allows creation and enforcement of consistent Security policy across multiple cloud environments.

C.

Tags cannot be defined statically on the firewall.

D.

It uses tags as filtering criteria to determine IP address mapping to a group.

E.

Its maximum number of registered IP addresses is dependent on the firewall platform.