hay ya farid
|
|
Título del Test:
![]() hay ya farid Descripción: todas en orden |



| Comentarios |
|---|
NO HAY REGISTROS |
|
An NGFW engineer is configuring multiple Layer 2 interfaces on a Palo Alto networks firewall, and all interfaces must be assigned to the same VLAN. During initial testing, it is reported that clients located behind the various interfaces cannot communicate with each other. Which action taken by the engineer will resolve this issue?. Configure each interface to belong to the same Layer 2 zone and enable IP routing between them. Assign each interface to the appropriate Layer 2 zone and configure Security policies for interfaces not assigned to the same zone. Assign each interface to the appropriate Layer 2 zone and configure a policy that allows traffic within the VLAN. Enable IP routing between the interfaces and configure a Security policy to allow traffic between interfaces within the VLAN. An organization is segmenting its network using a Palo Alto Networks firewall in Layer 2 mode, Several interfaces are configured for the loT VLAN, connecting different building floors. Although all devices are in the same VLAN and IP subnet loT devices on one floor cannot communicate with devices on another floor. What is required to enable traffic between the Layer 2 interfaces on the PAN.OS firewall in this scenario?. The virtual router must have "Allow Layer 2 Forwarding" enabled. The firewall must have a Layer 3 VLAN interface configured for the corresponding VLAN ID. The interfaces must belong to security zones, and traffic is permitted by either the default intrazone rule or an explicit interzone policy. Address objects must be created for each device and allowed in a Security policy. A network engineer is setting up a new external-facing interface on a firewall to terminate remote user connections. Which service can be bound to this Layer 3 interface that cannot be configured on a Layer 2 interface?. Link Aggregation Control Protocol (LACP). Global Protect Gateway. QoS Profile. Management profile with User-ID network service enabled. When configuring a physical interface on a Palo Alto Networks firewall, which IP-based service is only available if the interface is set to Layer 3 mode?. Link monitoring. DDNS client. NetFlow export. QoS. Which feature can be enabled on a Layer 3 interface but is not available on Layer 2 interfaces?. LLDP profile. DHCP client. NetFlow profile. QoS profile. Which networking technology can be configured on Layer 3 interfaces but not on Layer 2 interfaces?. NetFlow. Link duplex. LLDP. DDNS. What is the requirements for interface link speeds when configuring a virtual wire on a Palo Alto Networks firewall?. They must be configuration with auto-negotiate settings regardless of the port type. They must have the same link speed and transmission mode. They must be the same media type. They must all be either copper or fiber optic, however they can be different. An administratior is configuring a site-to-site IPSec VPN and assigns an IP address to the tunnel interface. Which two abilities are enabled by this specific configuration step? (Choose two). Configuring tunnel monitoring to verify the liveliness of the connection. Firewall encrypting and decrypting packet payloads. Firewall performing NAT traversal. Running a dynamic routing protocol like OSPF over the tunnel. For which two purposes is an IP address configured on a tunnel interface? (Choose two.). Use of peer IP. Tunnel monitoring. Redistribution of User-ID. Use of dynamic routing protocols. Which two functions require a tunnel interface to be configured with an IP address? (Choose two.). Tunnel monitoring. Encapsulating traffic using an IPSec crypto profile. Forwarding traffic that matches a static route. Running dynamic routing protocols. Which action is not compatible with aggregate interface configuration?. Aggregating 18 Layer 3 interfaces. Aggregating four virtual wire interfaces. Aggregating interfaces in an HA pair. Aggregating two 10Gbps optical and two 10Gbps copper Ethernet ports. An engineer is perfirming the initial setup of a PA-Series firewall. The management network uses DHCP to assing IP addresses. The engineer accesses the device through the console port to perform the initial configuration. Which CLI command will enable DHCP on the management interface in this scenario?. request deviceconfig system type dhcp-client. set deviceconfig system type dhcp-client. set system management-interface dhcp-client enable true. set netowrk profiles interface-management-profile dhcp. Which CLI command is used to configure the management interface as a DHCP client?. Set deviceconfig system type dhcp-client. Set network dhcp interface management. Set network dhcp type management-interface. Set deviceconfig management type dhcp-client. A security administrator is hardening the ingress zone of an NGFW. The goal is to prevent attacks that rely on malformed IP address packets with incorrect header lengths or invalid TCP packets that have both the SYN and FIN flags set. Within which section of a Zone Protection profile should these protections be configured?. Reconnaissance protection. Protocol Protection. Flood Protection. Packet-based attack protection. When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?. Packet-Based Attack Protection. Protocol Protection. Reconnaissance Protection. Flood Protection. A network administrator is connecting two different office departments to a Palo Alto Networks firewall with the goal of allowing seamless communication between the two departments. However, users in one department cannot ping users in the other. Both departments are: 1. on the same subnet 2. part of the same VLAN 3. connected via separate Layer 2 interfaces on the firewall What is the most direct way to enable traffic flow between these interfaces?. Enable the "Intra-VLAN Forwarding" option on the VLAN object. Create a static route between the two Layer 2 interfaces. Configure a NAT policy to translate addresses between the two interfaces. Assign both Layer 2 interfaces to the same security zone. When creating a new security zone on a PAN-OS Firewall, an administrator is presented with a drop-down menu to select the zone type. Which two selections are available to the administrator? (Choose two). Tunnel. Virtual Wire. IPSEC. Global Protect. Which two zone types are valid when configuring a new security zone? (Choose two). Tunnel. Intrazone. Virtual wire. Internal. For Zero Trust segmentation of mobile medical-imaging trailers, what is the cost-effective design?. A NAT policy. An Authentication Profile. A User-ID Agent. Place the trailer traffic in separate security zones and enforce policy through the existing NGFWs. How do zones improve NGFW security?. A QoS profile. A NAT policy. A static route. They segment interfaces/traffic into policy boundaries and enable granular interzone/intrazone enforcement. How should critical and non-critical assets be separated?. A static route. Place them on different interfaces/security zones and enforce least-privilege policy between zones. A BGP redistribution profile. A User-ID Agent. Which SYN-flood mechanism helps determine whether new session attempts are legitimate?. A NAT policy. A User-ID Agent. SYN cookies. A QoS profile. Which two practices are core NGFW network-hardening recommendations?. A static route. Segment networks with security zones. A BGP redistribution profile. Use User-ID/Device-ID-based policy. An active/active firewall cluster processes a user's web request. The session is established on FW-A, but due to asymmetric routing, the return packet from the web server arrives at FW-B. Which high availability (HA) interface does FW-B use to forward the packet to FW-A for stateful inspection?. HA3 link. MGT interface. HA2 link. HA1 link. In an active/active high availability (HA) configuration with two PA-Series firewalls, how do the firewalls use the HA3 interface?. To synchronize, forwarding tables, IPSec security associations, and ARP tables between firewalls in an HA pair. To exchange hellos, heartbeats, HA state information, and management plane synchronization for routing and User-ID information. To perform session cache synchronization among all HA peers having the same cluster ID. To forward packets to the HA peer during session setup and asymmetric traffic flow. When deploying a pair of Palo Alto Networks firewalls in an active/active high availability (HA) cluster, what is the dedicated role of the HA3 Link?. Packet forwarding for session setup and asymmetric routing. Management plane synchronization for configurations and policies. Control Plane synchronization for heartbeats and state information. Data plane synchronization for session tables and forwarding tables. Which active/active HA capability is not normally used the same way in active/passive designs?. A URL Filtering profile. ARP load sharing on Layer 3 deployments. An Authentication Sequence. A User-ID group mapping profile. A network administrator is configuring an Aggregate Ethernet (AE) interface on an active/pasive high availability (HA) pair. To reduuce network downtime during a failover, the administrator wants the passive firewall's AE interface to be fully negotiated with the switch before it becomes active. Which Link Aggregation Control Protocol (LACP) setting achieves this administrator's goal?. System priority: 1. LACP mode: active. Transmission Rate: fast. Enable in HA passive state. After a recent high availability (HA) failover test on an active/passive cluster, an engineer noted a 30-45 second delay before traffic started flowing through a Link Aggregation Control Protocol (LACP) aggregate interface on the newly active firewall. What should have been configured to support LACP pre-negotiation to minimize LACP convergence delay?. Enable in HA passive mode. Set LACP mode to passive. Set HA link monitoring to aggressive. D. Enable LACP fast failover. Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?. Set LACP mode to "Active.". Set Transmission Rate to "fast.". Set "Enable in HA Passive State". Set passive link state to "Auto.". A Palo Alto Networks firewall has the following interfaces configured: 1. ethernet1/1 (Layer 3) 2. ethernet1/2 (TAP) 3. ethernet1/3 (Layer 2) 4. ethernet1/4 (virtual wire) An administrator needs to create a link group to monitor upstream connectivity for high availability (HA) failover. Which set of interfaces can be added to the link group?. ethernet1/1, ethernet1/2, ethernet1/4. ethernet1/1, ethernet1/2, ethernet1/3. ethernet1/2, ethernet1/3, ethernet1/4. ethernet1/1, ethernet1/3, ethernet1/4. Which interface types should be used to configure link monitoring for a high availability (HA) deployment on a Palo Alto Networks NGFW?. HA, Layer 2 and Layer 3. HA, Virtual Wire and Layer 2. Virtual Wire, Layer 2 and Layer 3. Tap, Virtual Wire and Layer 3. Which set of interface types is exclusively supported for inclusion in a link group?. Layer 2, Layer 3, tunnel. Layer 2, Layer 3, virtual wire. Layer 3, TAP, tunnel. Layer 2, high-availability (HA) , virtual wire. Which HA monitoring metric checks peer liveliness using ICMP-style heartbeat checks?. Heartbeat polling. A BGP redistribution profile. An Authentication Profile. A User-ID Agent. A network administrator is troubleshooting a routing issue on a PAN-OS firewall. The firewall has learned a route to the 10.100.1.0/24 network from both OSPF and Routing Information Protocol (RIP). When checking the routing table, the administrator observes that only the OSPF route is active. What is the reason the firewall preferred the OSPF route over the RIP route?. The OSPF route was learned by the firewall before the RIP route. OSPF is an industry-standard protocol, while RIP is considered legacy. The OSPF route has a lower administrative distance than the RIP route. The OSPF route has a lower metric than the RIP route. How does a Palo Alto Networks firewall choose the best route when it receives routes for the same destination from different routing protocols?. It compares the administrative distance and chooses the one with the lowest value. It compares the administrative distance and chooses the one with the highest value. It will attempt to load balance the traffic across all routes. The route that was received first will be entered into the forwarding table, and all subsequent routes will be rejected. A firewall should be advertising the static route 10.2.0.0/24 into OSPF. The configuration on the neighbor is correct, but the route is not in the neighbor's routing table. Which two configurations should you check on the firewall? (Choose two.). Within the redistribution profile, ensure that Redist is selected. In the redistribution profile, check that the source type is set to OSPF. Ensure that the OSPF neighbor state is 2-Way. In the OSPF configuration, ensure that the correct redistribution profile is selected in the OSPF Export Rules section. A network administrator is configuring path monitoring for a primary static route to ensure immediate fallback from a backup route. The administrator wants the primary route to become active again without any delay as soon its path is restored. Which preemptive hold time value should the administrator configure to achieve this inmediate fallback. 1. 0. -1. 2. How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?. It removes the static route because 0 is a NULL value. It accepts the configuration but throws a warning message. It reinstalls the route into the routing information base (RIB) as soon as the path comes up. It does not accept the configuration. In regards to the Advanced Routing Engine (ARE), what must be enabled first when configuring a logical router on a PAN-OS firewall?. License. Plugin. Content update. General setting. Which initial action is required to configure logical routers?. Activating an advanced routing subscription. Committing a new advanced routing software module. Changing the virtual router type from “default” to “advanced”. Checking “advanced routing” in general settings. When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?. To enable Gateway authentication to the Portal. To enable Portal authentication to the Gateway. To enable user authentication to the Portal. To enable client machine authentication to the Portal. What determines whether a GlobalProtect endpoint uses an internal gateway?. A BGP redistribution profile. A QoS profile. Internal Host Detection, which typically uses DNS resolution/reachability of a configured internal host. A NAT policy. A network security engineer has designed a GlobalProtect deployment that uses machine certificates to authenticate devices for pre-logon and SAML authentication to validate users after they login to the endpoint. What is the primary security benefit of implementing this two step authentication methodology?. It provides a seamless single sing-on (SSO) experience for the user by using the machine certificate for all authentication events. It encrypts the user's windows domain logon credentials between the endpoint and the domain controller. It enforces a Zero Trust principle by independently verifying the device identity before logon and user identity after logon. It allows the firewalls to cache users credentials during pre-logon to accelerate the user authentication process. An administrator is configuring a GlobalProtect pre-logon VPN. The administrator has already imported the necessary internal certificate authority (CA) certificates for issuing machine certificates onto the firewall. Which configuration is required on the GlobalProtect Gateway to enable pre logon using these machine certificates?. Create a certificate profile that trusts the machine certificate's CA and assign it within the Gateway Agent-Client Authentication settings. Create a device-based Security policy that allows traffic from the pre-logon user to an internal management zone. Configure the Gateway Agent Tunnel Settings to use IPSec with machine certificate authentication for the pre-logon tunnel. Create an authentication profile that points to the machine certificate's CA and assign it by using the client authentication settings of the GlobalProtect Portal. An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy. Which approach ensures continuous, secure connectivity and consistent policy enforcement?. Deploy self-signed certificates on each firewall, allow IP-based authentication to override certificate checks, and use default GlobalProtect settings for user/machine identification. Use a wildcard certificate from a public CA, disable all revocation checks to reduce latency, and manage certificate renewals manually on each firewall. Configure a single certificate profile for both user and machine certificates. Rely solely on CRLs for revocation to minimize complexity. Distribute root and intermediate CAs via Panorama template, use distinct certificate profiles for user versus machine certs, reference an internal OCSP responder, and automate certificate deployment with Group Policy. An organization has configured Global Protect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user-logon. How does the Global Protect agent process the authentication flow on Windows endpoints?. Global protect requires the user to log in first for SAML-based MFA before establishing the pre-logon tunnel, rendering the pre-logon certificate authentication (CA) flow redundant. Once the machine certificate is validated at pre-logon, the Windows endpoint completes MFA on behalf of the user by passing existing Windows Credential Provider details to the Global Protect Gateway without prompting the user. The Global Protect agent uses the machine certificate to establish a pre-logon tunnel, upon user sign-in, it prompts for SAML-based MFA credentials, ensuring both device and user identities are validated before granting full access. The Global Protect agent uses the machine certificate during pre-logon for initial tunnel establishment and then seamlessly reuses the same machine certificate for user-based authentication for user-based authentication without requiring MFA. An organization needs a GlobalProtect solution that meets two key requirements: IT administrators must be able to run scripts and push updates to endpoints before a user logs in. Users must authenticate with their cloud identity provider, which is protected by multi-factor authentication (MFA). Which GlobalProtect authentication configuration should be used to meet both requirements?. Cookie-based authentication for both pre-logon and user logon. Certificate-based authentication for pre-logon and SAML authentication for user logon. Single authentication profile using Kerberos to handle both pre-logon and user logon. SAML authentication for pre-logon and certificate-based authentication for user logon. An organization wants to optimize its GlobalProtect deployment. The goal is to ensure that DNS requests for internal resources are resolved by corporate DNS servers, and DNS requests for public websites such as "https://www.google.com/search?q=google.com" are handled by the user's local, faster DNS service to improve browsing performance. Which GlobalProtect feature and configuration achieves this outcome?. DNS Security with a policy that sinkholes traffic to non-corporate domains. Internal Host Detection to change DNS behavior only when the user is on the corporate network. Split Tunnel for network traffic with an access route that excludes the IP addresses of public DNS servers. Split Tunnel for DNS with the internal company domains added to the include list. An administrator configures a GlobalProtect gateway with spit tunneling for network traffic based on an access route. Users report that pubic web browsing works, but they cannot resolve the names of internal servers. The administrator determines that all DNS queries are being sent to the public DNS servers configured on the users’ endpoints. Which GlobalProtect portal setting should be configured to resolve this issue?. NAT rule to allow DNS traffic from the GlobalProtect clients to the internal DNS servers. Split tunneling for DNS and specify the internal corporate domains in the “Domain list.”. DNS Proxy feature on the firewall to point clients to the gateway IP for DNS. “DNS Forwarding” option on the gateway’s tunnel interface. An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The requirement is to route DNS queries for "*.corp.internal.com" to the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's locally configured DNS. What is the effect of configuring this split DNS policy?. It blocks access to all domains that are not explicitly listed in the split tunnel configuration. It provides selective DNS resolution, with specified domains resolved through the tunnel, optimizing performance for other lookups. It creates a DNS proxy on the client endpoint that forwards all queries to the firewall for inspection. It forces all applications to use the corporate DNS servers, regardless of the split tunnel settings for IP traffic. What is a result of enabling split tunneling in the GlobalProtect portal configuration with the "Both Network Traffic and DNS" option?. It allows devices on a local network to access blocked websites by changing which DNS server resolves certain domain names. It specifies when the secondary DNS server is used for resolution to allow access to specific domains that are not managed by the VPN. It allows users to access internal resources when connected locally and external resources when connected remotely using the same FQDN. It specifies which domains are resolved by the VPN-assigned DNS servers and which domains are resolved by the local DNS servers. When configuring split tunneling in the GlobalProtect portal's agent configuration, an administrator adds several internal domains to ther "Domain and DNS" split tunnel list. What is the primary purpose of this configuration?. To bypass DNS Security inspection for the specified internal domains. To allow access to these domains only when the user is connected to the GlobalProtect VPN, while unconnected users are directed to additional DNS Security features. To direct DNS queries for specified domains to the private DNS servers pushed by the gateway, while other queries use the public DNS servers on the user's workstation. To configure the endpoint's DNS suffic search list to include the specific domains. A site-to-site IPsec VPN terminates on an untrust interface. An explicit cleanup deny rule is placed before the predefined default Security rules, so IKE/IPsec negotiation traffic to the firewall is being blocked. The business also requires application traffic between the trust zone and the VPN tunnel zone. Which two policy changes are appropriate? (Choose two.). Add an allow rule above the cleanup deny rule for the required IKE/IPsec traffic to and from the VPN peer. Create an Application Override policy for IKE and ESP so that VPN negotiation bypasses Security policy. Place the tunnel interface in the same security zone as the internet-facing physical interface. Add Security policy rule(s) that permit the required application flows between the trust zone and the tunnel zone in the needed direction(s). A security engineer is replacing a legacy firewall with a Palo Alto Networks firewall. The new firewall needs to build an IPSec tunnel to a partner's Juniper SRX device. After the initial configuration, the tunnel fails to pass traffic, and logs indicate a Phase 2 negotiation failure. The Juniper SRX is configured as a policy-based VPN. Which action must the engineer take to configure the Palo Alto Networks firewall to establish the connection?. Create a NAT policy to exempt traffic entering the tunnel. Change the IKE Crypto profile to use main mode instead of aggressive mode. Ensure the tunnel interface is in the same security zone as the physical interface. Configure Proxy IDs to match the local and remote networks defined. After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish. Which of the following actions will resolve this issue?. Check that IPSec is enabled in the management profile on the external interface. Ensure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel interface. Validate the tunnel interface VLAN against the peer's configuration. Configure the Proxy IDs to match the Cisco ASA configuration. An IPsec tunnel is established successfully. The tunnel interface is assigned to a VPN security zone, the internal interface is in the trust zone, and routing is correct. User application traffic through the tunnel is denied. What should the engineer configure?. An Application Override policy for all traffic entering the tunnel interface. A Security policy rule that permits the intended application traffic between the trust and VPN zones. An Interface Management Profile on the tunnel interface that enables IKE. A Proxy ID solely to bypass Security policy evaluation. An engineer observes that an IPSec tunnel between a PAN-OS firewall and a Cisco ASA peer is flapping. The IKE Phase 1 completes successfully, but the system logs show errors during the Phase 2 negotiation related to "Traffic selector mismatch". Which configuration on the PAN-OS firewall needs to be verified to resolve this Phase 2 failure?. IKE Gateway must be bound to a loopback interface instead of the physicial egress interface. IKE Phase 2 lifetime must be set to a value longer than the Cisco ASA's lifetime. Proxy ID settings must be configured with the specific local and remote subnets used by the remote peer. Tunnel monitor profile must be created to ping a host on the remove network. Which two statements apply to configuring Security policy when setting up an IPsec tunnel between a Palo Alto Networks firewall and a third-party gateway, assuming the predefined default Security rules have not been overridden? (Choose two.). IKE negotiation and IPsec/ESP packets to the firewall are allowed by default through the intrazone-default allow rule. Separate Security rules for incoming and outgoing tunneled traffic are always mandatory, even when the desired rule criteria are identical. Separate rules for incoming and outgoing tunneled traffic are optional and can be used when more granular directional control is required. IKE negotiation and IPsec/ESP packets to the firewall are denied by default through the interzone-default rule. To comply with new directives mandating the use of quantum-resistant cryptography for all data-in-transit, a network engineer is tasked with reconfiguring existing IKEv2 VPN Tunnels between PA series firewalls to meet this requirements. With two actions should the engineer take to ensure compliance? (choose two). Generate a post-quantum pre-shared key (PPK) and apply it within th3 IPSec tunnel configuration's advanced settings. Enable GlobalProtect with quantum-resistant tunneling and apply the profile to the IKE Gateway. Configure an IKE Crypto profile with one or more post-quantum rounds selected and apply it to an IKE gateway configured for the Post-quantum key exchange mechanism. Establish a shared secret of at least 64 characters and configure it as post-quantum pre-shared key (PPK) within a IKEv2-only IKE gateway. Which two actions in the IKE Gateway will allow implementation of post-quantum cryptography when building VPN between multiple Palo Alto Networks firewalls (choose two): Select IKE V2, Preferred enable the Advanced Options -> PQ KEM, then add one or more "Rounds.". Ensure Authentication is set to 'certificate " then import a post-quantum derived certificate. Select IKE V2, enable the Advanced Options -> PQ KEM, then create an IKE Crypto Profile with Advanced Options adding one or more Rounds. Select IKE V2, enable the Advanced Options -> PQ PPK then set a 64+ character string for the post-quantum pre shared key. What is the primary purpose of the 'Keep Alive' feature in a Palo Alto Networks GRE Tunnel configuration?. To detect if the remote GRE peer is unreachable and bring the logical tunnel interface down. To encrypt the GRE control messages between peers. To negotiate GRE encapsulation parameters like keys and sequence numbers. To perform NAT for GRE traffic. A security engineer is integrating a new third-party TACACS+ server for authenticating network administrators to the firewall's management interface. The existing local database authentication must be retained as a primary method for emergency. The requirement is to first check the TACACS+ server for credentials, and if that server is unavailable or rejects the login, the firewall should then check its local user database. Which two components must be configured on the firewall to meet this requirement? (Choose two.). Authentication sequence that prioritizes the TACACS+ authentication profile and includes the default local database profile as a secondary option. Authentication profile that specifies the TACACS+ server profile. Authentication Enforcement policy object to link the TACACS+ server and the local database. Custom administrator role configured to permit authentication from either TACACS+ or the local database. An engineer is implementing a new rollout of SAML for administrator authentication across a company's Palo Alto Networks NGFWs. User authentication on company firewalls is currently performed with RADIUS, which will remain available for six months until it is decommissioned. The company wants both authentication types to be running in parallel during the transition to SAML. Which two actions meet the criteria? (Choose two). Create and add the "SAML Identity Provider" Server Profile to the authentication profile for the "RADIUS" Server Profile. Create a testing and rollback plan for the transition from RADIUS to SAML as the two authentication profiles cannot be run in tandem. Create an authentication sequence that includes both the "RADIUS" Server Profile and "SAML Identity Provider" Server Profile to run the two services in tandem. Create and apply an authentication profile with the "SAML Identity Provider" Server Profile. An organization is migrating its GlobalProtect user authentication from an existing LDAP directory to a new Kerberos server. To ensure a smooth transition, the network security team needs to allow users from both directories to authenticate for a period of 90 days. The firewall should first attempt authentication against the new Kerberos server and then fall back to the legacy LDAP server if the initial attempt fails. Which two configurations are required to implement this authentication fallback strategy? (Choose two.). Implement a User-ID Group Mapping policy to link users between the LDAP and Kerberos directories. Configure a new RADIUS proxy on the firewall to handle authentication requests for both Kerberos and LDAP. Configure a new authentication profile that references the Kerberos server profile. Configure an authentication sequence that lists the Kerberos authentication profile first, followed by the LDAP authentication profile. What is the purpose of assigning an Admin Role Profile to a user in a Palo Alto Networks NGFW?. Enable multi-factor authentication (MFA) for administrator access. Select which external authentication protocol validates the administrator password. Allow access to all management functions without restrictions. Define granular permissions for management tasks. An administrator is partitioning a firewall using VSYS to serve different business units. To ensure fair resource allocation, which quota can be set on a per-VSYS basis?. Dedicated CPU core assignment. Maximum number of address objects. Throughput limit (in Mbps). Maximum number of security rules. What is the primary multitenancy advantage of Virtual Systems?. A WildFire Analysis profile. A Service Route. An Authentication Profile. Logical separation of administrative/security policy contexts on one physical firewall. Which type of firewall resource can be assigned when configuring a new firewall virtual system (VSYS)?. Security profile limit. CPU. Memory. Sessions limit. A systems engineer is working with an MSSP that wants logically separated BGP peering setups for each customer while reusing and maintaining a standard set of routing rules and settings. What should the engineer recommend?. Plan for logical routers in the PAN-OS Advanced Routing Engine so routing profiles can be shared across the logical routers. Create only an API call containing routing filters and maps for every new customer instead of using routing separation. Use existing virtual routers but accept that there is no way to reuse standard routing criteria. Use VSYS instead of logical routers because VSYS is the routing construct designed to share common BGP profiles. A Managed Service Provider (MSP) is hosting two tenants, Tenant-A and Tenant-B, on a single Palo Alto Networks firewall using VSYS. The MSP has configured inter-VSYS routing to allow Tenant-A to access a shared service in Tenant-B. The provider has also correctly configured separate virtual routers, static routes using the next-vr next-hop. external zones, and Security policies within each VSYS to allow traffic from internal zones to the external zones. Despite this, traffic is being dropped. What is the missing configuration that will permit traffic between the two VSYSs?. Create a single shared virtual router and assign interfaces from both VSYSs to it. Under the VSYS settings, ensure that Tenant-A is in the "Visible VSYs" list for Tenant-B, and vice versa. Configure a policy on Tenant-A with the destination zone set to Tenant-B's internal zone. Create a global Security policy in Panorama that allows inter-VSYs traffic between the two tenant. A NGFW engineer is establishing bidirectional connectivity between the accounting virtual system (VSYS) and the marketing VSYS. The traffic needs to transition between zones without leaving the firewall (no external physical connections). The interfaces for each VSYS are assigned to separate virtual routers (VR), and inter-VR static routes have been configured. an External zone has been created correctly for each VSYS. Security policies have been added to secure the desired traffic between each zones and it respective external zone. However, the desired traffic is still unable to successfully pass from one VSYS to the other in either direction. Which additional configuration task is required to resolve this issue?. Create security policies to allow traffic between the two External zones. Enable the "allow inter-VSYS traffic" option in both external zone configuration. Create a transit VSYS and route all the inter-VSYS traffic though it. Add each VSYS to the list of visible virtual system of the other VSYS. A network security engineer needs to permit traffic between two distinct VSYS that reside on one Palo Alto Networks firewall. This traffic will not egress the firewall to an external device. Which zone type must be configured to act as the logical source and destination for this traffic flow?. Layer 3. TAP. External. Layer 2. An engineer is troubleshooting a failed inter-VSYS communication path between DMZ-VSYS and internal-VSYS. The configuration includes separate virtual routers with next-vr static routes and appropriate Security policies with each VSYS allowing traffic to and from their external xones. Given that all routing and policy configurations within each indiivdual VSYS are correct, what is the probable cause of the failure?. The administrator did not configure Visible Virtual System. A tunnel interface is required to connect the two virtuual routers instead of using the next-vr option. The intrazone-default policy is blocking the traffic because two external zones are logically connected. The external zones were not assigned the External zone type, preventing the from connecting. A network security engineer is segmenting a single firewall into VSYS-A and VSYS-B. For traffic to flow from VSYS-A to VSYS-B, external zones are required. What are two fundamental properties of the external zones needed for this configuration? (Choose two). They are automatically created when inter-VSYS routing is enabled. They represent their parent VSYS without being tied to a physical or logical interface. They are a security construct belonging to a single VSYS. They must be linked to the same virtual router as the ingress interface. Which two characteristics accurately define the external zone? (Choose two.). It is a shared object that is visible to all VSYSs on the firewall. It must be associated with a dedicated virtual router for inter-VSYS traffic. It is a logical object that is bound to a specific VSYS, not an interface. It functions as a representation of its own VSYS when communicating with other VSYSs. Which two statements describe an external zone in the context of virtual systems (VSYS) on a Palo Alto Networks firewall? (Choose two). It is not associated with an interface, it is associated with a VSYS itself. It is a security object associated with a specific VSYS. It is a security object associated with a specific virtual router of a VSYS. It is associated with an interface within a VSYS of a firewall. Which zone type allows traffic between zones in different virtual systems (VSYS), without the traffic leaving the firewall?. Internal. Transient. External. Isolated. A network engineer is separating a corporate network from a guest network using two different VSYSs ("Corp-VSYS" and "Guest-VSYS") on the same firewall. A specific server in the corporate network needs to be accessible from the guest network. The engineer has set up inter-VSYS static routes with next-vr and the necessary Security policies within each VSYS to permit the traffic to and from their respective external zones. The traffic logs show the packets are dropped. In this use case, which setting governs the permission for traffic to pass between different VSYS contexts?. Zone Protection profile applied to the external zones. Virtual router "Enable Inter-VR Forwarding" checkbox. Visible Virtual System configured to explicitly allow one VSYS to see the other. NAT policy to translate the guest source IP address to an address within the corporate VSYS. A firewall administrator uses Panorama to manage a fleet of firewalls. After successfully onboarding the firewalls to Strata logging service and enabling cloud logging via a template, the security operation team reports that they can no longer see new logs on the on-premise Panorama log collectors. Logs are showing correctly in Strata logging service. Which setting was likely missed during the Panorama template configuration?. The log forwarding profile was modified to only sent logs to Strata logging service and no longer includes the on-premise Panorama log collectors. The device certificate from Panorama log collectors were not renewed after enabling the cloud logging service connection. Panorama log collectors were not defined as primary destination within the collector group configuration for the managed firewalls. Duplicate logging (on-premise and cloud) is disabled under Device>setup>Management. An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service. Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?. Enable the "Panorama/Cloud Logging" option in the Logging and Reporting Settings section under Device -> Setup -> Management in the appropriate templates. Select the "Enable Cloud Logging" option in the Cloud Logging section under Device -> Setup -> Management in the appropriate templates. Select the "Enable Duplicate Logging" option in the Cloud Logging section under Device -> Setup -> Management in the appropriate templates. Modify all active Log Forwarding profiles to select the "Cloud Logging" option in each profile match list in the appropriate device groups. How does Strata Logging Service address growing retention requirements?. A NAT policy. A GlobalProtect HIP profile. A Zone Protection profile. It provides scalable cloud logging capacity that can grow with the deployment. What should be checked when a firewall loses connectivity to Strata Logging Service?. The firewall device certificate and onboarding/connectivity state. A Zone Protection profile. A BGP redistribution profile. A Decryption Profile. An organization requires log forwarding to a Security Information and Event Management (SIEM) solution, critical alerts being sent to the operations team via email, and log forwarding to the central Panorama instance for long-term storage and analysis. To accomplish this, the engineer creates a new Log Forwarding profile. Which set of log forwarding methods are available to configure in this profile?. SNMP, HTTP, Elastic. Syslog, NetFlow, email. Panorama/Cloud logging, email, Syslog. Panorama, Cortex XDR, Syslog. An organization requires that specific, critical threat alerts generate an immediate notification to the security team distribution list as well as to the standard syslog server and the Panorama management station. Which available forwarding methods can be combined in a Log Forwarding profile to achieve this?. SNMP traps, NetFlow, Syslog. Panorama/Cloud logging, email, Syslog. Panorama, HTTP, TACACS+. Syslog, email, Strata Logging Service. Which forwarding methods can be used on the Objects tab when configuring the Log Forwarding profile?. Panorama, syslog, email. Panorama, ADEM, syslog. Syslog, HITP, NetFlow. SNMP, HTTP, RADIUS. Which statement applies to Log Collector Groups?. Log redundancy remains available even if Log Collectors in the group have different numbers of logging disks. In any single Collector Group, all Log Collectors must run on the same Panorama model. Enabling redundancy increases log processing traffic in a Collector Group by only 50%. A Collector Group supports up to 18 Log Collectors plus two hot spares. Using the standard manual PA-Series HA upgrade workflow (not the automated HA Pair Upgrade Orchestration feature), a network security engineer at a 24/7 online retailer is upgrading an active/ passive high availability (HA) cluster of PAN-OS firewalls. The primary goal is to perform the upgrade with no service interruption to online transactions. The engineer has already downloaded the new software to both devices. Which sequence of actions will meet this requirement?. Disable HA synchronization on the active firewall, upgrade the passive firewall, and then re-enable synchronization. Once synchronized, repeat the process on the other firewall. Force the active firewall into a suspended state to trigger a failover, then upgrade and reboot it. Suspend the currently active firewall to fail traffic back to the upgraded unit. Upgrade the remaining firewall. From Panorama, create a scheduled software update job targeting both firewalls in the HA pair to run at the same time, then rely on the HA election process to manage the failover automatically. Upgrade the passive firewall first while it is still in the passive state. Once it reboots and is operational, suspend the active firewall to fail over to the newly upgraded device. Then, upgrade the remaining firewall. Using the standard manual PA-Series HA upgrade workflow (not the automated HA Pair Upgrade Orchestration feature), an administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized. What is the recommended upgrade process for minimal disruption in this high availability (HA) scenario?. Shut down the currently active firewall and upgrade it offline, allowing the passive firewall to handle all traffic. Once the active firewall finishes upgrading, bring it back online and rejoin the HA cluster. Finally, upgrade the passive firewall while the newly upgraded unit remains active. Suspend the active firewall to trigger a failover to the passive firewall. With traffic now running on the former passive unit, upgrade the suspended (now passive) firewall and confirm proper operation. Then fail traffic back and upgrade the remaining firewall. Push the new PAN-OS version simultaneously to both firewalls, having them upgrade and reboot in parallel. Rely on automated HA reconvergence to restore normal operations without manually failing over traffic. Isolate both firewalls from the production environment and upgrade them in a separate, offline setup. Reconnect them only after validating the new software version, resuming HA functionality once both units are fully upgraded and tested. What must be verified before upgrading Panorama-managed firewalls to a newer PAN-OS version?. Panorama must be running a supported PAN-OS version that is the same as or newer than the managed firewall target version. A BGP redistribution profile. A Zone Protection profile. A Decryption Profile. What should be upgraded/validated before managed firewall PAN-OS upgrades?. An Authentication Profile. A static route. A QoS profile. Panorama software compatibility should be addressed before upgrading managed firewalls beyond the Panorama-supported version. A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency. Which approach best addresses these requirements while maintaining consistent policy enforcement?. Deploy self-signed certificates at each site to simplify local certificate validation and reduce dependencies on a centralized CA. Turn off certificate revocation checks for lower overhead, rely on IP-based rules for GlobalProtect authentication, and use a single certificate profile for both users and devices. Configure each firewall independently to trust the root and intermediate CA certificates. Rely only on manual CRL checks for certificate revocation, and import both user and device certificates directly into each firewall's local certificate store for authentication. Distribute the root and intermediate CA certificates via Panorama as shared objects to ensure all firewalls have a consistent trust chain. Configure OCSP responder profiles on each firewall to offload revocation checks to an internal OCSP server while keeping CRL checks as a fallback. Maintain separate certificate profiles for user and device authentication and use an automated enrollment method - such as Group Policy or SCEP - to deploy certificates to endpoints. Obtain wildcard certificates from a public CA for both user and device authentication, and configure firewalls to perform CRL polling at the default update interval. Manually install user certificates on endpoints and synchronize firewall certificate stores through frequent manual SSH updates to maintain consistency. A network administrator needs to replace the default self-signed certificate on a firewall with one signed by the company's internal certificate authority (CA). Which two firewall features would require this new certificate to be assigned via an SSL/TLS Service profile? (Choose two). User-ID agent redistribution. Authentication Portal. Global Protect Gateway. RADIUS Server authentication. Palo Alto Networks NGFWs use SSL/TLS profiles to secure which two types of connections? (Choose two.). GlobalProtect Gateways. GlobalProtect Portals. NAT rule processing. RADIUS server authentication. Which two Palo Alto Networks firewall services are secured by attaching an SSL/TLS service profile to their configuration? (Choose two). Prisma Access service connections. GlobalProtect portal. LDAP server profiles. Authentication portal. Which two services are configured by applying an SSL/TLS Service Profile? (Choose two). Log forwarding to Strata Logging Service. The User-ID syslog listening service when configured for SSL. A Forward Trust certificate used for SSL Forward Proxy. A GlobalProtect Portal. Which two services use an SSL/TLS service profile for securing communications? (Choose two.). Authentication portal. On-premises User-ID agent communication. Decryption profile. Firewall management web interface. A company is enabling SSL Forward Proxy to inspect encrypted traffic. A security engineer generates a new certificate on the firewall and flags it with the "Forward Trust" certificate property. What is the critical next step that must be performed for decryption to function correctly without causing security warnings for end users?. Install the public portion of the forward trust certificate into the trust store of all client machines. Import the private key of the forward trust certificate onto the domain controller. Create a Security policy rule that allows traffic from the certificate of the firewall to all the zones. Set the forward trust certificate as the SSL/TLS Service profile for the management interface. What is the purpose of a Decryption policy rule on an NGFW?. An Authentication Profile. A NAT policy. To inspect and enforce security controls on SSL/TLS traffic. A QoS profile. Which configuration step is required when implementing a new self-signed Forward Trust CA certificate for SSL Forward Proxy decryption on a Palo Alto Networks firewall?. Set the Forward Trust CA certificate as the default routing certificate for all network traffic. Disable all existing SSL decryption rules until the new certificate is fully propagated. Configure the Forward Trust CA certificate with an indefinite validity period. Distribute the public Forward Trust CA certificate to the trusted root certificate store of all client devices. Which decryption mode is used to inspect outbound SaaS traffic from internal users?. A BGP redistribution profile. SSL Forward Proxy. An Authentication Profile. A Service Route. Which two SSH Proxy decryption settings most improve security posture?. An Authentication Profile. Block sessions that use unsupported SSH algorithms. A BGP redistribution profile. Block sessions that use unsupported SSH versions. Which two conditions should be evaluated before broad internet SSL decryption?. Certificate pinning. Incomplete certificate chains. A Service Route. An HA3 link. Which policies balance employee privacy with SSL decryption for mobile users?. Use SSL Forward Proxy for decryptable traffic and No Decryption rules for approved sensitive/private categories. A BGP redistribution profile. A QoS profile. A NAT policy. An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving “Your connection is not private” browser errors for all external websites. What is the most likely cause of these widespread certificate errors?. The firewall’s forward untrust certificate has expired, preventing it from identifying untrusted sites. The external websites are using TLS1.3, which cannot be decrypted by the firewall without a specific license. The firewall’s self-signed CA certificate is not deployed to the trusted certificate store on client endpoints. The decryption policy is configured with a “no-decrypt” action, which causes browsers to reject the connection. How does SSL Inbound Inspection position the firewall?. The firewall transparently decrypts and inspects TLS between an external client and an internal server for which the server certificate/private key are available. A BGP redistribution profile. A NAT policy. A User-ID Agent. What is a common reason SSL Forward Proxy fails for a specific HTTPS site?. Certificate pinning or another application behavior that rejects the substituted certificate. An Authentication Profile. A QoS profile. A NAT policy. What role does an NGFW perform during SSL Forward Proxy?. A QoS profile. An Authentication Profile. A User-ID Agent. It dynamically signs substitute server certificates and acts as the trusted intermediary CA for outbound decrypted sessions. When should SSL Forward Proxy be used instead of SSL Inbound Inspection?. For outbound encrypted traffic from internal clients to external servers. A User-ID Agent. A QoS profile. A static route. Which function can detect, log, and control post-quantum cryptography usage in TLS traffic?. A User-ID Agent. A QoS profile. Decryption policy/decryption controls. A BGP redistribution profile. Which two SSL Forward Proxy practices are recommended?. A static route. Create No Decryption exceptions for justified sensitive or incompatible traffic. A QoS profile. Use a Forward Trust CA trusted by endpoints. Where are the global OCSP/CRL mechanisms and receive timeouts configured for server-certificate revocation checking used by SSL/TLS decryption?. Device > Setup > Session > Decryption Certificate Revocation Settings. Device > Certificate Management > SSL/TLS Service Profile. The Forward Trust certificate object. Device > Authentication Sequence. After a recent security audit, a company is required to enforce more strict validation for all certificate-based authentication, including for GlobalProtect clients. An engineer observes the firewall accepting certificates from a compromised intermediate certificate authority (CA). The engineer needs to update the firewall configuration to use an Online Certificate Status Protocol (OCSP) responder to check for revoked in real time. In which configuration object would the engineer enable OCSP verification for the CAs used in the authentication process?. Authentication sequence. Decryption Profile. Certificate profile. SSL/TLS Profile. In a Palo Alto Networks environment, GlobalProtect has been enabled using certificate-based authentication for both users and devices. To ensure proper validation of certificates, one or more certificate profiles are configured. What function do certificate profiles serve in this context?. They store private keys for users and devices, effectively allowing the firewall to issue or reissue certificates if the primary Certificate Authority (CA) becomes unavailable, providing a built-in fallback CA to maintain continuous certificate issuance and authentication. They define trust anchors (root / intermediate Certificate Authorities (CAs)), specify revocation checks (CRL/OCSP), and map certificate attributes (e.g., CN) for user or device authentication. They provide a one-click mechanism to distribute certificates to all endpoints without relying on external enrollment methods. They allow the firewall to bypass certificate validation entirely, focusing only on username / password-based authentication. A network security engineer wants to create Security policy rules that allow or deny traffic based on a user's department, which corresponds to groups in the company's Active Directory. To achieve this, the firewall needs to retrieve group information from the directory server. Which configuration object must be created first to establish the connection with the Active Directory server?. LDAP server profile. Authentication sequence. User-ID agent service account. Kerberos server profile. An administrator wants to use User-ID to enforce Security policies based on group membership defined in a central directory. After configuring the firewall to map IP addresses to usernames, the administrator navigates to the policy editor but cannot select any directory groups as source or destination criteria. Which foundational component must be configured on the firewall to query the directory server for group information?. Certificate profile. RADIUS server profile. LDAP server profile. Authentication Portal policy. Which option correctly identifies two identity capabilities provided by Cloud Identity Engine?. Directory synchronization/group visibility and cloud-based identity/authentication integration for supported Palo Alto Networks products. Static-route redistribution and BGP path selection. QoS shaping and DSCP remarking. HA link monitoring and path monitoring. An LDAP Server Profile is already configured and reachable. Which User-ID configuration retrieves directory group membership so users and groups can be used as Security policy match criteria?. Group Mapping Settings. A User Mapping profile. A second LDAP Server Profile. An Authentication Profile. A financial institution is deploying User-ID to enforce granular access control. Due to strict compliance requirements, the customer team needs to implement the User-ID mapping technique that provides the highest level of assurance and is least susceptible to inaccuracies from shared IP addresses. Which user-to-ip mapping method is most operationally efficient at meeting this requirement?. WMI probing. Syslog receiver. Internal gateway. Domain monitoring. For a remote workforce, which method provides the most deterministic mapping of a user to an IP address?. On-premises User-ID agent. Port mapping with Terminal Server agent. XML API. GlobalProtect client. Which PAN-OS method of mapping users to IP addresses is the most reliable?. GlobalProtect. Syslog. Server monitoring. Port mapping. Which type of information is Cloud Identity Engine User Context designed to redistribute through publishing and subscribing segments?. Static routes, BGP communities, and policy-based forwarding entries. Dynamic identity context such as IP-to-user mappings, IP tags, user tags, quarantine/Host-ID context, and IP-port mappings. Directory group definitions only, with no dynamic user-to-IP information. Panorama Security rules and template variables. In Cloud Identity Engine User Context, what is the relationship between a publishing segment and a subscribing segment?. The publishing segment only receives identity data, while the subscribing segment sends it. The publishing segment sends selected identity-context data collected from its devices, and the subscribing segment contains devices that receive that data. Both segment types are only directory-group filter lists and do not contain firewalls. A subscribing segment can receive Security policy rules but not identity context. Firewall group A learns dynamic IP-to-user and tag mappings. Firewall group B must consume those mappings without building a direct redistribution mesh between every firewall. Which Cloud Identity Engine capability best meets the requirement?. Directory Sync group filtering. User Context publishing and subscribing segments. An SSL/TLS Service Profile. A Panorama template variable. An organization wants to prevent selected Active Directory groups from being synchronized into Cloud Identity Engine at all. Which mechanism addresses this requirement most directly?. A User Context publishing segment. Directory Sync group/filter configuration for the connected directory. A Security policy rule after redistribution. The HA2 data link. A PA-Series firewall with all licensable features is being installed. The customer's security policy requires that users do not directly access websites. Instead, a security device must create the connection and there must be authentication back to the Active Directory servers for all sessions. Which action meets the requirements in this scenario?. Deploy the transparent proxy with Web Cache Communications Protocol (WCCP). Deploy the explicit proxy with Kerberos authentication scheme. Deploy the Next-Generation Firewalls as normal and install the User-ID agent. Deploy the Advanced URL Filtering license and captive portal. A government agency needs to ensure that all user web access is explicitly mediated and authenticated. The agency has the following requirements: 1. Client browsers must be manually configured to send traffic to the firewall's IP address and a specific port 2 The firewal must support seamles single sign-on (SO) with the users existing Active Directory credentials. Which feature set should the engineer configure to meet the agency's requirements?. User-ID agent integration with Authentication Portal for authentication. Decryption policy that redirects users to a SAML identity provider for authentication. Web proxy in explicit mode with an Authentication policy by using Kerberos. Web proxy in transparent mode with an Authentication policy by using multi-factor authentication (MFA). A school district is configuring a PA-Series firewall to control student internet access. The policy requires that all student web browsing must be explicitly sent to the firewall for inspection and that connections to external websites must originate from the firewall itself. Additionally, each web session must be authenticated against the school's Active Directory to identify the user. Which configuration satisfies all policy requirements for this school district?. Configure the firewall as an explicit proxy and use an Authentication policy with a Kerberos single sign-on (SSO) profile. Configure the firewall as a transparent proxy and use Authentication Portal to identify users. Configure User-ID agentless monitoring of the Active Directory domain controllers. Configure the firewall as a reverse proxy to protect internal web servers. A cloud-native NGFW design must remain available across multiple cloud availability zones without relying on PAN-OS active/active clustering. Which architecture mechanism best provides traffic distribution and fault detection?. An Ansible script by itself, with all firewall capacity in one zone. Cloud-native load balancing/service insertion with health checks and multi-AZ resilient firewall resources. Terraform templates that deploy all firewall instances into a single availability zone. An HA3 active/active link stretched across cloud availability zones. What is the initial IP address for the management interface on a new Palo Alto Networks firewall?. 10.0.0.1. 172.16.0.1. 192.168.1.1. 192.168.255.254. A network security engineer is designing a resilient architecture for inspecting traffic in Google Cloud Platform (GCP). The design must ensure that firewall service is maintained even if a single GCP zone becomes unavailable. Which architecture should be used for the VM-Series firewalls in this use case?. Instance group of VM-Series firewalls spread across multiple zones, with traffic routed to them by a GCP internal Load Balancer. PAN-OS active/active high availability (HA) cluster configured with dedicated HA interfaces in a Shared VPC. Single, large VM-Series firewall in one zone that is configured for live migration to another zone upon failure. Ansible playbook that monitors the health of the primary firewall and launches a new one in a different zone when a failure is detected. An organization is migrating its data center to Amazon Web Services (AWS) and needs to deploy VM-Series firewall to inspect all ingress and egress traffic. The solution must provide both resilience across multiple Availability Zones and the ability to scale horizontally. Which combination of AWS services and Palo Alto Networks components is required for this use case?. Amazon EC2 Auto Scaling group with VM-Series firewall and an Amazon Gateway Load Balancer. AWS Lambda function that monitors the firewalls health and re-routes traffic using the AWS API. Single VM-Series firewall with an Elastic IP address that can be re-associated upon failure. PAN-OS active/active high availability (HA) pair with an AWS Transit Gateway. When migrating an existing perpetual/ELA VM-Series firewall to flexible Software NGFW credits using a fixed-vCPU deployment profile, which deployment-profile choice best preserves the existing fixed-model capacity?. Use a DNS Proxy rule to define the licensed capacity. Use a fixed-vCPU deployment profile sized for the same VM-Series model/capacity as the existing deployment. Use a standalone Authentication Profile to select the vCPU count. Use the User-ID Agent to allocate Software NGFW credits. Which Azure deployment style places enforcement close to applications?. A User-ID Agent. A local-only NAT rule. A standalone Authentication Profile. VM-Series NGFWs using Layer 3 interfaces and security zones in Azure VNets. What Customer Support Portal object is used to generate/allocate flexible Software NGFW capacity?. A deployment profile. A NAT policy. A static route. An Authentication Profile. A cloud security team wants to extend its existing Palo Alto Networks Security policies into the organization's Kubernetes environments. The team requires an NGFW solution that can be deployed natively as a container and managed by Panorama. Which firewall form factor meets these requirements?. VM-Series. PA-5400 series. CN- series. Cloud NGFW. An organization runs multiple Kubernetes clusters both on premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within the cluster, maintain consistent Security policies across all environments, and dynamically scale as containerized workloads spin up or down. They also plan to use a centralized Panorama instance for policy management and visibility. Which approach meets these requirements. Configure the CN-Series only in public cloud clusters, and rely on Kubernetes Network Policies for on-premises cluster security. Synchronize partial policy information into Panorama manually as needed. Deploy a single CN-Series firewall in the on-premises data center to process traffic for all clusters, connecting remote clusters via VPN or peering. Manage this single instance through Panorama. Use Kubernetes' native deployment tools (e.g, Helm) to deploy CN-Series in each cluster, ensuring local insertion into the service mesh or CNI. Manage all CN-Series firewalls centrally through Panorama, applying uniform Security policies across on-premises and cloud clusters. Install standalone CN-Series instances in each cluster with local configuration only. Export daily policy configurations snapshots to Panorama for record keeping, but do not unify policy enforcement. What is the key value of CN-Series in container environments?. A standalone Authentication Profile. Inspect and control east-west traffic to limit lateral threat movement between workloads. A local-only NAT rule. A DNS Proxy rule. When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?. Ansible automation modules. Service graph. CN-Series firewalls. Panorama role-based access control (RBAC). An organization must secure its AWS and Azure environments using a managed Palo Alto Networks solution and all policies must be synchronized from an existing Panorama deployment. The organization wants to insert security with the least possible impact on its application teams and use existing hub-and-spoke network designs. 1. The AWS environment uses a centralized AWS Transit Gateway (TGW) architecture 2. The Azure environment uses a Virtual WAN (VWAN) hub Which two actions are the most appropriate in this use case? (Choose two). Deploy individual VM-Series firewalls in each spoke virtual network (VNet) and manage them as a device group in Panorama. Deploy Cloud NGFW into the WAN hub as a trusted security partner and update routing policies to secure traffic. Deploy Cloud NGFW endpoints into a security virtual private cloud (VPC) and adjust the TGW route tables to inspect traffic flowing through the hub. Deploy Cloud NGFW endpoints in every application virtual private cloud (VPC) ignoring the TGW. To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-series and VM-series devices used in physical data centers. Resources exist in AWS and Azure: 1. The AWS deployment is architected with AWS Transit Gateway, to which all resources connect 2. The Azure deployment is architected with each application independently routing traffic The engineer deploying Cloud NGFW in these two cloud environments must account for the following 1. Minimize changes to the two cloud environments 2. Scale to the demands of the applications while using the least amount of compute resources 3. Allow the company to unity the security policies across all protected areas Which two implementations will meet these requirements? (Choose two). Deploy a VM-Series firewall in AWS in each VPC, create an IPSEC tunnel between AWS and Azure and manage the policy with Panorama. Deploy cloud NGFW for Azure in vVAN, create a vNAN to route all appropriate traffic to the cloud NGFW attached to the vNAN and manage the policy with local rules. Deploy Cloud NGFW for AWS in a centralized security VPC, update the Transit Gateway to route all appropriate traffic through the security VPC and manage the policy with Panorama. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the deployed NGFWs and manage the policy with Panorama. Which management surfaces can configure Cloud NGFW for AWS?. A local-only NAT rule. An HA3 cable between cloud regions. Cloud-provider/native management and supported Palo Alto centralized management such as Panorama, depending on deployment mode. A standalone Authentication Profile. Which two cloud architecture mechanisms commonly provide HA for Cloud NGFW?. A standalone Authentication Profile. Automated scaling. A physical TAP interface only. Cloud load balancers and health probes. After deploying Prisma AIRS AI Runtime Security: Network Intercept, which configuration applies prevention controls for AI-specific network threats to matching traffic?. Create an AI Security Profile, add it to a Security Profile Group, and attach that profile group to the applicable Security policy rule. Configure a User-ID Agent and attach it directly to an IKE Gateway. Create only a NAT rule for the AI model endpoints; no Security Profile is required. Attach an IKE Crypto Profile to the AI application objects. An organization wants to provide its DevOps team with programmatic access to a Palo Alto Networks Firewall via the XML API to automate rule creation. However, the team should not have access to the web interface or the CLI. Which firewall configuration object is used to define this type of role-based access control?. Service object for the XML API. Authentication Sequence. Interface Management Profile. Admin Role Profile. A DevOps team is building a repeatable process for deploying new Palo Alto Networks VM-Series firewalls. The entire infrastructure, including virtual networks, subnets, and the firewalls themselves, must be defined in code to ensure consistency and enable version control. Which tool is primarily used for this type of declarative Infrastructure as Code (laC) provisioning?. Terraform. Ansible. Panorama. Azure DevOps. A security operations team is responsible for managing a large fleet of Palo Alto Networks VM-Series and PA-Series firewalls. The team needs to implement a solution that allows programmatic and consistent Security policy updates and configuration changes across all devices from a central point. Which third-party tool is specifically designed for this type of configuration automation?. Ansible. Panorama. Git. Terraform. An engineer is creating a automation workflow. The first step is to deploy a new VM-Series firewall into VMware vSphere environment, including its virtual machine (VM) configuration and network interfaces. The second step is to connect to the firewall and configure a complex set of Security policies and objects. The team uses both Terraform and Ansible. For which part of this workflow would Terraform typically be used?. Deploying the VM and associated network interfaces. Storing the credentials needed to access the vSphere environment. Pushing threat intelligence updates to the new firewall. Applying the detailed Security policies and objects. An organization is adopting an infrastructure as code (IaC) approach to manage its entire network environment, including its Palo Alto Networks Firewalls. The organization has chosen ansible as its primary tools for this initiative. How does Ansible enable an IaC model for managing this organization firewalls?. By providing real-time threat intelligence feeds directly to the firewall's data plane. By defining firewalls configuration in playbooks that can be version-controlled and executed repeatedly. By automatically discovering and mapping all network devices to generate a baseline configuration. By providing a graphical user interface that simplifies the creation of se security policies through a drag-and-drop interface. In a hybrid cloud deployment what is the primary function of Ansible in managing Palo Alto NGFWs?. It facilitates dynamic updated to NGFW threat databases. It enables centralized log collection and correlation for NGFWs. It provides a web interface for managing NGFW hardware clusters. It automates NGFW policy updates and configurations through playbooks. Which statement describes the role of Terraform in deploying palo alto networks NGFW?. It orchestrates real-time traffic inspection for network segments. It provides infrastructure-as-code (IaC) to automate NGFW deployments. It acts as a logging service for NGFW performance metrics. It manages thread intelligence data synchronization with NGFW. Which Panorama capability lets an administrator investigate activity across multiple managed firewalls from a central interface without opening each firewall's local web UI?. Aggregate and search centralized logs/ACC information collected from managed firewalls. Modify any firewall-local candidate configuration automatically without using templates/device groups or context switching. Run arbitrary dataplane CLI commands on every managed firewall without device permissions. Physically reset managed-firewall interfaces from Panorama without an operational command or device context. Which software-management task can Panorama perform centrally for managed firewalls?. Only download Panorama software; managed-firewall PAN-OS images cannot be deployed from Panorama. Download/upload PAN-OS or content updates in Panorama and install them on selected managed firewalls from Panorama > Device Deployment. Change the hypervisor CPU/RAM allocation of every VM-Series firewall regardless of cloud/hypervisor integration. Bypass PAN-OS upgrade compatibility and intermediate-version requirements for managed firewalls. What is Panorama's central management role?. A GlobalProtect HIP profile. A NAT policy. Manage policy, device groups, templates/template stacks, and centralized operations for supported firewalls. A tunnel interface. Without performing a context switch, which set of operations can be performed that will affect the operation of a connected firewall on the Panorama GUI?. Restarting the local firewall, running a packet capture, accessing the firewall CLI. Modification of post NAT rules, creation of new views on the local firewall ACC tab, creation of local custom reports. Modification of local security rules, modification of a Layer 3 interface, modification of the firewall device hostname. Modification of pre-security rules, modification of a virtual router, modification of an IKE Gateway Network Profile. What dynamic value should Panorama templates use for per-device HA peer IPs?. A BGP redistribution profile. Template variables. A tunnel interface. A Decryption Profile. What is the correct sequence of evaluation for security policy rule based?. Panorama Post-rules -> Panorama Pre-rules -> Local Firewall Rules. Panorama Pre-Rules -> Local Firewall Rules -> Panorama Post-Rules. Panorama Shared Rules -> Local Firewall Rules -> Device Groups Rules. Local Firewall Rules -> Panorama Pre-Rules -> Panorama Post-Rules. A Panorama administrator configures a pre-rule that blocks access to all social media applications across all managed firewalls. The marketing department, which sits behind a single firewall, requires a temporary exception to this rule. The firewall's local administrator is asked to implement this exception without modifying the Panorama configuration. Why will a local rule allowing social media applications for the marketing department fail to work?. The Panorama pre-rule is evaluated first and will block the traffic before the local exception rule is checked. Local security rules are unable to override any rules pushed from Panorama. A local pre-rule and application filter are required to create an exception. The firewall must be moved to a different device group in Panorama to have a separate policy. A security architect needs to implement a set of universal security rules that block access to malicious domains for all firewalls managed by Panorama. These block rules must be enforced regardless of any locally configured rules on the individual firewalls. Where should these rules be placed in the policy structure to ensure they are always evaluated first?. In a shared policy scope within the local rulebase. As default rules. In the pre-rulebase. In the post-rulebase. Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?. The order of policy evaluation can be configured differently in different device groups. Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules. When a policy match is found in a local firewall policy, if any Panorama shared post-rule is configured, it will still be evaluated. Panorama post-rules can be configured to be evaluated before local firewall policy for the purpose of troubleshooting. Which option contains only database categories that are available under Detailed Logs for a PAN-OS custom report?. Application Statistics (Summary), Tunnel (Summary), DecryptionLog (Summary), and Traffic (Summary). Threat (Detailed), URL Filtering (Detailed), WildFire Submissions, and GlobalProtect. System, Config, Session Browser, and Flow Basic. Application Statistics (Summary), HIP Match (Detailed), Tunnel (Summary), and User-ID (Detailed). How does Panorama improve enterprise reporting?. A NAT policy. It aggregates and analyzes logs from multiple managed firewalls. A BGP redistribution profile. A Zone Protection profile. Which Panorama report types are commonly used for administrator-defined reporting?. A BGP redistribution profile. Custom reports and PDF Summary reports. A NAT policy. A Zone Protection profile. Which set contains only sources available as Detailed Logs when building a custom report on a Palo Alto Networks NGFW?. Traffic (Detailed), User-ID (Detailed), and Application Statistics (Summary). GlobalProtect (Detailed), Traffic (Detailed), and Tunnel (Summary). Traffic (Detailed), Threat (Detailed), Data Filtering (Detailed), and User-ID (Detailed). Threat (Detailed), GlobalProtect (Detailed), Application Statistics (Summary), and WildFire Submissions (Detailed). A firewall administrator wants the dedicated management port to accept administrative connections only from a defined management subnet. Which management-interface control should be configured?. A service route for DNS. The Permitted IP Addresses list on the management interface. A Security policy on the untrust zone. A static route in the default virtual router. Which three cryptographic parameters belong in an IKE Crypto Profile used for IKE phase 1? (Choose three.). Tunnel-interface IP address. Authentication/hash algorithm. Diffie-Hellman group. Encryption algorithm. In a firewall HA pair, what is the main purpose of Path Monitoring?. To measure log-forwarding throughput. To verify the peer management interface responds to HTTPS. To test reachability of critical network destinations and contribute to failover decisions. To synchronize the candidate configuration. Which statement best distinguishes the GlobalProtect portal from a GlobalProtect gateway?. The portal terminates user tunnels while the gateway only distributes client configuration. The portal provides client configuration and agent information, while the gateway authenticates/terminates the remote-access connection and handles tunneled traffic. Both components perform the same function and differ only by hostname. The portal is used only for internal users and the gateway only for external users. For an IPsec site-to-site tunnel that uses traffic selectors, which configuration identifies the local and remote traffic that should match the phase-2 selector?. Proxy IDs. Dead Peer Detection settings. IKE lifetime. Tunnel-monitor profile. What is the principal reason to configure an Aggregate Ethernet interface on a PAN-OS firewall?. To place one physical port in multiple virtual routers. To create an encrypted site-to-site tunnel. To combine multiple physical links into one logical link for capacity and link resiliency. To replace the HA1 control link. Which three settings are fundamental when placing an Ethernet interface into Layer 3 mode for routed dataplane traffic? (Choose three.). Virtual router association. Aggregate group membership. Security zone assignment. IP address configuration. What action does the predefined interzone-default Security rule take on traffic between different zones when no earlier Security rule matches?. Allow. Deny/drop. Reset both endpoints. Forward without logging and without policy evaluation. Two PAN-OS OSPF neighbors are expected to form an adjacency. Which two parameters must be consistent between the neighbor interfaces for the adjacency to form normally? (Choose two.). Area ID. Hello/dead timing. Interface description. Ethernet speed. Which three elements are part of a standard agentless User-ID server-monitoring design for Windows domain controllers? (Choose three.). A service/server-monitoring account with appropriate permissions. An IPsec tunnel to every domain controller. WMI or WinRM-based server monitoring. The domain controller added to Server Monitoring. After two Ethernet interfaces have been paired in a virtual wire object, what additional configuration is required so the firewall can enforce Security policy on traffic crossing the virtual wire?. Assign IP addresses to both virtual-wire interfaces. Assign the virtual-wire interfaces to appropriate virtual-wire security zones. Enable a dynamic routing protocol on both interfaces. Add both interfaces to a Layer 2 VLAN. An administrator wants the firewall management web service to reject obsolete TLS versions. Which PAN-OS object controls the allowed TLS protocol versions for that service?. Interface Management Profile. SSL/TLS Service Profile. Decryption Profile. Certificate Profile. Which HA link is responsible for synchronizing session state and other dataplane state between peers?. HA1. HA2. HA3. The dedicated management interface. In the PAN-OS XML API, what does the request parameter type=config indicate?. Generate a new API key. Run an operational-mode command. Read or modify configuration data using configuration actions. Export a packet capture or certificate. What is the core function of a PAN-OS virtual router?. Perform content inspection. Store security logs. Maintain routing information and perform Layer 3 route lookups. Distribute GlobalProtect client software. Which three dynamic routing protocols are supported on a classic PAN-OS virtual router? (Choose three.). RIP. BGP. OSPF. EIGRP. When a routed packet first enters a PAN-OS Layer 3 interface, which configuration determines the routing table used for the initial route lookup?. The destination security zone. The egress interface management profile. The source user group. The virtual router assigned to the ingress interface. What is the purpose of the OSPF Router ID on a PAN-OS firewall?. Uniquely identify the router within the OSPF domain. Encrypt OSPF hello packets. Set the metric for all learned routes. Select the Ethernet interface speed. What topology condition makes a PAN-OS OSPF router an Area Border Router (ABR)?. It runs BGP and OSPF simultaneously. It owns the numerically highest Router ID. It participates in the OSPF backbone Area 0 and at least one additional OSPF area. It uses a tunnel interface for every neighbor. An organization wants a PAN-OS log event to invoke an external HTTPS endpoint/webhook. Which feature is designed for this?. A static route with path monitoring. An SNMP polling profile. A service route by itself. A Log Forwarding Profile using an HTTP Server Profile destination. During VM-Series bootstrap onboarding to Panorama, which bootstrap file carries initial parameters such as Panorama server information and bootstrap/onboarding values?. license.key. init-cfg.txt. running-config.xml only. ha-state.dat. Which two types of content are valid components of a VM-Series bootstrap package? (Choose two.). init-cfg.txt. Endpoint hardware drivers. A binary User-ID database. A PAN-OS software image in the supported bootstrap structure. In a Panorama design with heavy centralized logging, what component can be used to offload log storage/processing and forwarding duties from individual firewalls?. An HA3 link. A GlobalProtect portal. Dedicated Panorama Log Collectors. A virtual-wire interface pair. In BGP route selection on PAN-OS, which attribute is commonly used inside an autonomous system to prefer one outbound exit over another, with the higher value preferred?. MED. Local Preference. OSPF cost. Route tag. How are Panorama pre-rules, locally defined firewall rules, and Panorama post-rules ordered during Security policy evaluation on a managed firewall?. Pre-rules first, local rules next, post-rules last. Local rules first, then post-rules, then pre-rules. Post-rules first, pre-rules second, local rules last. All three groups are merged alphabetically by rule name. Which PAN-OS XML API request type is used when a script needs to export a configuration file or another supported file from a firewall?. type=op. type=config. type=export. type=user-id. Which two conditions are fundamental to establishing a standard external BGP peering session? (Choose two.). Matching OSPF area IDs. IP connectivity that permits the BGP TCP session. Correctly configured peer autonomous-system information. Matching interface descriptions. When an automation script targets a specific configuration object through the XML API, which three pieces of information are commonly used to describe the target and the change? (Choose three.). The object location/context such as vsys, device group, or template. The XML element containing the value to apply. An SNMP community hash. An XPath identifying the configuration node. An XML API edit against Panorama returns an "Invalid Object" error even though the object is visible in the GUI. The API key is valid. What should be checked first?. Whether NTP is enabled on the firewall. Whether the XPath includes the correct device-group, template, or vsys hierarchy for that object. Whether the firewall has an HA3 interface. Whether DNS Security is licensed. An automation platform must centrally issue API operations for multiple firewalls already managed by Panorama. Which management endpoint is normally the most appropriate central API target?. A Log Collector only. The HA2 address of each firewall. A GlobalProtect gateway. The Panorama management server. What transport is normally used for PAN-OS XML API requests to a firewall or Panorama management interface?. FTP on TCP/21. SSH subsystem on TCP/22 only. Plain HTTP on TCP/80 only. HTTPS, normally TCP/443. Which two Palo Alto Networks management APIs can be used to programmatically modify supported NGFW configuration and policy objects? (Choose two.). SNMP SET as the primary policy API. REST API. XML API. FTP control channel. What does the xpath parameter identify in a PAN-OS XML API configuration request?. The exact node/location in the XML configuration hierarchy. The API-key expiration time. The commit description. The TCP port used by the request. Which XML API request type should an automation script use to execute a PAN-OS operational-mode command such as a show command?. type=op. type=config. type=export. type=keygen. Which two actions are required for a Zone Protection Profile to protect a security zone? (Choose two.). Create a NAT rule for the zone. Apply the Zone Protection Profile to the zone. Assign the zone itself to an HA peer. Create/configure the Zone Protection Profile under the network profile settings. What happens to established sessions during an active/passive HA failover when session synchronization is operating correctly?. All sessions are always terminated. Only UDP sessions survive. Synchronized sessions can be maintained on the new active peer. The new active peer must send TCP resets before forwarding. In an active/passive HA pair with preemption enabled, what can occur after the higher-priority preferred firewall recovers?. The preferred firewall can automatically reclaim the active role after the preemption conditions/timer are met. Both firewalls permanently remain active. The recovered firewall deletes the peer configuration. The passive firewall disables all HA monitoring. What is a primary use of Panorama templates in centralized NGFW administration?. Replace all device groups and policy rulebases. Automatically install firewall hardware. Centrally define and consistently push Device and Network settings to managed firewalls. Store traffic logs instead of Log Collectors. A PAN-OS firewall reports a critical system event stating that a GRE tunnel interface is going down due to recursive routing. Which condition is the most likely cause?. The route to the GRE peer resolves through the GRE tunnel interface itself. GRE Keep Alive is disabled on the tunnel. The GRE tunnel is missing an IPSec Proxy ID. The physical interface carrying GRE does not have a Decryption Profile. A Panorama administrator has an address object named DNS-SERVICE defined as Shared = 172.16.10.10, Americas = 172.16.20.20, and US-East = 172.16.30.30. The US-East device group is a child of Americas. The administrator enables "Objects defined in ancestors will take higher precedence" and pushes the device-group configuration. Which value will the US-East firewall use for DNS-SERVICE?. 172.16.30.30 from the US-East device group. 172.16.20.20 from the Americas device group. 172.16.10.10 from Shared. The push fails because duplicate object names are never allowed in a device-group hierarchy. An authentication sequence contains an LDAP authentication profile followed by a RADIUS authentication profile. "Exit the sequence on failed authentication" is enabled. The LDAP server is reachable and returns an authentication failure because the user entered an incorrect password. What does the firewall do next?. It immediately tries the RADIUS authentication profile. It ends the authentication sequence and denies the authentication attempt. It retries the LDAP server until the server times out. It skips both profiles and falls back automatically to the local administrator database. Two PA-Series firewalls operate as an active/passive HA pair using a dedicated HA1 control link. Heartbeat Backup is enabled and the management interfaces can route to each other. The HA1 link fails, but both firewalls and their management paths remain operational. What is the expected behavior?. The passive firewall immediately becomes active because any HA1 failure always triggers promotion. The pair can continue exchanging heartbeat and hello messages over the management path, helping prevent split brain. HA2 becomes the control link and begins carrying all HA1 hello and heartbeat traffic. Both firewalls suspend because Heartbeat Backup is used only for software upgrades. A certificate profile has both Use OCSP and Use CRL enabled and also has "Block sessions if certificate status cannot be retrieved within timeout" selected. During authentication, the OCSP responder is unavailable and the firewall cannot retrieve a usable CRL before the configured certificate-status timeout. What is the expected result?. The firewall trusts the certificate because the issuing root CA is already trusted. The firewall disables revocation checking for this session and permits access. The firewall blocks the session after the certificate-status retrieval timeout. The firewall converts the certificate authentication attempt to password authentication. An engineer must use two physical links as one LACP bundle while carrying VLAN 100 and VLAN 200 to a Palo Alto Networks firewall. The firewall must route both VLANs and apply different Security policies to them. Which design best meets the requirement?. Create a Layer 3 Aggregate Ethernet interface, add tagged Layer 3 subinterfaces for VLAN 100 and VLAN 200, and assign each subinterface to the required routing context and security zone. Create one Layer 2 Aggregate Ethernet interface and place both VLANs in the same security zone without any Layer 3 interfaces. Configure the two member interfaces as independent Layer 3 interfaces with the same IP address and rely on LACP to merge their routing tables. Create a virtual wire between the two aggregate members and configure VLAN objects on the management interface. An active/active HA pair receives asymmetric first packets on both peers. The design goal is to minimize packet forwarding across HA3, distribute session-setup load, and have the firewall that owns a session perform Layer 7 inspection and generate the traffic logs. Which packet-forwarding settings best match these goals?. Session Owner: Primary Device; Session Setup: Primary Device. Session Owner: First Packet; Session Setup: IP Modulo. Session Owner: Primary Device; Session Setup: First Packet. Session Owner: First Packet; Session Setup: Primary Device. A firewall has Layer 3 interfaces ethernet1/2 and ethernet1/3 connecting two internal server networks that share the same trust level and should use the same security-policy treatment. ethernet1/4 connects a restricted partner network that requires a different policy boundary. How should the interfaces be assigned to security zones?. Place ethernet1/2, ethernet1/3, and ethernet1/4 in the same zone because all three are Layer 3 interfaces. Place ethernet1/2 and ethernet1/3 in the same zone and place ethernet1/4 in a different zone. Place every Layer 3 interface in a unique zone because PAN-OS allows only one interface per zone. Do not assign ethernet1/2 or ethernet1/3 to zones; assign only the Internet-facing interface to a zone. A PAN-OS virtual router has a static route for 10.40.0.0/16 with administrative distance 10 and a BGP route for 10.40.25.0/24 with administrative distance 20. Both routes are active and their next hops are reachable. Which route is used for traffic destined to 10.40.25.50?. The static 10.40.0.0/16 route because its administrative distance is lower. The BGP 10.40.25.0/24 route because it is the more specific longest-prefix match. Both routes are load-balanced because they overlap. The firewall drops the traffic because routes learned from different sources cannot overlap. |





