TestHUSTLE
|
|
Título del Test:
![]() TestHUSTLE Descripción: Practica Hustle |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Which layer of the OSI model is responsible for routing?. Layer 2. Layer 3. Layer 4. Layer 7. At which layer does a standard physical switch primarily operate?. Layer 1. Layer 2. Layer 3. Layer 4. What is the PDU (Protocol Data Unit) for Layer 4?. Bits. Frames. Packets. Segments. Which layer handles encryption and formatting (e.g., JPEG, ASCII)?. Application. Presentation. Session. Transport. What is the PDU for Layer 2?. Packets. Segments. Frames. Bits. Which layer is responsible for end-to-end error recovery and flow control?. Network. Data Link. Transport. Physical. HTTP, FTP, and SSH operate at which layer?. Layer 4. Layer 5. Layer 6. Layer 7. What does the "Session" layer (Layer 5) do?. Routes packets. Encrypts data. Manages connections between applications. Defines cable types. Which device is considered a Layer 1 device?. Router. Switch. Hub. Firewall. What is the primary difference between the OSI model and the TCP/IP model?. OSI has 4 layers, TCP/IP has 7. OSI is a reference model; TCP/IP is the practical implementation. OSI does not have a Network layer. TCP/IP is only for Apple devices. What is the destination MAC address for an ARP Request?. 00:00:00:00:00:00. FF:FF:FF:FF:FF:FF. 255.255.255.255. The Router’s MAC. Which protocol prevents loops in a Layer 2 switched network?. OSPF. BGP. STP (Spanning Tree Protocol). ARP. What is a "Native VLAN"?. A VLAN for encrypted traffic. The default VLAN for untagged traffic on a trunk port. A VLAN that cannot be deleted. The VLAN used only for voice traffic. What is the difference between an Access Port and a Trunk Port?. Access carries one VLAN; Trunk carries multiple. Access is for routers; Trunk is for PCs. Access tags traffic; Trunk does not. Trunk is only for fiber cables. What does a Switch do if it receives a frame for a MAC address not in its CAM table?. Drops it. Floods it to all ports except the source. Sends it to the Router. Resets the connection. What is "Proxy ARP"?. Hiding a MAC address. A router answering ARP for a host on another subnet. A server assigning IP addresses. A switch blocking ARP traffic. What is the purpose of a Gratuitous ARP (GARP)?. To request a new IP. To update other devices' ARP tables without being asked. To encrypt ARP traffic. To find the DNS server. Which IEEE standard defines VLAN Tagging (Trunking)?. 802.11. 802.3. 802.1Q. 802.1X. What is a "Collision Domain"?. The range of a Wi-Fi signal. A group of devices where packets could physically collide. The set of devices receiving a broadcast. A logical group of users. What is "Link Aggregation" (LACP/LAG) used for?. To encrypt cables. To combine multiple physical links into one logical link for bandwidth/redundancy. To separate VLANs. To block viruses. What is the typical aging time for a MAC address in a switch table?. 5 seconds. 300 seconds. 1 hour. Indefinite. What does VTP stand for?. Virtual Trunking Protocol. Voice Transfer Protocol. Virtual Terminal Process. Verified Tunnel Path. What is a "Broadcast Storm"?. A type of weather. An endless loop of broadcast frames that crashes a network. A high-speed data transfer. A security feature. Which device breaks up a Broadcast Domain?. Hub. Switch. Router. Bridge. What is a "Sub-interface" on a router?. A physical port. A logical interface used for inter-VLAN routing (Router-on-a-stick). A backup power supply. A wireless antenna. What is the size of an IPv4 address?. 32 bits. 64 bits. 128 bits. 48 bits. What is the size of an IPv4 address?. 32 bits. 64 bits. 128 bits. 48 bits. What is the size of an IPv6 address?. 32 bits. 64 bits. 128 bits. 256 bits. What does the "TTL" field in the IP header do?. Sets the speed of the packet. Prevents infinite routing loops. Identifies the sender. Encrypts the payload. Which ICMP message does a Ping command use?. Time Exceeded. Destination Unreachable. Echo Request. Redirect. What is the "DF" bit in an IP header?. Data Flow. Don't Fragment. Destination Final. Dual Frequency. Who reassembles IP fragments?. The first router. The last router. The destination host. The ISP. What is the range of Class C private IP addresses?. 10.0.0.0 - 10.255.255.255. 172.16.0.0 - 172.31.255.255. 192.168.0.0 - 192.168.255.255. 127.0.0.0 - 127.255.255.255. What is the loopback IP address for IPv4?. 0.0.0.0. 255.255.255.255. 127.0.0.1. 1.1.1.1. What is the purpose of a "Default Gateway"?. To connect to the local printer. The IP address used to send traffic outside the local subnet. A security password. The address of the switch. Which protocol translates Private IPs to one Public IP?. ARP. NAT (PAT). DNS. DHCP. What is the MTU (Maximum Transmission Unit) for standard Ethernet?. 512 bytes. 1460 bytes. 1500 bytes. 9000 bytes. What is a "Jumbo Frame"?. A frame over 1500 bytes. A very small frame. An encrypted frame. A frame used only for video. Which ICMP code indicates "Communication Administratively Prohibited" (blocked by firewall)?. Type 3, Code 1. Type 3, Code 13. Type 0. Type 11. What happens in an "ICMP Redirect"?. A router tells a host to use a better gateway for a specific destination. The ping is sent to a different server. The firewall blocks the traffic. The IP address changes. How many bits are in a Subnet Mask?. 16. 24. 32. 48. Is TCP connection-oriented or connectionless?. Connectionless. Connection-oriented. Which protocol is used for DNS queries (usually)?. TCP. UDP. ICMP. ARP. What is the TCP 3-way handshake sequence?. SYN, ACK, FIN. SYN, SYN-ACK, ACK. SYN, PUSH, ACK. FIN, ACK, FIN. What does the "Window Size" in TCP represent?. The speed of the link. Amount of data sent before an ACK is required. The number of open ports. The size of the computer screen. What is the purpose of the TCP "FIN" flag?. To start a connection. To reset a connection. To gracefully close a connection. To prioritize data. Which flag is used to force-close a TCP connection?. FIN. RST (Reset). SYN. PUSH. What is the TCP port for HTTPS?. 80. 22. 443. 53. What is the TCP port for SSH?. 21. 22. 23. 25. What is the UDP port for DHCP Server?. 67. 68. 53. 123. What is "Sequence Numbering" in TCP?. A way to count packets. Ensuring packets are reassembled in the correct order. A security password. A way to label the router. What is "SACK" (Selective Acknowledgment)?. A way to acknowledge specific missing segments. A type of encryption. A faster handshake. A UDP feature. What is the MSS (Maximum Segment Size)?. MTU minus IP/TCP headers. The size of the whole packet. The speed of the CPU. The number of hops. Which protocol would you use for Live Streaming video?. TCP. UDP. ICMP. SSH. What is the "Keep-alive" timer in TCP?. A timer to close the connection. A packet sent to verify the other side is still there. A way to speed up data. A license check. What does the "PUSH" (PSH) flag do?. Tells the receiver to process data immediately without waiting for the buffer to fill. Forces a disconnect. Encrypts the segment. Increases the window size. What is the Administrative Distance of OSPF?. 90. 100. 110. 120. What is the AD of a Static Route?. 0. 1. 5. 20. What is "Area 0" in OSPF?. The testing area. The Backbone Area. The last area. An area for printers. Which BGP attribute is checked first (on Cisco)?. AS-Path. MED. Weight. Local Preference. OSPF uses which algorithm to calculate the best path?. Bellman-Ford. DUAL. Dijkstra (SPF). Recursive. BGP runs over which port?. UDP 500. TCP 179. TCP 443. UDP 179. What is an OSPF "Hello" packet used for?. To send the whole database. To find neighbors and keep adjacencies. To reset the router. To ping the internet. What is an "ASBR" in OSPF?. Area Sub Router. Autonomous System Boundary Router (connects to other protocols). Always Backup Router. A type of cable. In BGP, what does "AS-Path" represent?. The speed of the path. The list of Autonomous Systems a route has passed through. The name of the router. The number of hops. What is the difference between eBGP and iBGP?. eBGP is internal; iBGP is external. eBGP is between different AS; iBGP is within the same AS. iBGP doesn't use TCP. eBGP is slower. What is an OSPF "Stub Area"?. An area with only one exit. An area that doesn't accept external routes (Type 5 LSAs). A broken area. A wireless area. What is the OSPF metric called?. Hops. Bandwidth. Cost. Delay. BGP is what type of protocol?. Link-state. Distance-vector. Path-vector. Static. What does the "MED" attribute in BGP stand for?. Medium Entry Device. Multi-Exit Discriminator. Most Effective Data. Manual Entry Delay. What is an "OSPF Router ID"?. The router's name. A 32-bit unique identifier (usually highest loopback IP). The serial number. The admin's username. How many messages in IKEv1 Phase 1 Main Mode?. 3. 4. 6. 9. How many messages in IKEv1 Phase 1 Aggressive Mode?. 3. 6. 4. 2. What is the purpose of Phase 1 of IPsec?. To send data. To establish a secure management tunnel (ISAKMP SA). To encrypt the internet. To verify the password. What is the purpose of Phase 2?. To negotiate data SAs for actual traffic. To find the neighbor. To reset the connection. To download updates. What is "NAT-Traversal" (NAT-T)?. A way to bypass NAT. Encapsulating IPsec in UDP 4500 to pass through NAT devices. A type of routing. A wireless feature. Which port does IKE use by default?. TCP 443. UDP 500. UDP 4500. TCP 22. What is "Diffie-Hellman" used for?. Hashing. Secure key exchange. Encryption. Routing. What is the difference between ESP and AH?. ESP provides encryption; AH only provides integrity/authentication. AH provides encryption; ESP does not. They are the same. ESP is only for Cisco. What is "Tunnel Mode" in IPsec?. Encrypts only the payload. Encrypts the entire packet and adds a new IP header. Does not use encryption. Only for mobile users. What is "Transport Mode"?. Encrypts only the payload, keeps original IP header. For hub-to-hub. Only for fiber. Slower than Tunnel mode. What does a "Security Association" (SA) contain?. The user's name. Encryption keys and algorithms for a tunnel. The router's password. A list of websites. What is "PFS" (Perfect Forward Secrecy)?. A strong password. Ensuring that if one key is compromised, future keys are still safe. A type of cable. A firewall rule. How many messages in the IKEv2 handshake?. 6. 3. 4. 2. What is a "Dead Peer Detection" (DPD)?. A way to delete users. A mechanism to check if the VPN tunnel is still up. A hardware failure. A log entry. Which hashing algorithm is considered insecure today?. SHA-256. MD5. SHA-512. AES. Who sends the Digital Certificate in an SSL handshake?. Client. Server. Router. ISP. How does the client verify a certificate?. It asks the admin. It checks the signature against a trusted CA (Certificate Authority). It pings the server. It restarts the browser. What is a "Public Key"?. A key everyone can see used to encrypt data. A secret key used to decrypt. A door key. The login password. What is a "Private Key"?. Shared with everyone. Kept secret by the server to decrypt data. Printed on the certificate. A backup key. What does HTTPS use to secure traffic?. ARP. SSL/TLS. IPsec. BGP. What is a "CSR"?. Customer Service Representative. Certificate Signing Request. Central Security Router. Cloud Storage Rule. What is "SSL Decryption" (Forward Proxy) on a firewall?. Turning off encryption. The firewall acting as a "man-in-the-middle" to inspect encrypted traffic. A virus. Hacking the server. What is a "Self-Signed Certificate"?. A certificate signed by a CA. A certificate signed by the entity itself (not trusted by default). A fake certificate. An expired certificate. What is "OCSP"?. Online Certificate Status Protocol (checks if a cert is revoked). A type of VPN. A routing protocol. A cloud service. What is the current secure version of TLS?. SSL 3.0. TLS 1.0. TLS 1.2 / 1.3. TLS 4.0. What is a "Stateful" Firewall?. Remembers the state of connections. Only blocks ports. Only for Layer 2. A firewall that never restarts. What is "App-ID"?. A user’s ID badge. Palo Alto Networks technology that identifies applications regardless of port. An iPhone app. A serial number. What is "User-ID"?. A username/password. Linking IP addresses to specific users for policy enforcement. A security camera. The admin account. What is "Content-ID"?. The size of a file. Inspecting traffic for threats, vulnerabilities, and data patterns (DLP). The name of a website. A type of memory. What is the "Management Plane" on a Palo Alto Firewall?. Where traffic is processed. Where the UI, CLI, and logging are handled. The power supply. The fans. What is the "Data Plane"?. Where you log in. Specialized hardware that processes network traffic (Security, Signature match). A backup cloud. The documentation. What is "Active-Passive" High Availability (HA)?. Both firewalls work. One firewall works, one stays in standby. Neither firewall works. Both are standby. What is a "Security Zone"?. A physical room. A logical grouping of interfaces (e.g., Trust, Untrust). A password. A country. What is an "Implicit Deny" rule?. Allowing everything. The rule at the bottom that drops all traffic not explicitly allowed. A rule that alerts the admin. A rule for printers. What is "Panorama"?. A wide photo. Palo Alto Networks' centralized management platform for multiple firewalls. A type of VPN. A routing protocol. What is "WildFire"?. A forest fire. Palo Alto Networks' cloud-based malware analysis sandbox. A fast router. A Wi-Fi name. What is a "Virtual System" (vsys)?. A virtual machine. A logical partition of a physical firewall into multiple independent firewalls. A cloud storage. A software update. What is "NAT Policy" in PAN-OS?. A security rule. A separate set of rules that define how IP addresses are translated. A routing table. A list of users. What is "Policy Based Forwarding" (PBF)?. Standard routing. Routing traffic based on application, user, or service rather than just destination IP. Blocking traffic. A backup plan. What is the default IP for a new Palo Alto Management interface?. 192.168.1.1. 192.168.1.254. 192.168.1.20. 10.0.0.1. What does "ION" stand for?. Internet On Network. Instant-On Network. Internal Office Node. Integrated Operational Network. Prisma SD-WAN is "Application Defined." What does this mean?. You have to code it. It makes routing decisions based on Layer 7 apps and their performance. It only works for mobile apps. It is very cheap. What is "Direct Internet Access" (DIA)?. Going through the HQ. Branch offices connecting directly to the internet locally. Using a modem. No firewall. What is "Path Health Monitoring"?. Counting packets. Measuring latency, jitter, and loss on a WAN link to ensure app performance. Checking the cable. A security scan. What is a "CloudBlade"?. A sharp cloud. An API-based integration platform for Prisma SD-WAN to connect to other services (like Prisma Access). A type of hard drive. A software version. Traditional SD-WAN is packet-based. Prisma SD-WAN is: Byte-based. Session-based. Hardware-based. Manual. What is "Dynamic Path Selection"?. Changing the cable. Moving a traffic session to a better link if the current one degrades. Turning off the link. Blocking the link. Which component manages the ION devices centrally?. The ION itself. The Prisma SD-WAN Controller (Cloud). Panorama. The PC. What is the benefit of SD-WAN over MPLS?. Lower cost and better cloud performance. Higher cost. Harder to manage. Only for fiber. What is an "AppFabric"?. A piece of clothing. The secure, logical overlay network created between ION devices. A database. A data center. What does CASB stand for?. Cloud Access Security Broker. Central App Security Board. Computer Access System Backup. Cloud Audit Security Base. What is "Shadow IT"?. Dark mode. SaaS apps used by employees without IT's approval. Hacking. Working at night. What is "Data-at-Rest" scanning in CASB?. Scanning traffic live. Using APIs to scan files already stored in the cloud (e.g., Google Drive). Scanning the hard drive. Scanning printers. What is "Data-in-Motion" scanning?. Scanning files in cloud storage. Inspecting traffic as it flows to/from the cloud app. Scanning a moving car. Scanning USB drives. What is "DLP" (Data Loss Prevention)?. Preventing hard drive failure. Identifying and blocking sensitive data (SSNs, Credit Cards) from leaving the network. Backing up data. Encrypting data. What is a "Sanctioned App"?. A blocked app. An app officially approved by the company (e.g., Office 365). A virus. A game. Next-Gen CASB by Palo Alto is integrated into: Only printers. Prisma Access and NGFW. Only Android phones. Windows 95. What is "SaaS Security Inline"?. API connection. Real-time visibility and control of SaaS apps through the firewall. A type of cable. A security badge. What is a "Public Cloud" example?. A company data center. AWS / Azure / GCP. A hard drive. A local switch. What is "SSPM"?. SaaS Security Posture Management (checking for cloud misconfigurations). A protocol. A type of firewall. A password. What is SASE?. A type of router. Secure Access Service Edge (Convergence of Network + Security in the cloud). A new firewall model. A software update. Prisma Access is Palo Alto’s: Cloud-delivered security platform (SASE). Smallest firewall. Antivirus software. Consulting service. What is a "Remote Network" in Prisma Access?. A home user. A branch office connected via IPsec tunnel. The internet. A server. What is a "Mobile User"?. Someone in the office. A user connecting via GlobalProtect from anywhere. A cell phone tower. A wireless mouse. What is "GlobalProtect"?. A map. The agent/client used to connect to Prisma Access or a local firewall. A web browser. A antivirus. What is "ZTNA 2.0"?. Zero Trust Network Access (Least privilege, continuous verification). A fast connection. A second router. A new Wi-Fi standard. What is "ADEM"?. A type of encryption. Autonomous Digital Experience Management (Monitors user experience/performance). An admin account. A cloud storage. What is a "Service Connection"?. A link to the internet. A tunnel connecting Prisma Access to a customer's Data Center/HQ. A technical support call. A power cord. Where does security inspection happen in Prisma Access?. On the user's laptop. In the cloud (Security Processing Nodes). At the local ISP. In the branch office. What is "Split Tunneling"?. Two VPNs at once. Sending some traffic to the VPN and some directly to the internet. A broken tunnel. Encrypting only half the data. What is the first step in troubleshooting a "down" VPN?. Restart the firewall. Check Layer 1/2 connectivity and logs for Phase 1. Delete the configuration. Call the ISP immediately. A customer says a website is blocked. Where do you look first?. Routing table. Traffic logs and Security Policy. CPU usage. The cable. What is the "Life of a Packet" in a Palo Alto Firewall?. A movie. The sequence of steps (Ingress, Slow Path, Fast Path, Content-ID, Egress). A sales pitch. A support ticket. What is a "Tech Support File"?. A manual. A comprehensive dump of logs and configuration for troubleshooting. A contact list. A software patch. If a customer complains of "slowness," what is the best tool in Prisma?. Antivirus. ADEM (to see where the latency is). GlobalProtect. NAT. What does a CSE do?. Just fixes bugs. Ensures the customer gets value and is successful with the product. Only sells new hardware. Codes the OS. How do you handle an angry customer?. Hang up. Listen, empathize, and show a clear path to resolution. Argue. Ignore them. What is a "BPA" (Best Practice Assessment)?. A test. A tool that reviews a customer's config against security best practices. A billing statement. A new firewall. What is "Strata Cloud Manager"?. A new cloud storage. Unified management for Firewalls, SD-WAN, and Prisma Access. A weather app. A Linux command. What is the difference between an "Incident" and a "Problem"?. No difference. Incident is a single event; Problem is the underlying cause of multiple incidents. Problem is more expensive. Incident is for Wi-Fi only. What is the standard port and protocol for DNS?. TCP 53. UDP 53. UDP 67. TCP 443. Which port does NTP (Network Time Protocol) use?. UDP 123. TCP 123. UDP 161. TCP 80. What is the standard port for SNMP (Simple Network Management Protocol)?. UDP 500. UDP 161. TCP 161. UDP 514. Which port is used by the Telnet protocol?. TCP 22. TCP 23. UDP 23. TCP 21. What is the control port for FTP (File Transfer Protocol)?. TCP 20. TCP 21. UDP 21. TCP 22. Which port does BGP (Border Gateway Protocol) use for peer communication?. UDP 179. TCP 179. TCP 110. UDP 500. What is the standard port for IKE (Internet Key Exchange) in VPNs?. UDP 4500. UDP 500. TCP 500. TCP 443. Which port is used for IPsec NAT-Traversal (NAT-T)?. UDP 500. UDP 4500. TCP 4500. IP Protocol 50. What is the default port used by the GlobalProtect agent to connect to the Portal/Gateway?. TCP 80. TCP 443. UDP 443. TCP 8080. What is the standard port for Syslog (logging)?. UDP 514. TCP 514. UDP 161. TCP 25. What is the primary purpose of a "Vulnerability Protection Profile"?. To block specific websites. To protect against exploit attempts such as buffer overflows and code execution. To identify users by name. To speed up the internet. Which profile protects a network against Command-and-Control (C2) traffic?. URL Filtering. Anti-Spyware Profile. File Blocking. QoS Profile. What is the function of "URL Filtering"?. To encrypt web traffic. To control access to websites based on their category (e.g., Social Media, Gambling). To change the IP address of a server. To block all HTTP traffic. What is the purpose of a "File Blocking Profile"?. To block all internet traffic. To prevent specific file types (like .exe or .zip) from being uploaded or downloaded. To delete files on the user's hard drive. To compress files for faster transfer. Which profile is used to detect and block PII (Personally Identifiable Information) like credit card numbers?. Vulnerability Profile. Data Filtering Profile. User-ID Profile. App-ID Profile. What does a "Log Forwarding Profile" do?. It deletes logs to save space. It defines which logs are sent to external destinations like Syslog or Panorama. It displays logs on the firewall dashboard. It encrypts the management interface. What is "QoS" (Quality of Service) used for?. To make all traffic faster. To prioritize critical traffic (like VoIP) over less important traffic (like file downloads). To block viruses. To assign IP addresses. What is "Netflow"?. A way to download files faster. A protocol for collecting and monitoring IP traffic flow information. A type of fiber optic cable. A Palo Alto antivirus feature. What is a "Packet Capture" (PCAP) used for?. To block traffic. To record raw network traffic for detailed troubleshooting and analysis. To speed up the CPU. To hide the IP address. Which software tool is most commonly used to analyze PCAP files?. Microsoft Word. Wireshark. Google Chrome. Photoshop. What is the "Ping of Death"?. A fast ping. A legacy DoS attack involving oversized ICMP packets. A successful connectivity test. A feature of Windows 11. What happens during a "SYN Flood" attack?. The server runs out of disk space. An attacker sends many SYN requests to overwhelm a server's connection table. The power goes out. The internet becomes faster. What is the "Anti-Replay" feature in IPsec?. It plays music during a VPN connection. It prevents attackers from capturing and resending valid packets to disrupt a session. It allows the VPN to stay up forever. It blocks YouTube. What is "Perfect Forward Secrecy" (PFS)?. A very long password. Ensuring that a compromise of one session key does not compromise past or future keys. Hiding the firewall from the internet. A type of physical lock. What is "Route Redistribution"?. Manually typing every route. Sharing routing information between different protocols (e.g., OSPF to BGP). Turning off the router. Changing the router's IP. Why would an administrator use "AS-Path Prepending" in BGP?. To speed up a route. To make a path look longer and less desirable to influence inbound traffic. To encrypt the BGP session. To hide the AS number. What is a "BGP Community"?. A group of network engineers. A tag used to group and apply policies to sets of BGP routes. A public chat room. A type of router hardware. What is the role of a "DHCP Relay"?. To assign IPs to local users. To forward DHCP requests from a client to a server on a different subnet. To block DHCP traffic. To act as a backup DNS server. In a VPN, what is the "Proxy-ID"?. The name of the admin. The definition of local and remote subnets that are allowed through the tunnel. The password for the VPN. The location of the firewall. What is "FIPS Mode"?. A fast internet mode. A high-security operational mode that meets US Federal security standards. A mode for gaming. A diagnostic mode for fans. What is "ZTP" (Zero Touch Provisioning)?. Fixing a firewall with no hands. Automatically provisioning and configuring a device when it connects to the network. A type of touch-screen monitor. A password-free login. What is the goal of "AIOps" in networking?. To replace all engineers with robots. Using AI and ML to proactively identify and resolve network and security issues. To make the UI look better. To lower the price of hardware. What is "Cortex XDR"?. A new firewall model. An Extended Detection and Response platform for endpoint, network, and cloud. A type of disk drive. A routing protocol. What is "Cortex XSOAR" used for?. To browse the web. Security Orchestration, Automation, and Response (automating security workflows). To store logs for 10 years. To build websites. What does "Prisma Cloud" focus on?. Home Wi-Fi. Securing cloud-native applications, workloads, and containers. Physical server maintenance. Office printers. What is "Micro-segmentation"?. Cutting a cable into small pieces. Applying granular security policies to individual workloads or servers (Zero Trust). Dividing a big office into small rooms. A type of subnetting. What is "SaaS"?. Software as a Service (e.g., Salesforce, Office 365). System as a Service. Security as a Software. Small and Simple. What is "IaaS"?. Internet as a Service. Infrastructure as a Service (e.g., AWS, Azure virtual machines). Internal as a Service. Integrated as a Service. What is "PaaS"?. Platform as a Service (e.g., Heroku, Google App Engine). Protocol as a Service. Password as a Service. Private as a Service. What is a "Hybrid Cloud"?. A cloud that produces rain. A combination of on-premises data centers and public cloud services. A cloud with two owners. A very fast cloud. What is "Multi-cloud"?. Using many different cloud providers (e.g., AWS and Azure). Having many users on one cloud. Using the cloud in many countries. A cloud with many layers. What is "Latency"?. The speed of the download. The time delay for data to travel from source to destination. The amount of data lost. The number of users. What is "Jitter"?. A nervous feeling. The variation or inconsistency in latency over time. A type of signal interference. The total bandwidth used. What is "Packet Loss"?. Data that is sent but never reaches the destination. Encrypted data. Data that is sent too fast. A small packet. What is "Bandwidth"?. The physical length of the cable. The maximum rate of data transfer across a network path. The number of routers in a path. The cost of the internet. What is "Throughput"?. The maximum possible speed. The actual amount of data successfully transferred over time. The time it takes to boot a router. The number of ports on a switch. What is "Full Duplex"?. Communicating in only one direction. Simultaneous two-way communication. One person talking at a time. A type of double-sized packet. What is a "Broadcast" message?. One-to-one communication. One-to-all communication (sent to everyone on the subnet). One-to-many communication. Communication to the internet. What is "Multicast" communication?. One-to-one. One-to-a specific group of interested receivers. All-to-all. One-to-none. What is "Unicast"?. One-to-all. One-to-one (single source to single destination). One-to-many. A type of radio wave. A customer reports that their "GlobalProtect" users can access the Internet but cannot reach the internal Data Center. Where is the first place you check?. The user's home router. The Security Policy and the "Service Connection" status in Prisma Access. The ISP's DNS settings. The laptop's battery level. What is the "Slow Path" in Palo Alto Networks packet processing?. When the firewall is broken. The initial packet of a session where the firewall performs Layer 7 identification (App-ID) and policy lookup. Traffic sent over a slow satellite link. The management interface traffic. A customer is seeing "Asymmetric Routing" issues after installing a firewall. What does this mean?. The packets are too large. The traffic takes one path to the destination but returns via a different path/firewall, causing the stateful firewall to drop it. The router is using OSPF and BGP at the same time. The firewall is in Active-Passive mode. How does "App-ID" handle an application that starts on Port 80 but then changes its behavior?. It blocks it immediately. It continuously shifts the identification as the content changes until it finds a match. It ignores it after the first packet. it asks the admin for permission. What is the benefit of "Single-Pass Parallel Processing" (SP3) Architecture?. It makes the firewall cheaper. It performs networking, security, and content inspection all at once in a single pass, reducing latency. It allows two admins to log in at the same time. It only works for VPN traffic. If a customer wants to block "Facebook" but allow "Facebook Messenger," how does Palo Alto handle this?. It is impossible. App-ID recognizes sub-applications, allowing granular control within the same platform. You have to block the IP addresses of Facebook. You must use a special cable. What is the "Predictive Analysis" engine in DNS Security used for?. To guess what the user will type next. To identify and block DGA (Domain Generation Algorithms) used by malware for Command & Control. To speed up Google searches. To count how many users are online. In a "SASE" architecture, what is "ZTP" and how does it help a CSE?. Zero Trust Protocol; it blocks all users. Zero Touch Provisioning; it allows a customer to ship a device to a branch and have it configure itself automatically via the cloud. Zone Transfer Process; for DNS. A type of encrypted file. A customer’s BGP peering is "Established," but they aren't receiving routes. What is a common cause?. The password is wrong. A BGP Import Policy or Filter is blocking the routes. The router is too hot. BGP only works for IPv6. What is the difference between "Destination NAT" and "Policy-Based Forwarding"?. They are the same. DNAT changes the destination IP; PBF changes the egress interface (the "exit") based on specific criteria. PBF is only for hackers. DNAT is only for outbound traffic. What is "Egress Filtering"?. Blocking traffic coming into the network. Monitoring and restricting traffic leaving the internal network to the internet. A type of physical filter for dust. Only used for email. Why would a customer use "SSO" (Single Sign-On) with GlobalProtect?. To make it harder to log in. To provide a seamless user experience where the user logs in once to their PC and is automatically connected to the VPN. To save electricity. To bypass the firewall. What is "East-West" traffic?. Traffic between the US and Europe. Network traffic moving laterally within a data center (between servers). Traffic from a user to the internet. Traffic from a branch to a hub. What is "North-South" traffic?. Traffic between the Data Center and the Internet. Traffic between two local switches. Traffic on a vertical cable. Traffic only for mobile users. A customer wants to use "SSL Inbound Inspection." What do they need?. The private key of the internal server. The public key of Google. A new internet provider. To disable their antivirus. What is the "Strata Logging Service" (SLS)?. A paper notebook for the admin. A cloud-based central repository for all logs from firewalls and Prisma Access. A way to delete old logs. A type of VPN. In OSPF, what is a "DR" (Designated Router) and why is it elected?. To act as the boss of the network. To reduce the number of adjacencies and LSA flooding on multi-access segments (like Ethernet). To handle all the encryption. Because it has the most RAM. What is a "FQDN Address Object"?. A static IP address. An object that resolves a domain name (like *.google.com) to IPs, allowing policies to follow dynamic IP changes. A fast routing protocol. A type of user account. What is "Device-ID" in Palo Alto Networks?. The serial number of the firewall. A feature that identifies the specific device type (e.g., iPhone, IoT camera) to apply granular policies. A barcode. A login password. What is "SaaS Security API" vs "SaaS Security Inline"?. API scans the cloud storage; Inline inspects the live traffic. Inline is for email; API is for web. They are the same product. One is for AWS, one is for Azure. What is "Autonomous DEM" (ADEM)?. A robot that fixes the network. Real-time synthetic testing that monitors the path from a user's device to the application, isolating where "slowness" is happening. A new type of firewall. An automatic update service. What is "GlobalProtect Internal Gateway"?. A way to connect to the office from home. A way to apply security policies to users inside the office based on their GlobalProtect identity. A router for the basement. A type of Wi-Fi. What is "Certificate Pinning"?. Sticking a certificate to a wall. A security technique where an app only trusts a specific, hardcoded certificate, which can break SSL Decryption. A way to share passwords. A routing feature. A customer is getting a "Certificate Expired" error on their VPN. What is the fix?. Buy a new firewall. Renew the certificate on the Firewall/Portal and update the Root CA if necessary. Tell the users to ignore the error. Restart the internet. What is "Data Masking" in DLP?. Hiding the data from hackers. Obscuring sensitive data (like showing only the last 4 digits of a Credit Card) in logs to protect privacy. Deleting the data. Changing the font of the data. What is a "HIP Check" (Host Information Profile) used for?. To check the speed of the user's internet connection. To verify the security posture of an endpoint (e.g., checking for antivirus, disk encryption, or OS patches) before allowing access. To identify the user's geographical location. To assign a new IP address to a mobile user. What is the primary function of a "User-ID Agent"?. To block users from accessing social media. To monitor the firewall's CPU usage. To pull user login information from sources like Active Directory to map IP addresses to specific usernames. To reset user passwords automatically. What is a "Captive Portal"?. A physical room for servers. A web-based authentication page that users must complete before being granted network access. A type of encrypted tunnel for site-to-site VPNs. A backup management interface. What is the purpose of the "App-ID Cache"?. To store downloaded files from the internet. To store identification results for known applications, speeding up the processing of subsequent packets in a session. To keep a record of all deleted security rules. To save energy on the data plane hardware. What is an "External Dynamic List" (EDL)?. A list of all employees in the company. A text file hosted on an external web server that the firewall automatically retrieves to update blocklists (IPs, URLs, or Domains). A list of all available Wi-Fi networks. A backup of the routing table. What is "Sinkholing" in the context of DNS Security?. Deleting the DNS server's database. Redirecting malicious DNS queries to a safe, controlled IP address to identify infected internal hosts. A physical failure of a data center. Encrypting all DNS traffic. What does a "Zone Protection Profile" protect against?. User login failures. Flood attacks (SYN, UDP, ICMP) and reconnaissance attempts like port scans at the ingress interface level. Outdated software versions. High electricity costs. What is the main function of a "DoS Protection Policy"?. To speed up the firewall's boot time. To limit the number of concurrent sessions or the rate of new sessions allowed for specific source or destination IPs. To provide antivirus updates. To monitor the temperature of the router. What is the "Packet Diagnostics" (Packet Diag) tool in the CLI used for?. To change the admin password. To track exactly how a specific packet is handled as it moves through each stage of the firewall's internal processing. To test the speed of the fiber optic cables. To generate a billing report. In PAN-OS, what does the "Commit" action do?. It deletes the current configuration. It takes all changes from the "Candidate Config" and applies them to the "Running Config" to make them active. It restarts the physical firewall hardware. It sends a support ticket to Palo Alto Networks. What is the "Candidate Config"?. A configuration that is ready to be deleted. The workspace containing all staged changes that have not yet been applied to the live system. The configuration used by a competitor's firewall. The default factory settings. What is the "Running Config"?. A configuration used for testing only. The active configuration currently being used by the firewall to process traffic. A configuration that makes the firewall run faster. The configuration stored in the cloud backup. What is "High Availability (HA) Lite"?. A free version of the firewall software. A simplified HA mode for smaller firewall models that provides configuration sync but not session state synchronization. An HA mode that only works during the day. A way to connect two firewalls via Wi-Fi. What is a "Config Audit"?. A financial review of the IT budget. A management tool used to compare the differences between two different configuration versions. A security scan for viruses. A way to count the number of ports used. What does the "Rule Usage" counter tell an administrator?. How much money the rule has saved. Whether a specific security policy rule has actually matched traffic and been triggered. The name of the person who created the rule. The time of day the rule was created. Why should a CSE look for "Unused Objects" in a customer's configuration?. To find hidden viruses. To clean up and optimize the configuration by identifying items (IPs, Services, Groups) that are not linked to any active policy. To see which users have left the company. To reduce the weight of the firewall. What is the "App-ID Cloud Engine"?. A way to host websites in the cloud. A cloud-based service that helps identify new or unknown applications that aren't yet in the local database. An email service for firewalls. A way to sync the firewall with a smartphone. What information is provided by "Prisma Access Insights"?. Personal information about mobile users. A comprehensive view of the operational health, performance, and status of the global SASE environment. The cost of the monthly subscription. A list of competitor products. What is the role of the "GlobalProtect Portal"?. To act as the main VPN tunnel. To manage authentication and provide the GlobalProtect client with the correct configuration and list of available Gateways. To host the company's public website. To block all mobile devices. What is the "GlobalProtect Gateway"?. A router in the user's home. The endpoint where the VPN tunnel terminates and security policies are actually enforced on the traffic. The website where users download the agent. A physical gate in the office. What is "MTU Path Discovery"?. A way to find the shortest path to a destination. A mechanism that automatically determines the largest packet size allowed along a network path to avoid fragmentation. A tool to find lost cables. A feature of the DNS protocol. What is the purpose of "MSS Clamping"?. To make the firewall physically smaller. To adjust the TCP segment size to ensure packets (including VPN headers) do not exceed the MTU of the path. To increase the speed of a CPU. To count the number of sessions. What is "BGP Multi-hop"?. A BGP session that uses multiple protocols. A configuration that allows BGP peering between two routers that are not directly connected (more than one hop away). A way to jump between different ISPs. A type of routing loop. What is "Route Summarization"?. A short description of a routing protocol. The process of advertising a single broad route (e.g., 10.0.0.0/8) to represent many smaller specific routes, saving router memory. Deleting unused routes. A list of all possible paths. How is "Success" defined for a Palo Alto Networks Customer Success Engineer (CSE)?. Closing as many support tickets as possible in one hour. Ensuring the customer is fully protected, their technical outcomes are met, and they are getting maximum value from the platform. Selling the customer more hardware every month. Memorizing all the CLI commands. |





