Courseiva

Certified Network Security Architect (NetSec-Architect) (NetSec-Architect) — Questions 151225

228 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQhard

An architect is deploying Prisma Access for users who require explicit proxy settings due to strict corporate network egress policies. How should the architect configure Prisma Access to support explicit proxy connections for mobile users?

A.Configure explicit proxy settings in the GlobalProtect app configuration in Panorama, specifying the Prisma Access explicit proxy IP and port.
B.Deploy an internal hardware firewall running PAN-OS in proxy mode and tunnel all traffic via IPsec to Prisma Access.
C.Enable explicit proxy mode inside the Decryption Profile attached to the mobile user security policy.
D.Modify the DNS proxy settings on the local branch router to resolve all explicit proxy requests to the local gateway.
AnswerA

Explicit proxy for Prisma Access mobile users is configured in the GlobalProtect app settings to direct traffic to Prisma Access proxy nodes.

Why this answer

Prisma Access supports explicit proxy for mobile users by configuring explicit proxy settings within the GlobalProtect client configuration and provisioning proxy listeners in the cloud.

152
MCQhard

An organization is implementing a Zero Trust architecture across their hybrid network. Workloads in Azure need to access a database hosted in an on-premises datacenter through a secured IPsec VPN tunnel terminated by VM-Series firewalls. To enforce granular application-layer controls (App-ID) instead of port-based controls, where must the security policy be applied?

A.On the VM-Series firewall security policy rules governing the hybrid VPN zone
B.On the on-premises core switch Spanning Tree Protocol configuration
C.Inside the operating system firewall of the Azure client workload
D.On Azure Network Security Groups (NSGs) applied to the database subnet
AnswerA

The VM-Series security policy evaluates App-ID, User-ID, and Content-ID across the VPN zone.

Why this answer

Security policies using App-ID must be enforced on the VM-Series firewalls inspecting the traffic traversing the hybrid boundary.

153
Multi-Selecthard

An architect is planning a large-scale Panorama deployment managing over 500 firewalls. To optimize performance and maintain high availability, which THREE operational best practices should be implemented? (Choose three)

Select 3 answers
A.Disable configuration backups to maximize available disk space for logging.
B.Design a clean, shallow hierarchical Device Group and Template structure to minimize commit evaluation complexity.
C.Deploy Dedicated Log Collectors to offload log processing and storage from the Panorama management appliances.
D.Implement Panorama High Availability (HA) to provide automatic failover of the management plane.
E.Combine Panorama management and log collection onto a single virtual appliance to reduce server footprint.
AnswersB, C, D

Avoiding overly deep nested hierarchies reduces configuration evaluation overhead during commits.

Why this answer

Best practices for scaling Panorama include separating management and logging functions with Dedicated Log Collectors, utilizing Panorama HA, and structuring device groups hierarchically.

154
MCQmedium

An architect is troubleshooting log forwarding issues between a managed firewall and a Panorama Dedicated Log Collector. The firewall's system logs indicate that log forwarding connections are failing authentication. Where should the architect verify or reset the communication secret between the firewall and Panorama?

A.Device > High Availability > Control Link
B.Device > Setup > Management > SSL/TLS Service Profile
C.Panorama > Log Collectors > Collector Group Settings
D.Panorama > Managed Devices > Summary, where a new auth-key can be generated and applied to the firewall.
AnswerD

Auth-keys are generated in Panorama under Managed Devices and entered on the firewall via CLI or WebUI to establish trust.

Why this answer

The communication between firewalls and Panorama/Log Collectors is secured via a registration auth-key generated in Panorama and applied to the firewall.

155
MCQeasy

A Prisma SD-WAN architect is setting up branch clustering for high availability at a regional office. How are the Prisma SD-WAN ION devices deployed to achieve high availability at the branch?

A.Deployed as an active-standby or active-active pair connected via HA links, managed centrally by Prisma SD-WAN controller.
B.Configured with Panorama High Availability primary and secondary peer settings.
C.Configured as an active-active cluster using OSPF routing directly to GlobalProtect gateways.
D.Configured using traditional PAN-OS High Availability cable pairings between control planes.
AnswerA

Prisma SD-WAN supports high availability clustering of ION devices at branch locations for redundancy.

Why this answer

Prisma SD-WAN ION devices support High Availability (HA) deployments where two ION devices are deployed locally in an active-standby or active-active configuration depending on the interface design.

156
MCQhard

An architect is planning a log collection architecture using Panorama Dedicated Log Collectors. The design requires compliance log retention for 3 years, exceeding the local disk capacity of a single log collector. How should the architect design the log storage architecture to scale log retention capacity?

A.Configure a Collector Group containing multiple Log Collectors to pool storage capacity and distribute log indexing load.
B.Configure Panorama to automatically compress all logs into ZIP format and email them daily to an archive mailbox.
C.Attach external NFS network shares directly to Panorama's management plane via the CLI.
D.Enable Panorama RAID-0 disk striping across all managed firewalls.
AnswerA

Log Collector Groups aggregate storage across multiple collectors, allowing horizontal scaling of log retention and query performance.

Why this answer

Collector Groups allow administrators to pool multiple Log Collectors together. Firewalls forward logs to the Collector Group, which distributes and indexes the logs across the member collectors, scaling total retention capacity.

157
Multi-Selecthard

An enterprise security architect is implementing data security architecture using Enterprise DLP and SaaS Security. Which THREE enforcement actions can be triggered when Enterprise DLP detects a policy violation? (Choose three)

Select 3 answers
A.Block the transaction (e.g., reset the TCP connection or block the file upload).
B.Perform an automated BIOS flash on the switch fabric.
C.Automatically re-image the endpoint operating system via Cloud Identity Engine.
D.Quarantine the file in SaaS applications (via SaaS Security API integration).
E.Generate an alert log entry in Panorama / Logging Service.
AnswersA, D, E

Blocking is a standard DLP enforcement action.

Why this answer

Enterprise DLP enforcement actions include block, alert, quarantine, and allow (with logging).

158
MCQmedium

An organization is using Panorama to manage VM-Series firewalls deployed across AWS and Azure. They want to dynamically push security policy updates based on tags assigned to workloads in both clouds. Which Panorama component should be configured to ingest cloud tags?

A.GlobalProtect clientless VPN gateway
B.User-ID Agent
C.Panorama Cloud Services plugin with Cloud Discovery configured
D.Log Collector correlation engine
AnswerC

The Cloud Services plugin allows Panorama to query AWS and Azure APIs and populate dynamic address groups.

Why this answer

Cloud Services plugin enables Panorama to connect to cloud provider APIs, retrieve instance tags, and map them to dynamic address groups.

159
MCQmedium

You are troubleshooting a VM-Series firewall in AWS where CPU utilization on the dataplane vCPU is at 100%, leading to packet drops. Which PAN-OS CLI command should you run to inspect traffic and process utilization across dataplane cores?

A.debug software restart process mgmtserver
B.show system resources
C.request system factory-reset
D.show session all filter state active
AnswerB

'show system resources' displays CPU and memory utilization for management and dataplane processes.

Why this answer

The command 'show running resource-monitor' or 'show system resources' along with dataplane specific packet buffer commands helps diagnose high CPU on the VM-Series.

160
MCQeasy

What is the purpose of the VM-Series deployment package 'BYOL' (Bring Your Own License)?

A.It bills the customer hourly directly through the cloud provider's marketplace billing system.
B.It requires the firewall to connect to a physical hardware PA-Series appliance for licensing.
C.It allows administrators to use licenses purchased independently from Palo Alto Networks or channel partners.
D.It restricts the firewall to running evaluation software for a maximum of 14 days.
AnswerC

BYOL enables customers to use pre-purchased authorization codes or CSS subscription credits.

Why this answer

BYOL allows customers to purchase VM-Series software licenses directly from Palo Alto Networks or partners and apply the auth code to the firewall or Panorama.

161
MCQhard

An enterprise is automating security policy generation. A script generates custom URL filtering custom categories and pushes them to Panorama via the XML API. However, after the API call returns a successful status code, the changes are not visible in the Panorama Web UI or on the firewalls. What crucial step was omitted in the automation workflow?

A.Sending a session termination command to clear active admin UI connections.
B.Restarting the management server process on Panorama using an operational command API call.
C.Executing a commit API request to promote the candidate configuration to the running configuration.
D.Generating a new API key because authentication tokens expire upon object creation.
AnswerC

Making API changes modifies only the candidate configuration database. A commit operation is mandatory to apply changes.

Why this answer

In PAN-OS and Panorama architecture, API calls that modify the configuration only update the candidate configuration. A separate commit API request must be executed to push changes to the running configuration and target devices.

162
MCQeasy

In a Zero Trust network design, why is network micro-segmentation considered superior to traditional macro-segmentation (flat internal zones)?

A.Micro-segmentation allows all internal users to bypass authentication checks
B.Micro-segmentation eliminates the need for firewalls by relying on switch ACLs
C.Micro-segmentation limits lateral movement and reduces the blast radius if an attacker compromises a single workload or endpoint
D.Micro-segmentation increases network latency by adding 10ms of jitter to every packet
AnswerC

Correct. Micro-segmentation stops attackers from moving laterally across a flat network.

Why this answer

Micro-segmentation restricts lateral movement by breaking large zones into smaller, isolated segments, limiting the blast radius of a potential breach.

163
MCQhard

An enterprise architect is troubleshooting an issue where an internal host is successfully executing a DNS tunneling attack through corporate firewalls. Standard DNS security profiles are enabled, but the attacker is using a randomized, low-frequency query rate that avoids triggering high-volume DNS tunneling signatures. Which advanced CDSS architectural feature must the architect configure to mitigate this threat?

A.Enforce strict TCP proxying for all DNS traffic passing through the firewall dataplane.
B.Write a custom URL Filtering category blocking all domains with more than three subdomains.
C.Enable DNS Security with advanced machine learning-based categorization and predictive domain analysis within the Anti-Spyware profile.
D.Configure a custom Threat Prevention vulnerability signature with an extremely low threshold for UDP port 53 packet counts.
AnswerC

Machine learning models in DNS Security detect subtle, low-frequency DGA and tunneling patterns that evade standard signature detection.

Why this answer

DNS Security cloud-delivered service utilizes predictive analytics and machine learning models in the cloud to analyze patterns, domain generation algorithms (DGAs), and low-frequency DNS tunneling behavior that static signatures miss.

164
MCQeasy

An architect is designing mobile user security with Prisma Access and needs to ensure that all DNS queries from mobile devices are inspected and secured. Which Prisma Access feature handles DNS security for mobile users?

A.Local client DNS caching configured in GlobalProtect settings.
B.GlobalProtect split-tunnel DNS exclusion lists.
C.SD-WAN DNS proxy forwarding.
D.Prisma Access DNS Security service applied via Anti-Spyware / DNS Security profiles.
AnswerD

DNS Security profiles in Prisma Access analyze DNS queries against threat intelligence to block malicious domains.

Why this answer

Prisma Access integrates DNS Security services to analyze DNS requests, block malicious domains, and prevent C2 communication over DNS.

165
MCQeasy

An architect is designing a high-security enterprise perimeter where inline threat prevention must identify and block sophisticated command-and-control (C2) callbacks without causing unacceptable latency to real-time voice and video traffic. Which configuration best balances deep inspection with performance?

A.Enable inline WildFire signature and machine learning inspection on the security profile applied to the voice and video security rules.
B.Configure a custom decryption profile to bypass SSL decryption entirely for all traffic originating from voice and video VLANs.
C.Disable Threat Prevention on voice and video zones to minimize packet processing overhead while relying solely on layer-4 stateful inspection.
D.Set the TCP Three-Way Handshake timeout to the maximum value to ensure complete session establishment before triggering malware scans.
AnswerA

Inline WildFire blocks threats in real-time by leveraging signature and machine learning checks directly in the datapath.

Why this answer

WildFire inline machine learning provides real-time protection against zero-day C2 by inspecting traffic at the packet level before sessions are fully established, ensuring immediate enforcement without disrupting performance-sensitive voice and video streams.

166
Multi-Selecthard

An enterprise is securing generative AI applications and internal usage of public Large Language Models. Which THREE capabilities are provided by Palo Alto Networks AI Access Security / Prisma Cloud AppSec for AI protection? (Choose three)

Select 3 answers
A.Automated physical layer cable testing for fiber optic connections linking AI cluster data centers.
B.Prevention of sensitive data exfiltration (such as PII or source code) entering AI prompt inputs.
C.Inspection and blocking of prompt injection and model jailbreak attempts in real-time.
D.GlobalProtect VPN user posture checks verifying disk encryption on mobile laptops.
E.Discovery and visibility of shadow AI applications used by employees across the enterprise.
AnswersB, C, E

DLP checks prevent users from pasting confidential company data or credentials into public AI models.

Why this answer

AI Access Security and Prisma Cloud LLM security provide visibility into shadow AI usage, protection against prompt injection and jailbreaking, and prevention of sensitive data leakage (DLP) in AI prompts.

167
Multi-Selectmedium

An enterprise architect is troubleshooting application visibility issues where custom internal web applications are categorized as 'unknown-tcp' by App-ID. Which THREE methods can the architect use to properly identify or create a signature for this application? (Choose three)

Select 3 answers
A.Change the default gateway IP address of the core routing switch to force packet re-ordering.
B.Configure an Application Override policy if the application cannot be reliably identified via App-ID inspection and must bypass DPI.
C.Disable the Single Sign-On (SSO) agent to force all internal HTTP traffic into the default application bucket.
D.Submit application traffic pcaps and request a signature through the Palo Alto Networks App-ID development process.
E.Create a Custom App-ID object defining specific traffic patterns, port mappings, and content signatures.
AnswersB, D, E

Application Override forces identification for proprietary or custom apps.

Why this answer

Custom applications can be identified using Application Override, Custom App-ID signature creation using packet inspection, or submitting traffic PCAPs to Palo Alto Networks for App-ID development.

168
MCQhard

An enterprise architect is designing a Zero Trust Network Access (ZTNA) architecture using GlobalProtect and Prisma Access / NGFW integration. The design requires continuous trust verification where user device posture (e.g., disk encryption status, OS patch level) is reassessed periodically. How does the architecture enforce this?

A.Cortex Data Lake runs a port scan against every remote client IP address over the VPN tunnel.
B.The Active Directory domain controller forces a password change every 15 minutes for all remote workers.
C.Host Information Profile (HIP) checks collect endpoint security posture data periodically and feed HIP matches into Security Policy rules.
D.The firewall terminates the IPsec tunnel every 60 seconds, forcing a complete Layer-2 re-authentication handshake.
AnswerC

HIP profiles assess endpoint posture and allow security policies to dynamically enforce trust based on compliance.

Why this answer

GlobalProtect works with Cortex XDR and Host Information Profile (HIP) checks to evaluate device posture periodically and update dynamic security policy enforcement via HIP matches.

169
MCQhard

An architect is designing a high-performance network where multiple virtual routers and virtual systems (vsys) are configured on a PA-7000 series firewall. The security design requires inter-vsys traffic to undergo full CDSS threat inspection (WildFire, Vulnerability Protection, URL Filtering). How should this traffic flow be architected?

A.Configure a Dynamic NAT pool mapping vsys 1 private IP addresses directly to vsys 2 management IP addresses.
B.Route inter-vsys traffic through shared security zones using virtual routers or virtual wires with security profiles explicitly applied to the inter-vsys rules.
C.Configure a direct cross-connect cable between physical interface ports on the front panel to bridge the virtual systems at Layer 1.
D.Disable stateful inspection globally so that packets pass freely between virtual systems without session table creation.
AnswerB

Routing traffic through security zones with attached security profiles ensures full inspection between virtual systems.

Why this answer

Inter-vsys communication requires forwarding traffic between virtual systems using virtual wires (vswires) or via shared internal zones where security rules and CDSS profiles are explicitly applied between the vsys boundaries.

170
MCQeasy

A security architect is configuring an Anti-Spyware profile on a Palo Alto Networks NGFW. The team wants to ensure that hosts infected with malware attempt-to-communicate with known Command-and-Control (C2) servers are automatically isolated. Which feature in the Anti-Spyware profile should be configured to achieve this redirection?

A.WildFire file forwarding
B.DNS Sinkhole
C.Packet Capture (Pcap)
D.URL filtering category override
AnswerB

DNS Sinkhole intercepts malicious DNS lookups and redirects the traffic to a designated sinkhole IP address for host identification.

Why this answer

DNS Sinkholing allows the firewall to intercept DNS requests to malicious domains and redirect the infected client to a sinkhole IP address, identifying compromised internal hosts.

171
Multi-Selecthard

An architect is designing security policy optimization for a mature enterprise firewall rulebase containing over 5,000 rules. Which THREE features or capabilities in Panorama Policy Optimizer should be utilized to clean up and optimize the rulebase? (Choose three)

Select 3 answers
A.Unused rule identification based on rule hit count tracking over a specified timeframe
B.Automatic kernel panic recovery and reboot scheduling
C.Shadowed rule detection to identify rules rendered ineffective due to preceding broader rules
D.App-ID adoption recommendations that analyze port-based traffic and suggest appropriate App-IDs
E.Automated DNS zone transfer generation for public-facing web servers
AnswersA, C, D

Correct. Identifying unused rules helps safely remove clutter.

Why this answer

Panorama Policy Optimizer provides visibility into unused rules, App-ID adoption status for port-based rules, and shadowed rule detection.

172
Multi-Selecthard

An enterprise is designing an AI application security architecture using Palo Alto Networks solutions. Which THREE key security risks in generative AI and LLM deployments must be addressed by this architecture? (Choose three)

Select 3 answers
A.Insecure plugin design and supply chain vulnerabilities in third-party AI model components.
B.Prompt injection attacks designed to manipulate LLM behavior and bypass safety controls.
C.Physical hardware failure of enterprise branch PoE switches.
D.Data exfiltration and sensitive data leakage through LLM prompts and model outputs.
E.Traditional SQL injection attacks against legacy database servers.
AnswersA, B, D

LLM supply chain and insecure plugins represent critical AI architecture risks.

Why this answer

AI security architecture must address prompt injection, data exfiltration/leakage, insecure output handling, and LLM supply chain risks.

173
MCQmedium

An organization's security architecture requires that any file downloaded over web browsing or email must be blocked if its WildFire verdict is malicious, but files with unknown verdicts should be allowed to download while analysis occurs in the cloud. Which WildFire architectural profile setting achieves this?

A.Disable WildFire forwarding and configure a static EDL blocking all file extensions (.exe, .pdf, .zip).
B.Set the WildFire analysis profile action to 'Reset-Both' for all unknown file types, effectively blocking all file downloads.
C.Configure a Decryption Profile to drop all sessions containing binary file headers.
D.Configure the WildFire Analysis profile forwarding rule with 'forward' for unknown files and a Security Rule action of 'allow', while enabling Threat Prevention to block known malicious hashes.
AnswerD

Forwarding unknowns for analysis while allowing the stream (or using inline ML to block) fulfills the requirement to permit unknowns while blocking malicious.

Why this answer

WildFire inline analysis and forward profiles support 'download-after-verdict' or allowing unknown files while holding execution on endpoints, or allowing the download while the cloud analyzes the file in real time depending on the exact forwarding rule configuration. For inline blocking of unknowns, 'block session' can be selected; to allow unknown files while analyzing, the action is set to allow with forwarding.

174
MCQeasy

An architect is designing a Zero Trust network segmentation strategy using a Palo Alto Networks Next-Generation Firewall. Which architectural approach provides the most granular internal segmentation enforcement between distinct application tiers residing on the same physical subnet?

A.Implementing standard VRRP failover groups across the core routing switches
B.Configuring static VLAN tagging on the core switch to separate traffic into distinct broadcast domains
C.Deploying internal firewalls operating in Virtual Wire mode between application tiers
D.Relying on standard subnetting with classic IP-based access control lists at the gateway router
AnswerC

Virtual Wire mode allows transparent insertion of the firewall into existing L2/L3 topologies without changing IP addressing, enabling granular inter-tier segmentation.

Why this answer

Deploying internal Firewalls in Virtual Wire (vwire) mode or using Zone Protection and Inter-Zone routing rules allows deep application visibility and threat prevention between sub-tiers without altering the existing IP routing topology.

175
Multi-Selecthard

An architect is configuring mobile user security with Prisma Access and needs to implement Host Information Profile (HIP) checks. Which THREE conditions or attributes can be validated using HIP checks? (Choose three)

Select 3 answers
A.Real-time CPU temperature and fan speed of the remote laptop.
B.BGP routing table entries on the user's home Wi-Fi router.
C.Disk encryption status (whether FileVault or BitLocker is enabled on the hard drive).
D.Antivirus software status (whether it is installed, enabled, and up-to-date).
E.Operating system version and patch level.
AnswersC, D, E

Disk encryption status can be verified via HIP checks.

Why this answer

HIP checks validate operating system version, antivirus software status, disk encryption status, and patch status on mobile endpoints.

176
MCQmedium

An architect is deploying Panorama in an environment where network interfaces and virtual routers must be configured identically across ten branch firewalls, except for the IP addresses of the WAN interfaces. Which Panorama feature should the architect use to handle this efficiently without creating ten separate templates?

A.Template Variables
B.Dynamic Address Groups
C.Log Collector Group Mapping
D.Device Group Post-Rules
AnswerA

Template variables allow administrators to substitute unique values (like IP addresses) into a shared template for individual managed firewalls.

Why this answer

Template variables allow administrators to define a single template structure while using variables (such as $WAN_IP) to inject unique values per firewall.

177
Multi-Selectmedium

An enterprise security architect is designing an intrusion prevention and threat intelligence architecture. Which TWO of the following statements accurately describe the behavior and capabilities of Palo Alto Networks Threat Prevention and CDSS integration? (Choose two)

Select 2 answers
A.Threat intelligence feeds can automatically integrate dynamic threat indicators via External Dynamic Lists (EDLs) without requiring firewall reboots or commits.
B.Threat Prevention inspects both inbound and outbound traffic flows for vulnerability exploit signatures across all supported protocols.
C.Vulnerability Protection signatures require manual administrator intervention every hour to compile raw C code on the firewall dataplane.
D.DNS Security profiles can only be applied to hardware firewalls and are unsupported in virtualized firewall form factors (VM-Series).
E.WildFire cloud updates are dependent on manual file hashing performed exclusively by local administrators via CLI.
AnswersA, B

EDLs update dynamically without triggering firewall configuration commits or reboots.

Why this answer

Threat Prevention inspects traffic bi-directionally for known exploits, and cloud threat intelligence automatically synchronizes threat signatures and IOCs globally to protect against zero-days and known attacks.

178
MCQeasy

An administrator is designing a Panorama deployment to manage 150 next-generation firewalls across various geographic regions. The design requires efficient reuse of shared security objects, while still allowing regional teams to customize local security rules and network objects. Which configuration construct in Panorama should the architect utilize to meet this requirement?

A.Device Groups
B.Templates
C.Log Collectors
D.Panorama Administrative Roles
AnswerA

Device Groups provide the hierarchical policy management structure required to push shared objects and policies to specific sets of managed firewalls.

Why this answer

Device Groups allow administrators to logically group firewalls and push shared policies, while templates handle network configurations. This enables centralized governance with regional flexibility.

179
MCQhard

An enterprise network architect is implementing the Palo Alto Networks IoT Security service on an NGFW deployment. The architecture requires automated policy generation based on observed device behavior and manufacturer profiles without manual tagging. How does IoT Security achieve automated security policy enforcement on the firewall?

A.By analyzing traffic patterns and telemetry in the cloud and generating policy recommendations via Panorama
B.By using GlobalProtect agent telemetry embedded on all managed IoT endpoints
C.By converting all DHCP lease tables into External Dynamic Lists refreshed every 60 seconds
D.By deploying dedicated physical sensor appliances on every network switch access port
AnswerA

IoT Security uses cloud-based machine learning to identify devices and push policy recommendations to Panorama and the firewalls.

Why this answer

IoT Security analyzes device telemetry in the cloud, categorizes devices, assesses risks, and recommends security policy rules that can be pushed directly to Panorama and applied to the NGFW policy.

180
MCQeasy

When architecting security policy optimization for a Palo Alto Networks firewall, what is the primary security risk associated with maintaining 'shadowed' security rules in the rulebase?

A.Shadowed rules can mask intended security intent, leading to unexpected policy behavior where explicit allow or deny rules are rendered ineffective
B.Shadowed rules automatically disable WildFire and Threat Prevention engine updates
C.Shadowed rules increase firewall CPU and memory consumption by 50%
D.Shadowed rules are bypassed entirely by PAN-OS and cause kernel panics
AnswerA

Correct. Because rules are processed top-down, a shadowed rule is never evaluated, which can undermine security policy design.

Why this answer

Shadowed rules occur when a broader rule precedes a more specific rule, causing the specific rule to never be hit. This can conceal intended security policies or allow unintended traffic if the broader rule is modified.

181
MCQeasy

Which cloud-native storage mechanism is used by Panorama to store and archive historical log data when deployed in AWS?

A.AWS EBS (Elastic Block Store) mmapped volumes only
B.AWS S3 (Simple Storage Service) via log forwarding and archival
C.AWS EFS (Elastic File System) NFS shares
D.AWS DynamoDB NoSQL tables
AnswerB

AWS S3 is the native object storage service used for archiving Panorama logs in AWS.

Why this answer

Panorama log collectors in public clouds often leverage object storage (e.g., AWS S3) for log forwarding and long-term log archiving.

182
MCQhard

An architect is designing a Zero Trust secure access solution where remote users must authenticate using multi-factor authentication (MFA) and have their device health verified before accessing internal applications. However, certain unmanaged third-party vendor laptops cannot install the GlobalProtect agent. Which architectural solution should be implemented for these specific third-party vendors?

A.Provide local administrative credentials to the vendor over phone support
B.Deploy GlobalProtect Clientless VPN portals combined with SAML-based MFA and strict application-level URL filtering
C.Send pre-configured full-tunnel IPsec client software via unencrypted email attachments
D.Block third-party vendors entirely with no access options under any circumstances
AnswerB

Correct. Clientless VPN provides secure access for unmanaged devices via browser portals with MFA and strict controls.

Why this answer

GlobalProtect Clientless VPN allows unmanaged endpoints to access specific web-based applications securely via a browser portal without requiring an endpoint client installation, while still supporting SAML/MFA.

183
Multi-Selecthard

An architect is troubleshooting an automated workflow where Cortex XSOAR attempts to quarantine a compromised host by registering an IP address to a Dynamic Address Group on Panorama. The API returns a success code, but the firewall does not apply the security rule action. Which THREE potential issues should the architect investigate? (Choose three)

Select 3 answers
A.Verify that the physical firewall chassis has active power redundancy on both power supply units.
B.Ensure that the BGP routing table on the core switch is advertising the quarantined IP address.
C.Confirm that Panorama has successfully pushed the updated Dynamic Address Group policy configuration to the managed firewalls.
D.Check that the target firewall is successfully receiving User-ID updates and communicating with Panorama/User-ID agents.
E.Verify that the tag name used in the User-ID API registration exactly matches the tag specified in the Dynamic Address Group object configuration.
AnswersC, D, E

If the security rule referencing the DAG hasn't been committed and pushed to the firewall, traffic matching will not occur.

Why this answer

When DAG tagging succeeds via API but policy enforcement fails, potential issues include tag name mismatches between registration and security rules, the firewall not receiving the dynamic object updates, or the security rule not referencing the correct DAG.

184
MCQmedium

You are architecting a Transit Gateway (TGW) design in AWS with centralized security using VM-Series firewalls in a security VPC. East-West traffic between Spoke VPCs must be inspected by the firewalls. Which AWS feature must be configured on the TGW route tables to ensure traffic destined to another Spoke VPC is intercepted and routed to the security VPC attachment?

A.AWS Network Firewall rules mirroring all traffic to the VM-Series interface
B.Security groups attached directly to the TGW attachment interface
C.Route table propagation with specific static routes pointing to the security VPC attachment
D.Cross-region peering attachments with BGP enabled
AnswerC

Static routes pointing to the security VPC attachment are required in the spoke route tables to steer inter-VPC traffic.

Why this answer

AWS Transit Gateway route tables must be configured with specific route associations and propagations, directing traffic from Spoke attachments toward the security VPC attachment for inspection.

185
Multi-Selectmedium

An architect is designing security policy optimization to ensure that rules are easy to audit and maintain. Which TWO best practices should be followed when structuring PAN-OS security rulebases for Zero Trust? (Choose two)

Select 2 answers
A.Consolidate all business traffic into a single massive rule allowing 'any' application over port 443
B.Rely entirely on default intra-zone and inter-zone allow rules without creating custom policies
C.Use clear, descriptive naming conventions for every security rule indicating business justification and owner
D.Disable logging on all security rules to conserve disk space on Panorama Management Server
E.Leverage Panorama pre-rules and post-rules structure to enforce global corporate policies while allowing local administrative flexibility
AnswersC, E

Correct. Clear naming aids auditability and policy maintenance.

Why this answer

Best practices include using descriptive rule naming conventions, grouping rules logically into pre-rules, post-rules, and device group rules, and avoiding overly broad 'any-any' rules.

186
Multi-Selecteasy

An architect is configuring User-ID mapping sources for an enterprise network with Windows Active Directory. Which TWO of the following mechanisms can be used by PAN-OS to gather user-to-IP mappings? (Choose two)

Select 2 answers
A.Direct SNMP polling of client workstation BIOS serial numbers.
B.Manual entry of user credentials into the firewall LCD front panel display.
C.Windows Security Log polling performed by the firewall or dedicated User-ID agent.
D.Automatic conversion of ICMP ping packets into Kerberos ticket grant requests.
E.Captive Portal authentication prompting users via web browser.
AnswersC, E

Log polling is a primary method for gathering user-to-IP mappings from Active Directory.

Why this answer

User-ID gathers mappings via Windows Security Log polling by the firewall or User-ID agent, and via Captive Portal authentication.

187
MCQeasy

Which hypervisor platforms are officially supported for deploying VM-Series firewalls in a private cloud environment?

A.VMware ESXi, KVM, Nutanix AHV, and Microsoft Hyper-V
B.Apple macOS Hypervisor Framework exclusively
C.Bare-metal x86 servers without any hypervisor layer
D.Oracle VirtualBox and Docker containers only
AnswerA

These are the primary supported enterprise private cloud hypervisors for VM-Series.

Why this answer

VM-Series supports multiple hypervisors including VMware ESXi, KVM, Nutanix AHV, and Microsoft Hyper-V.

188
MCQeasy

An architect is designing mobile user security using Prisma Access. The design requires all remote users to connect via a single persistent client interface that automatically establishes secure tunnels regardless of user location. Which client software must be deployed to the endpoints?

A.Prisma SD-WAN ION client
B.GlobalProtect app
C.Prisma Cloud Defender agent
D.WildFire agent for endpoints
AnswerB

The GlobalProtect app is the standard agent deployed to endpoints for mobile user secure connectivity in Prisma Access.

Why this answer

GlobalProtect is the client software used by Prisma Access to establish secure IPsec/SSL connections from mobile user endpoints to the Prisma Access cloud infrastructure.

189
MCQmedium

An administrator is configuring Prisma SD-WAN at a retail branch and needs to ensure that guest Wi-Fi traffic is isolated from corporate POS traffic while both exit through the same ION device. Which Prisma SD-WAN configuration construct should be used?

A.Configure separate LAN zones and VRFs/segments mapped to distinct security policies on the ION device.
B.Deploy an independent secondary hardware appliance for guest Wi-Fi connected to a separate ISP link.
C.Enable GlobalProtect clientless VPN on the ION device management interface for guest users.
D.Apply a NAT source override policy on the default LAN interface pointing to the guest SSID.
AnswerA

VRFs and LAN zones isolate traffic at Layer 3 and Layer 4, ensuring guest traffic cannot communicate with the POS environment.

Why this answer

Prisma SD-WAN uses VRFs (Virtual Routing and Forwarding) or tenant/segment separation combined with security policies to isolate traffic from different functional groups within the same branch hardware appliance.

190
MCQmedium

An architect is designing a Prisma Access deployment for remote users and needs to inspect outbound internet traffic using explicit proxy mode. Which configuration component must be provisioned in Panorama Cloud Services to handle explicit proxy authentication and traffic steering?

A.Enable SSL Inbound Inspection on the GlobalProtect gateway object under Network > Gateway.
B.Deploy a Prisma SD-WAN branch gateway configured with explicit proxy redirect rules.
C.Configure a PAC file and define explicit proxy settings under Mobile Users > Setup > Explicit Proxy in Panorama.
D.Provision a dedicated IoT Security sensor instance attached to the mobile user zone.
AnswerC

This is the correct path and configuration mechanism for provisioning explicit proxy services in Prisma Access for mobile users.

Why this answer

To support explicit proxy in Prisma Access, administrators configure PAC (Proxy Auto-Configuration) files and explicit proxy settings under Mobile Users > Setup > Explicit Proxy. The explicit proxy mechanism intercepts HTTP/HTTPS traffic sent directly to the Prisma Access service node IP.

191
MCQhard

An enterprise architect is designing a Zero Trust architecture for Kubernetes container environments using Palo Alto Networks CN-Series container native firewalls. Where must the CN-Series firewall be positioned to inspect pod-to-pod traffic within a Kubernetes cluster effectively?

A.Installed directly on employee laptops as a browser extension
B.Inline within the Kubernetes cluster network path as containerized instances (CN-Series) inspecting pod-to-pod traffic via Kubernetes service insertion and CNI integration
C.As a physical hardware appliance sitting outside the Kubernetes worker node cluster racks
D.Configured exclusively as an SMTP mail relay proxy in the DMZ
AnswerB

Correct. CN-Series provides container-native inspection for east-west pod traffic.

Why this answer

CN-Series firewalls are deployed as daemonsets or containerized firewalls enforcing micro-segmentation at the Kubernetes CNI (Container Network Interface) layer for pod-to-pod east-west traffic inspection.

192
MCQmedium

A security architect is configuring User-ID at scale across 50 distributed enterprise branches using Panorama and local firewalls. The environment utilizes Microsoft Entra ID (formerly Azure AD) for identity. Which integration method provides the most scalable and resilient identity mapping mechanism for User-ID in a large cloud-centric architecture?

A.Configure port-mapping on NAT devices to correlate user IP addresses manually via a custom script
B.Configure Panorama to pull user mappings exclusively via Windows client-based WMI polling across WAN links for every endpoint
C.Deploy the Palo Alto Networks Cloud Identity Engine (CIE) to authenticate users and sync identities directly from Microsoft Entra ID to Panorama and firewalls
D.Rely solely on local User-ID agent installations on every single workstation without central management
AnswerC

Correct. Cloud Identity Engine (CIE) provides cloud-delivered scale and native integration with cloud identity providers like Microsoft Entra ID.

Why this answer

The PAN-OS User-ID Agent and XML API integrations allow direct querying of directories, but using the Syslog integration or User-ID Agent with GlobalProtect provides scalability, while the Cloud Identity Engine (CIE) natively connects to cloud identity providers like Microsoft Entra ID for large-scale deployments.

193
MCQmedium

An architect is configuring a Prisma SD-WAN branch deployment. The business requires high-priority voice traffic to fail over instantly to a secondary cellular backup link if jitter exceeds 30ms on the primary MPLS link, without dropping active VoIP calls. Which Prisma SD-WAN feature accomplishes this?

A.Create a traffic engineering path policy with dynamic path selection based on performance criteria and session-preserving failover.
B.Apply a QoS profile with priority queueing and strict shaping on the LAN egress interface.
C.Implement GlobalProtect Site-to-Site VPN with IPsec backup tunnels and dead peer detection (DPD).
D.Configure an SD-WAN active-passive HA pair with Ethernet link-state monitoring on the branch ION devices.
AnswerA

Dynamic path selection in Prisma SD-WAN evaluates metrics like jitter, latency, and packet loss in real time and steers sessions across paths without session termination.

Why this answer

Prisma SD-WAN uses App-Insights and path selection policies combined with forward error correction (FEC) and packet duplication to achieve hitless failover for real-time traffic like VoIP based on dynamic path performance metrics.

194
MCQmedium

A security architect is deploying Prisma Access to secure remote workers following a Zero Trust Network Access (ZTNA) model. The design requires continuous verification of device posture before granting access to internal applications. Which Palo Alto Networks capability should be integrated to enforce this requirement?

A.Deploying User-ID agents to query Microsoft Active Directory group memberships every 15 minutes
B.Configuring static GlobalProtect portal agent configuration profiles based on source IP regions
C.Integrating GlobalProtect with Cortex XDR device assessment for continuous posture checks
D.Enabling SSL decryption on the Prisma Access explicit proxy to inspect outbound web traffic
AnswerC

Cortex XDR and GlobalProtect work together to continuously evaluate device posture (OS patches, disk encryption, antivirus status) before permitting app access.

Why this answer

GlobalProtect Device Inspector or Cortex XDR device assessment integrates directly with Prisma Access to enforce dynamic posture checks, ensuring non-compliant endpoints are restricted from accessing sensitive resources.

195
MCQmedium

When designing AI application security using Palo Alto Networks capabilities, an architect wants to protect internal Large Language Models (LLMs) from prompt injection attacks and data exfiltration. Which product suite provides native LLM security posture management and runtime defense?

A.Cortex XDR agent
B.Prisma Access Mobile Users
C.Prisma Cloud Application Security / AI Security posture management
D.WildFire cloud-based malware analysis
AnswerC

Prisma Cloud includes features for AI application security, securing LLM pipelines and prompt injection vulnerabilities.

Why this answer

Prisma Cloud provides LLM security posture management (DSPM for AI) and runtime visibility for AI applications, securing AI models and pipelines.

196
MCQmedium

An architect is troubleshooting an issue where an NGFW with Advanced Threat Prevention is failing to inspect encrypted HTTPS traffic traversing the security gateway. The security team confirms that WildFire and Vulnerbility Protection profiles are attached to the security policy. What architectural omission is causing the lack of threat inspection?

A.Outdated WildFire signature database version on the local dataplane
B.Incorrect configuration of the Zone Protection profile on the egress interface
C.Missing Decryption policy and profile to decrypt SSL/TLS sessions
D.Failure to enable User-ID mapping for the source IP addresses
AnswerC

Content-based CDSS features require decrypted traffic to inspect the application payload inside SSL/TLS tunnels.

Why this answer

Without an SSL Decryption policy and associated decryption profile, the firewall cannot inspect the payload of encrypted HTTPS sessions, rendering CDSS capabilities like Vulnerability Protection and WildFire unable to inspect layer 7 contents.

197
MCQeasy

An enterprise security architect wants to gain visibility into shadow IT and unmanaged AI applications utilized by employees across the organization. Which Palo Alto Networks solution provides this cloud application discovery and risk scoring?

A.Prisma Access with SaaS Security inline discovery and risk scoring
B.Prisma SD-WAN branch interface counters
C.Cortex XDR host isolation policies
D.GlobalProtect portal splash page notifications
AnswerA

SaaS Security inline (integrated with Prisma Access and Next-Generation Firewalls) discovers shadow IT and assesses risk scores for cloud and AI apps.

Why this answer

Prisma Access / Prisma Cloud / Enterprise DLP / Advanced URL Filtering provide SaaS security visibility. Specifically, Prisma Access and Advanced URL Filtering with SaaS Security provide shadow IT discovery and risk assessment.

198
MCQhard

An enterprise architect is configuring WildFire inline machine learning and analysis on a PA-7050 firewall. The security requirement states that potential zero-day malware must be blocked instantly at the session layer before the complete file download finishes. Which WildFire deployment setting satisfies this inline requirement?

A.Enabling DNS Security with automated command-and-control domain block lists
B.Deploying a local WF-500 appliance in private cloud mode with a 15-minute polling interval
C.Configuring Inline ML for WildFire within the Anti-Spyware and WildFire Analysis profiles
D.Enabling WildFire Analysis on the Security Rulebase with standard public cloud forwarding
AnswerC

Inline ML for WildFire uses machine learning models running directly on the hardware or leveraged via cloud services to block zero-day files in real-time.

Why this answer

Inline ML for WildFire enables the firewall to make real-time verdict determinations on PE files and other executable formats during the session before the file transfer completes.

199
MCQmedium

An architect is implementing SaaS Security inline to discover and control unauthorized (shadow IT) cloud applications used by employees. The requirement is to generate logs and alert administrators when high-risk file-sharing applications are accessed, without immediately blocking business operations. How should this be configured?

A.Set the security rule action to 'Deny' and configure a custom response page directing users to submit a business justification ticket.
B.Disable App-ID inspection and configure Layer-4 port-based blocking rules for ports 80 and 443.
C.Configure a GlobalProtect client certificate authentication requirement for all web traffic.
D.Create a Security Rule allowing the specific App-ID applications, attach a SaaS Security policy profile, and set log-setting to log at session end.
AnswerD

Allowing the applications while logging and profiling via SaaS Security provides visibility and risk scoring without breaking business processes.

Why this answer

SaaS Security inline policies and App-ID security rules can be configured with logging enabled and the action set to 'allow' while applying a custom SaaS Security profile to tag and monitor risk levels without dropping traffic.

200
MCQhard

An architect is implementing Prisma SD-WAN with SaaS Quality of Experience (QoE) monitoring. How does Prisma SD-WAN determine the optimal path for cloud applications like Microsoft 365?

A.By enforcing static path rules configured in Panorama template stacks.
B.By inspecting DNS response times returned by the local ISP DNS resolver.
C.By periodically querying the local BGP routing table on the core branch switch.
D.By actively probing SaaS endpoints and continuously measuring latency, jitter, and packet loss across all available WAN paths.
AnswerD

Prisma SD-WAN measures path quality via active probes and selects the best path based on application SLAs.

Why this answer

Prisma SD-WAN uses active and passive probing, including SaaS QoE monitoring probes to office-365 endpoints, to measure real-time path characteristics and steer traffic accordingly.

201
Multi-Selectmedium

An administrator is troubleshooting API connectivity issues between an external automation script and Panorama. Which TWO configuration settings on Panorama must be verified to ensure successful API access? (Choose two)

Select 2 answers
A.The administrator account used for API requests must have sufficient RBAC permissions to execute the requested API commands.
B.HTTPS and XML/REST API access must be enabled and permitted in the Management Profile applied to the management interface.
C.The SSH daemon must be configured to allow root password login.
D.The firewall Data Plane interface must have user-id redistribution enabled.
E.BGP routing must be enabled on the management interface to advertise API routes.
AnswersA, B

API requests inherit the permissions of the authenticated user; insufficient RBAC rights result in authorization errors.

Why this answer

API access requires valid administrative credentials/keys, proper RBAC permissions for the API user, and enabled HTTPS/API services on the management profile.

202
MCQeasy

An administrator is setting up centralized log collection in Panorama and needs to determine how long logs are retained across different log types. Where should the administrator check the disk allocation breakdown for Traffic, Threat, and System logs on a Dedicated Log Collector?

A.Device > Log Settings > Disk Quotas
B.Panorama > Log Collectors > Collector Group > [Select Group] > Log Storage
C.Monitor > Log Settings > Storage Allocation
D.Panorama > Setup > High Availability
AnswerB

Log storage allocation and retention settings for log collectors are configured and viewed within the Collector Group configuration.

Why this answer

Panorama > Log Collectors > Collector Group > Log Storage provides the exact disk allocation percentages and retention metrics for each log type.

203
MCQeasy

In a Zero Trust architecture designed around Palo Alto Networks best practices, what is the primary purpose of implementing decryption (SSL/TLS Inbound Inspection and Forward Secure Proxy)?

A.To log user browsing habits for human resources compliance reporting
B.To store plaintext copies of all banking and medical passwords in the firewall local database
C.To accelerate TCP handshake performance and reduce firewall CPU utilization
D.To eliminate blind spots by inspecting encrypted traffic payloads for malware, hidden threats, and data exfiltration
AnswerD

Correct. Decryption allows security engines (Threat Prevention, WildFire, DLP) to inspect encrypted traffic payloads.

Why this answer

Zero Trust mandates inspecting all traffic for threats and unauthorized data exfiltration. Since over 80% of enterprise traffic is encrypted, lack of decryption creates a massive blind spot where malicious payloads and exfiltration can hide.

204
MCQmedium

You are deploying VM-Series firewalls in Google Cloud Platform (GCP) using a Shared VPC architecture. Where should the VM-Series firewall instances be deployed to centrally inspect traffic across multiple service projects?

A.In a centralized Host/Security VPC project with shared subnet attachments
B.In an isolated, standalone GCP project with no network peering
C.Directly inside each individual service project without centralized management
D.Inside the Google Kubernetes Engine (GKE) control plane cluster nodes
AnswerA

Deploying firewalls in a centralized host/security project allows management of interfaces across shared subnets.

Why this answer

In a GCP Shared VPC architecture, security appliances are typically deployed in a centralized Host Project (or Security Project), where VPC networks are shared with service projects.

205
MCQhard

You are configuring Panorama to manage a fleet of VM-Series firewalls in AWS utilizing AWS Secrets Manager to dynamically retrieve API keys and external database credentials. Which Panorama feature enables this integration?

A.Panorama External Services / Secrets Engine integration
B.Log Collector syslog forwarding rules
C.WildFire cloud threat intelligence connector
D.GlobalProtect HIP object mapper
AnswerA

Panorama supports integrating with cloud secrets managers like AWS Secrets Manager to securely fetch credentials.

Why this answer

Panorama external services integration allows retrieval of secrets from AWS Secrets Manager or Azure Key Vault for use in API integrations and User-ID.

206
MCQmedium

An architect is designing an automated workflow using Python and the Palo Alto Networks REST API. The script needs to retrieve operational state data from a managed firewall via Panorama using the XML-to-JSON or native REST endpoints. Which API route format is standard for executing operational commands via the PAN-OS XML/REST API structure?

A./api/?type=op&cmd=<show><system><info></info></system></show>
B./api/?type=report&reporttype=custom
C./restapi/v1.0/config/devices/entry[@name='localhost.localdomain']/deviceconfig
D./api/?type=config&action=get&xpath=/config/devices
AnswerA

The 'type=op' parameter with a wrapped XML command in the 'cmd' query string is the standard API syntax for operational queries.

Why this answer

The standard XML API operational command path format uses /api/?type=op&cmd=...

207
Multi-Selectmedium

An architect is reviewing the deployment of DNS Security. Which THREE security use cases are directly addressed by the DNS Security cloud-delivered service? (Choose three)

Select 3 answers
A.Identification and blocking of known malicious domains associated with botnets and malware distribution.
B.Automatic compilation of physical switch VLAN trunking protocols (VTP).
C.Mitigation of DNS tunneling attacks used for data exfiltration and covert communication.
D.Detection and blocking of Domain Generation Algorithms (DGAs) used by malware for command-and-control.
E.Local static IP address assignment for DHCP client reservations on corporate VLANs.
AnswersA, C, D

DNS Security blocks known malicious domains via threat intelligence feeds.

Why this answer

DNS Security addresses DGA domains, DNS tunneling, and known malicious domains/C2 servers operating over DNS.

208
MCQhard

An architect is designing an automated deployment pipeline for VM-Series firewalls using Terraform. When creating the initialization configuration for bootstrapping, which file contains the management IP address, gateway, and static routes if DHCP is not used?

A.authcodes.txt
B.init-cfg.txt
C.bootstrap.xml
D.panorama.conf
AnswerB

init-cfg.txt defines basic parameters such as static IP, netmask, default gateway, and Panorama IP addresses.

Why this answer

In VM-Series bootstrap packages, the init-cfg.txt file located in the config directory specifies initial settings like IP address, netmask, default gateway, and Panorama connection details.

209
MCQhard

An enterprise architect is deploying GlobalProtect for Zero Trust Network Access (ZTNA) across 20,000 remote endpoints. The design requires that device posture checks (checking for corporate certificate, disk encryption, and active endpoint protection) be evaluated before granting network access. Which feature combination should the architect configure?

A.Static IPsec pre-shared keys configured on standard native OS VPN clients
B.Standard HTTP basic authentication prompts combined with local administrator username/password files
C.RADIUS authentication to an external OTP token server without any endpoint compliance agent
D.GlobalProtect HIP (Host Information Profile) checks combined with HIP-based Security Policy rules on the firewall
AnswerD

Correct. HIP gathers endpoint posture data, and HIP objects/profiles are used in security rules to enforce continuous posture assessment.

Why this answer

GlobalProtect Host Information Profile (HIP) checks the security posture of the endpoint and sends the data to the firewall, where HIP-based objects can be enforced within security policy rules.

210
Multi-Selecthard

When deploying VM-Series firewalls behind an AWS Gateway Load Balancer (GWLB), which THREE characteristics or requirements are true regarding the architecture? (Choose three)

Select 3 answers
A.GWLB requires BGP peering to be configured directly between the load balancer and the firewalls.
B.VM-Series firewalls can be scaled out horizontally across multiple availability zones behind the GWLB.
C.GWLB uses the GENEVE protocol on UDP port 6081 to encapsulate packets sent to the VM-Series appliances.
D.The VM-Series firewall data interfaces must terminate the GENEVE encapsulated traffic.
E.GWLB alters the source and destination IP addresses of the packets passing through it.
AnswersB, C, D

GWLB supports horizontal auto-scaling of security appliance pools across AZs.

Why this answer

GWLB uses GENEVE encapsulation, inspects traffic transparently at Layer 3 without modifying IP headers, and scales horizontally with target groups.

211
Multi-Selecthard

An enterprise architect is designing a disaster recovery (DR) strategy for Panorama managing hundreds of VM-Series firewalls across AWS and Azure. Which THREE components are essential for a robust Panorama high availability or backup and recovery design? (Choose three)

Select 3 answers
A.Backing up Panorama VM virtual disks directly to public S3 buckets using unencrypted plain text.
B.Redundant Panorama Log Collectors configured in HA collector groups for log resilience.
C.Maintaining synchronized Template and Device Group hierarchies across primary and secondary management nodes.
D.Relying on manual local text file copies on each individual VM-Series firewall instead of Panorama.
E.Regular scheduled exports of Panorama device state configuration snapshots.
AnswersB, C, E

Log collector groups ensure log data is not lost if a collector fails.

Why this answer

Panorama DR planning involves regular configuration backups, state/log collector replication, and maintaining synchronized template/device group hierarchies.

212
Multi-Selectmedium

Which TWO deployment patterns are supported for integrating VM-Series firewalls into Microsoft Azure enterprise networks? (Choose two)

Select 2 answers
A.Hub-Spoke VNet architecture with User Defined Routes (UDRs) steering traffic to the hub firewalls
B.Azure Virtual WAN (vWAN) secured virtual hub integration with VM-Series as third-party NVA
C.Replacing the Azure cloud control plane with PAN-OS kernel code
D.Direct physical stacking of VM-Series software onto Azure physical datacenter routers
E.Running VM-Series firewalls as native extensions inside Azure SQL databases
AnswersA, B

Hub-Spoke with UDRs is a standard design pattern for Azure.

Why this answer

VM-Series in Azure can be deployed using Hub-Spoke architectures or Azure Virtual WAN secured virtual hubs.

213
MCQeasy

An administrator needs to push a software and content update (such as Applications and Threats) to 200 firewalls managed by Panorama. To prevent network disruption during business hours, the administrator wants to schedule the download and installation during a maintenance window. Where in Panorama is this configured?

A.Panorama > Setup > Operations > Software
B.Monitor > Reports > Schedules
C.Panorama > Device Deployment > Dynamic Updates
D.Device > Setup > Content
AnswerC

This menu path is where software and content updates are scheduled and managed across device groups and firewalls.

Why this answer

Panorama > Device Deployment > Dynamic Updates allows administrators to schedule software, antivirus, wild-fire, and app-threat updates for managed firewalls.

214
Multi-Selecteasy

An architect is designing identity management at scale using Palo Alto Networks solutions. Which TWO components or services are key components of Palo Alto Networks identity ecosystem? (Choose two)

Select 2 answers
A.Cloud Identity Engine (CIE) for cloud-delivered enterprise identity synchronization and authentication
B.Static SNMP v1 trap community strings
C.PAN-OS User-ID feature set integrating with Active Directory, LDAP, and Syslog sources
D.Physical Layer 1 Ethernet patch cable labeling standards
E.Local firewall CLI root password rotation scripts written in bash
AnswersA, C

Correct. CIE provides cloud-scale identity synchronization.

Why this answer

The Cloud Identity Engine and User-ID (via agents, API, or service mapping) form the core identity ecosystem in PAN-OS architectures.

215
Multi-Selecthard

An architect is designing a high-availability identity resolution architecture using Palo Alto Networks User-ID. If primary Active Directory domain controllers fail, the design must maintain identity awareness without administrative intervention. Which THREE architectural mechanisms support this resilience? (Choose three)

Select 3 answers
A.Integrating Syslog forwarding from multiple identity and authentication sources as a secondary mapping source
B.Configuring multiple redundant User-ID agents pointing to different domain controllers across the forest
C.Configuring multiple Active Directory server monitor connections directly on the firewalls for failover capability
D.Permanently disconnecting all directory servers and relying solely on manual CLI IP typing
E.Disabling User-ID failover timeouts and setting retry intervals to infinity
AnswersA, B, C

Correct. Syslog provides an alternative ingestion path if direct DC queries fail.

Why this answer

Resilient identity architecture relies on multiple redundant User-ID agents, multiple domain controller server monitors, and Panorama log forwarding fallback mechanisms.

216
Multi-Selectmedium

When deploying Prisma Access for mobile users, an architect must configure service connections and remote networks. Which TWO statements accurately describe the function of Service Connections in Prisma Access? (Choose two)

Select 2 answers
A.They enable mobile users to access internal corporate applications residing behind your enterprise firewall.
B.They replace the need for GlobalProtect client software on mobile user laptops.
C.They act as standalone public web servers hosting enterprise SaaS portals.
D.They provide secure, high-speed connectivity from Prisma Access to corporate headquarters or data centers.
E.They perform local Wi-Fi channel optimization at branch office locations.
AnswersA, D

Internal application access for mobile users is routed through Service Connections.

Why this answer

Service Connections connect Prisma Access to corporate headquarters or data centers, allowing mobile users to access internal applications and supporting secure routing.

217
MCQhard

An architect is troubleshooting asymmetric routing issues in a multi-region AWS deployment where VM-Series firewalls are deployed behind an AWS Gateway Load Balancer. The logs show drops due to 'tcp-non-syn'. What is the root cause and standard remediation?

A.Configuring static ARP entries on the VM-Series data interfaces
B.Disabling TCP SYN validation globally on the Panorama managed firewalls
C.Switching from AWS Gateway Load Balancer to an internal Application Load Balancer
D.Ensuring cross-zone load balancing is enabled on the GWLB target groups so flows return through the same firewall
AnswerD

Cross-zone load balancing and correct GWLB configuration ensure bidirectional traffic hits the same firewall instance.

Why this answer

Asymmetric routing occurs when return traffic bypasses the original firewall instance. With GWLB, flow stickiness is maintained using GENEVE flow hashes, but misconfigured routing tables or multiple AZ crossings can cause asymmetry.

218
Multi-Selecthard

An architect is troubleshooting a high availability (HA) split-brain scenario in an active/passive VM-Series deployment in a public cloud. Which THREE factors or misconfigurations typically cause split-brain conditions in cloud HA environments? (Choose three)

Select 3 answers
A.Running different PAN-OS minor patch versions on the HA pair for an extended period.
B.Misconfigured path monitoring that fails to detect upstream routing failures.
C.Using identical MAC addresses on all data plane interfaces without cloud hypervisor support.
D.Excessive packet loss or high latency on the dedicated HA heartbeat network path.
E.Network Security Groups or firewall rules blocking UDP/TCP ports used for HA1 and HA2 communication.
AnswersB, D, E

Improper path monitoring prevents the active unit from stepping down when isolated.

Why this answer

Split-brain in cloud HA can be caused by blocking HA communication ports in security groups, intermittent packet loss on HA1/HA2 links, or misconfigured path monitoring failing to trigger state changes.

219
MCQmedium

You are designing a hybrid cloud architecture where an on-premises datacenter connects to an Azure Virtual Network (VNet) via ExpressRoute. To ensure all inter-VNet and hybrid traffic passes through a pair of VM-Series firewalls deployed in a hub VNet, what Azure feature must you configure on the hub VNet gateway subnet?

A.ExpressRoute FastPath configuration
B.User Defined Route (UDR) table associated with the GatewaySubnet
C.Virtual Network peering remote gateways setting
D.Azure Firewall Manager Route Propagation
AnswerB

Associating a UDR with the GatewaySubnet forces gateway traffic to route to the VM-Series security appliance.

Why this answer

To steer traffic from an ExpressRoute or VPN gateway through a hub-spoke security architecture, a User Defined Route (UDR) must be associated with the GatewaySubnet pointing to the firewall's internal load balancer or interface.

220
MCQhard

An architect is designing a multi-tenant Prisma Access architecture. Different business units require segregated mobile user access policies while sharing the same GlobalProtect infrastructure. Which Prisma Access feature enables this logical separation?

A.GlobalProtect client-side virtual routing and forwarding (VRF) configuration
B.Configuring static IPsec crypto maps on the GlobalProtect client adapter.
C.Panorama Device Groups and security policy rule segmentation tailored for distinct Prisma Access mobile user zones.
D.Deploying separate physical firewalls at every Prisma Access cloud location.
AnswerC

Administrators use Panorama Device Groups and distinct security zones/rules to segregate traffic for different business units in Prisma Access.

Why this answer

Prisma Access supports containerization and multi-tenancy or rule-based administrative scoping using Panorama device groups and address/zone separation. Furthermore, Prisma Access allows configuring separate Mobile User Container / Service Setup structures or security domains.

221
Multi-Selectmedium

An architect is designing mobile user security with Prisma Access. Which TWO deployment modes are supported for connecting mobile users to Prisma Access? (Choose two)

Select 2 answers
A.Explicit proxy mode using the GlobalProtect app configuration.
B.Traditional site-to-site GRE tunneling from user web browsers.
C.GlobalProtect VPN tunnel mode (IPsec and SSL).
D.Direct client-side BGP peering between the laptop and the public cloud gateway.
E.Manual PPTP dial-up connections managed via Panorama.
AnswersA, C

Prisma Access supports explicit proxy configuration for mobile user web traffic.

Why this answer

Prisma Access for mobile users supports GlobalProtect app connections in both explicit proxy mode and IPsec/SSL VPN tunnel mode.

222
MCQmedium

An architect is designing security policy optimization using Panorama. The security team needs to identify rules that have not been hit in the last 90 days to clean up the rulebase. Which Panorama tool should the architect use?

A.WildFire malicious sample submission logs
B.Traffic log export to Excel with manual VLOOKUP formulas
C.Panorama Policy Optimizer rule usage hit count tracking
D.GlobalProtect client posture assessment reports
AnswerC

Correct. Policy Optimizer provides built-in rule hit count tracking to identify unused rules.

Why this answer

Policy Optimizer in Panorama tracks hit counts and usage statistics for every security rule, allowing administrators to easily identify unused or stale rules.

223
MCQeasy

When deploying a VM-Series firewall on Microsoft Azure, how many network interfaces (NICs) are minimally required to implement a standard 3-subnet architecture (Management, Trust, Untrust)?

A.2 NICs
B.1 NIC
C.3 NICs
D.4 NICs
AnswerC

3 NICs allow dedicated interfaces for management, untrust, and trust subnets.

Why this answer

A typical production deployment of a VM-Series firewall in Azure requires at least 3 NICs: management, untrust (external), and trust (internal).

224
Multi-Selectmedium

An architect is designing an enterprise deployment where Advanced URL Filtering must block known malicious or risky web categories. Which THREE categories are commonly recommended for blocking or high-risk alerting in corporate environments? (Choose three)

Select 3 answers
A.Malware (sites hosting malicious binaries and payloads).
B.Reference and News (general informational and news publishing portals).
C.Phishing (sites attempting credential theft and social engineering).
D.Computer and Internet Info (technical documentation and software support forums).
E.Proxy Avoidance and Anonymous Surfing (sites offering tools to bypass corporate security controls).
AnswersA, C, E

Malware sites represent active security threats and are blocked.

Why this answer

High-risk web categories commonly blocked include malware, phishing, and proxy-avoidance/anonymous-proxies.

225
MCQmedium

An enterprise deploys VM-Series firewalls in an Azure Hub-Spoke topology. Spoke VNets must communicate with each other exclusively through the hub VM-Series firewalls. What Azure construct prevents spoke VNets from bypassing the firewall by communicating directly via VNet peering?

A.Enabling Azure DDoS Protection Standard on all spoke subnets
B.Disabling 'Allow Forwarded Traffic' on the VNet peering settings and enforcing UDRs in spoke subnets
C.Deploying Azure Bastion hosts in each spoke VNet
D.Configuring Azure ExpressRoute Global Reach between all spokes
AnswerB

To force traffic through the hub firewall, spoke subnets must use UDRs pointing to the firewall, and peering must be carefully structured.

Why this answer

By default, Azure VNet peering allows direct traffic between peered VNets unless peerings are configured without gateway transit, or UDRs/Network Security Groups (NSGs) are used to block direct traffic, or peering routes are overridden.

Page 2

Page 3 of 4

Page 4

All pages