Courseiva

Certified Next-Generation Firewall Engineer (NGFW-Engineer) (NGFW-Engineer) — Questions 175

190 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQeasy

You are configuring a new NGFW and need to ensure administrative access is restricted to a specific management subnet. Which interface setting should you modify to enforce this?

A.Management Interface Settings
B.Service Route Configuration
C.Device > Setup > Session
D.Network Profile - Interface Management
AnswerA

The Management Interface Settings allow an administrator to specify allowed IP addresses for the management port.

Why this answer

The Management Interface Settings allow you to define an allowed IP address list to restrict access to the management plane.

2
MCQeasy

Which of these is a valid way to define a source IP in a policy?

A.Interface Name
B.Address Object
C.Zone Name
D.Virtual Router Name
AnswerB

Address objects are the preferred way to define IPs.

Why this answer

You can use an IP address, subnet, or Address Object to define the source IP in a policy rule.

3
MCQmedium

What is the best way to monitor the firewall's CPU and memory usage?

A.The CLI 'show version'
B.Dashboard system resources
C.System logs
D.The traffic logs
AnswerB

The dashboard provides live system utilization charts.

Why this answer

The Dashboard tab contains system resources widgets that show real-time CPU and memory load.

4
Multi-Selectmedium

Which THREE items are defined in an IKE Crypto Profile?

Select 3 answers
A.Tunnel interface IP
B.Proxy ID
C.Hashing algorithm
D.Diffie-Hellman group
E.Encryption algorithm
AnswersC, D, E

Phase 1 setting.

Why this answer

IKE Crypto Profiles define encryption algorithms, hashing algorithms, and Diffie-Hellman groups for Phase 1.

5
MCQhard

What is the purpose of 'Path Monitoring' in HA?

A.Monitor link state of the peer
B.Monitor VPN tunnel state
C.Monitor reachability of critical resources
D.Monitor traffic volume
AnswerC

This triggers failover if the path is down.

Why this answer

Path Monitoring allows the firewall to monitor reachability to critical network resources (like a gateway or server); if the path fails, the firewall can trigger an HA failover.

6
MCQhard

When troubleshooting routing, which command allows you to test the path of a packet?

A.test routing fib-lookup
B.traceroute
C.show routing route
D.ping
AnswerA

This command tests where a packet will be routed for a given destination IP.

Why this answer

The 'test routing fib-lookup' command is the primary tool for verifying how the firewall will route a packet.

7
MCQhard

You are troubleshooting a REST API integration where Python scripts are failing to retrieve device information. The API returns a '403 Forbidden' error. What is the most likely cause?

A.The API Key is expired.
B.The JSON body is malformed.
C.The admin account lacks permissions for the requested object.
D.The API endpoint URL is incorrect.
AnswerC

403 Forbidden implies authentication was successful, but authorization failed.

Why this answer

A 403 error indicates that the API key provided has insufficient permissions or the admin account associated with the key lacks the necessary role to access the resource.

8
MCQeasy

Where do you configure the DNS servers that the firewall itself uses to resolve hostnames for updates?

A.Network > Virtual Routers
B.Network > Interfaces
C.Objects > Services
D.Device > Setup > Services
AnswerD

DNS and NTP settings are configured here for management plane use.

Why this answer

DNS settings for the firewall management plane are found under Device > Setup > Services.

9
MCQmedium

How can you verify the status of a tunnel interface?

A.Check the system logs
B.Use the CLI command 'show interface tunnel.<id>'
C.Review the routing table
D.Ping the tunnel interface
AnswerB

This CLI command provides real-time tunnel stats.

Why this answer

The 'show interface tunnel.<id>' command displays the status, packet counts, and errors for the tunnel interface.

10
MCQmedium

Which tool in the Palo Alto Networks ecosystem is designed specifically for automated orchestration of security workflows?

A.Panorama
B.AutoFocus
C.Cortex XSOAR
D.Expedition
AnswerC

XSOAR is built for security automation.

Why this answer

Cortex XSOAR is the industry-leading SOAR platform designed for security orchestration and automation.

11
MCQhard

What is the purpose of the 'Policy Optimizer' feature?

A.To increase throughput
B.To identify and clean up unused rules
C.To update threat signatures
D.To automatically create NAT rules
AnswerB

Policy Optimizer is designed to streamline rulebases.

Why this answer

Policy Optimizer helps identify unused rules and improve policy efficiency by suggesting changes to security rules.

12
MCQhard

In GlobalProtect, what is the 'Portal' vs. 'Gateway'?

A.Portal handles traffic, Gateway distributes config
B.Portal distributes config, Gateway handles traffic
C.They are the same thing
D.Portal is for internal users only
AnswerB

Clear distinction between management and data plane.

Why this answer

The Portal is responsible for distributing the configuration/client software, while the Gateway handles the actual tunnel and traffic enforcement.

13
Multi-Selectmedium

Which TWO objects can be used to identify traffic in an Application Override policy?

Select 2 answers
A.Source Address
B.Security Profile
C.User Group
D.URL Category
E.Service
AnswersA, E

Matching traffic origin.

Why this answer

Application override matches traffic based on source, destination, and service (port/protocol).

14
MCQhard

A firewall is experiencing high CPU usage during traffic spikes. You suspect that App-ID is performing too much scanning on internal traffic. Which action should you take to optimize performance while maintaining security?

A.Increase the packet buffer size in Device > Setup.
B.Disable the Content-ID engine globally.
C.Create an Application Override policy for known trusted internal traffic.
D.Enable 'Strict' mode in the App-ID engine.
AnswerC

Application Override skips the App-ID engine for specific traffic, which significantly reduces CPU load for known traffic flows.

Why this answer

Creating an App-ID override or adjusting security policies to use more specific signatures can reduce unnecessary processing, but creating an Application Filter/Group is the standard method for management; however, using 'Application Override' is the direct way to bypass App-ID for known, trusted traffic.

15
Multi-Selectmedium

Which TWO of the following settings are required when configuring a Service Route to ensure the firewall uses a specific interface for external traffic?

Select 2 answers
A.Destination MAC address
B.Source IP address
C.Source Interface
D.Default Gateway
E.VLAN Tag
AnswersB, C

The source IP ensures the response traffic returns correctly.

Why this answer

Service routes require defining the source interface and the source IP address for specific services.

16
MCQmedium

When configuring an interface, what is the role of a 'Security Zone'?

A.To assign an IP address
B.To enable management
C.To handle routing
D.To associate the interface with policy rules
AnswerD

Policies refer to zones, and interfaces belong to zones.

Why this answer

Assigning an interface to a security zone makes it eligible for participation in security policies.

17
MCQhard

In a Site-to-Site VPN, which setting determines how the firewall handles traffic that does not match the phase 2 selector?

A.Proxy ID
B.Re-key interval
C.Dead Peer Detection
D.IKE Crypto Profile
AnswerA

Proxy IDs specify the tunnel traffic flow.

Why this answer

The Proxy ID configuration in the IKE Gateway/IPsec tunnel settings defines exactly which traffic (source/destination/protocol) is permitted through the tunnel; unmatched traffic is dropped or routed outside the tunnel.

18
MCQmedium

What is the purpose of an 'Aggregate Ethernet' interface?

A.Route traffic to different zones
B.Apply security policies to specific VLANs
C.Combine interfaces for throughput/redundancy
D.Manage HA links
AnswerC

Definition of link aggregation.

Why this answer

Aggregate Ethernet (AE) allows you to combine multiple physical interfaces into one logical interface for higher throughput and link redundancy.

19
Multi-Selecteasy

Which TWO interface types support IP addresses?

Select 2 answers
A.Aggregate Ethernet (Layer 2)
B.Tap interface
C.Layer 3 interface
D.Virtual Wire interface
E.Loopback interface
AnswersC, E

Standard L3 interface.

Why this answer

Layer 3 and Loopback interfaces support IP addresses.

20
MCQhard

A network administrator needs to ensure that internal users can access a public-facing web server located in the DMZ using its public IP address (Hairpin NAT). The policy exists, but traffic is being dropped. Which configuration step is critical to enable this?

A.The NAT rule must have the destination zone set to the DMZ and the source interface as the internal interface.
B.Enable 'Disable Server Response Inspection' on the NAT policy.
C.Set the security policy action to 'Allow' and enable 'Source Translation'.
D.Configure an external Proxy ARP entry for the public IP address.
AnswerA

For hairpin NAT, the firewall must be able to route the traffic from the internal zone back into the DMZ zone via a NAT policy that matches the source/destination criteria.

Why this answer

Hairpin NAT requires the security policy to allow the traffic into the zone where the server resides and for the NAT rule to be correctly configured with the source zone set to the internal zone.

21
Multi-Selectmedium

Which THREE settings are configured in a Layer 3 interface?

Select 3 answers
A.Virtual Router
B.Aggregate setting
C.Security Zone
D.IP address
E.Management Profile
AnswersA, C, D

Required for routing.

Why this answer

L3 interfaces require an IP address, a zone assignment, and an association with a virtual router.

22
MCQeasy

What is the default action for the 'interzone-default' security policy?

A.Alert
B.Drop
C.Allow
D.Reset
AnswerB

The firewall defaults to a 'deny all' stance.

Why this answer

The default security policy for traffic moving between different zones is to drop it.

23
Multi-Selectmedium

Which TWO of the following are valid methods to authenticate administrators to the firewall?

Select 2 answers
A.LDAP
B.Local Database
C.Syslog
D.NTP
E.DHCP
AnswersA, B

LDAP is a standard supported method.

Why this answer

PAN-OS supports various authentication methods including local database, LDAP, RADIUS, and TACACS+.

24
Multi-Selecthard

Which THREE features are associated with Threat Prevention?

Select 3 answers
A.Anti-Spyware
B.Antivirus
C.Data Filtering
D.URL Filtering
E.Vulnerability Protection
AnswersA, B, E

C2 protection.

Why this answer

Threat prevention includes Antivirus, Anti-Spyware, and Vulnerability Protection profiles.

25
MCQeasy

What is the default behavior when a firewall is configured for HA but the control link fails?

A.The firewall reboots
B.Traffic is dropped immediately
C.Potential split-brain condition
D.The passive firewall takes over
AnswerC

Lack of sync leads to uncontrolled state.

Why this answer

If the HA control link fails, the firewalls may lose synchronization, and both could potentially try to become 'Active' (a split-brain scenario) unless heartbeat link monitoring is correctly configured.

26
Multi-Selectmedium

Which TWO of the following are valid methods for an administrator to authenticate to the Palo Alto Networks firewall management plane?

Select 2 answers
A.Local Database
B.DNS
C.RADIUS
D.DHCP
E.NTP
AnswersA, C

Local authentication is a standard built-in feature.

Why this answer

Administrators can authenticate using local database accounts or external services like RADIUS or TACACS+.

27
MCQmedium

What happens if a zone is not assigned to an interface?

A.The interface cannot be used in a policy
B.The interface drops all traffic
C.The firewall will automatically create a zone
D.The interface becomes a management-only port
AnswerA

Zone membership is required for policy usage.

Why this answer

The interface cannot be used in a security policy, effectively making it unusable for traffic management through the firewall.

28
MCQmedium

Which object defines the encryption settings for a Site-to-Site VPN?

A.Virtual Router
B.IPsec Crypto Profile
C.Tunnel Interface
D.IKE Crypto Profile
AnswerD

This profile handles IKE phase parameters.

Why this answer

The IKE Crypto Profile defines the encryption, hashing, and DH group settings for the IKE negotiation phase.

29
Multi-Selecthard

Which TWO issues can prevent BGP from reaching the 'Established' state?

Select 2 answers
A.Router ID mismatch
B.Blocked TCP port 179
C.AS number mismatch
D.Keepalive timer mismatch
E.Area ID mismatch
AnswersB, C

Prevents session startup.

Why this answer

BGP will not establish if there is a mismatch in AS numbers or if TCP port 179 is blocked.

30
MCQhard

In a complex automation environment, how can you ensure the integrity of the firewall configuration across multiple automated runs?

A.Using only the CLI.
B.Disabling the API after every run.
C.Performing periodic 'get' requests to verify current state against the desired state.
D.Using only static IP addresses.
AnswerC

State verification is essential for idempotent automation.

Why this answer

Regularly fetching and verifying the 'running-config' against a known-good baseline or source-of-truth is critical for integrity.

31
Multi-Selecteasy

Which TWO items must match for an OSPF adjacency to form?

Select 2 answers
A.Area ID
B.Hello Timer
C.Router Priority
D.Interface Speed
E.Interface Description
AnswersA, B

Must be the same.

Why this answer

OSPF requires Area ID and Hello/Dead timers to match to form an adjacency.

32
Multi-Selecthard

Which THREE steps are involved in the standard User-ID agentless configuration?

Select 3 answers
A.Configure a Service Account
B.Configure an IPsec tunnel
C.Enable WMI or WinRM
D.Install software on every user PC
E.Add Domain Controller to Server Monitoring
AnswersA, C, E

Needed for permissions.

Why this answer

Agentless User-ID requires defining a service account, enabling WMI/WinRM, and adding the domain controller as a server to monitor.

33
MCQeasy

What must you do after making any change in the web interface to make it active?

A.Commit the configuration
B.Log out
C.Refresh the browser
D.Save the configuration
AnswerA

Commit is required to move changes to the running configuration.

Why this answer

Changes on a Palo Alto firewall are 'staged' and only active once the 'Commit' button is pressed.

34
Multi-Selectmedium

Which TWO actions are required to successfully integrate a new External Dynamic List (EDL)?

Select 2 answers
A.Install an SSL certificate for the list source.
B.Enable threat prevention logs.
C.Configure the refresh interval.
D.Restart the firewall.
E.Define the URL/IP source location.
AnswersC, E

The refresh interval determines how often the firewall updates the list.

Why this answer

You must define the source URL and set the update frequency in the EDL object.

35
MCQmedium

When configuring an interface for DHCP client, where do you set this?

A.Device > Setup > Management
B.Network > DHCP
C.Network > Virtual Router
D.Network > Interfaces > [Interface] > IPv4
AnswerD

This is the correct configuration path.

Why this answer

In the Network > Interfaces > [Interface Name] > IPv4 tab, you can select 'DHCP' for the IP configuration.

36
MCQmedium

You are experiencing issues with traffic passing through the firewall. What command is used to see the session table in the CLI?

A.debug dataplane show sessions
B.show system info
C.test policy match
D.show session all
AnswerD

This command lists all current sessions.

Why this answer

The 'show session all' command is the standard way to view active sessions on the firewall.

37
Multi-Selectmedium

Which TWO items are required to configure a site-to-site IPsec VPN?

Select 2 answers
A.Tunnel Interface
B.DHCP Server
C.Management Profile
D.URL Filtering
E.IKE Gateway
AnswersA, E

Required for routing traffic into the tunnel.

Why this answer

VPN configuration requires a tunnel interface, a crypto profile (IKE/IPsec), and a static/dynamic route.

38
Multi-Selectmedium

Which THREE items can be assigned to a Security Zone?

Select 3 answers
A.Physical interfaces
B.Virtual routers
C.Tunnel interfaces
D.Management interfaces
E.Sub-interfaces
AnswersA, C, E

Valid zone member.

Why this answer

Physical interfaces, sub-interfaces, and tunnel interfaces can all be assigned to security zones.

39
MCQmedium

A administrator is configuring a VPN. What does the 'Local IP' in the IKE Gateway represent?

A.The firewall interface address for VPN
B.The virtual router IP
C.The internal network IP address
D.The client machine's IP
AnswerA

The source/destination IP for the IKE tunnel.

Why this answer

The Local IP is the interface IP address on the firewall that will initiate or receive the VPN connection.

40
MCQmedium

You are configuring a virtual wire interface. Which setting is required to ensure that traffic is passed between the two interfaces?

A.Configure an IP address on both interfaces
B.Assign a security zone to each interface
C.Create a loopback interface
D.Enable dynamic routing on the virtual wire
AnswerB

Virtual wire interfaces require zone assignment to participate in security policies.

Why this answer

Virtual wire requires a vwire object mapping two interfaces; once the object is assigned to the interfaces, traffic is passed based on the virtual wire security policy.

41
MCQmedium

How do you back up the firewall's configuration?

A.Export the configuration file
B.Delete the current config
C.Restart the firewall
D.Clear the logs
AnswerA

Exporting the XML config file creates a backup.

Why this answer

The 'Export' option in the Device > Setup > Operations tab allows for taking a configuration snapshot.

42
MCQmedium

An administrator needs to ensure that the firewall uses a specific internal server for DNS resolution of external traffic. Where must this be configured?

A.Network > Interfaces
B.Network > Virtual Routers
C.Device > Setup > Service Route Configuration
D.Device > Setup > Services
AnswerC

Service routes allow you to override default routing for specific services like DNS.

Why this answer

Service routes are used to define which interface the firewall uses to reach services like DNS, NTP, and updates.

43
MCQhard

How do you ensure that only the most secure TLS versions are used for management access?

A.Through an Interface Management Profile
B.Via SSL/TLS Service Profile
C.By disabling HTTPS
D.Using a Security Policy
AnswerB

This profile defines which cipher suites and TLS versions are permitted.

Why this answer

SSL/TLS service settings under Device > Setup > Management > SSL/TLS Service Profile allow you to restrict minimum TLS versions.

44
MCQhard

You are troubleshooting a REST API integration issue where the firewall returns '400 Bad Request'. What should you check first?

A.The server's internal firewall status.
B.The request payload syntax.
C.The network latency between client and firewall.
D.The API Key expiry date.
AnswerB

400 implies the server cannot process the request structure.

Why this answer

A 400 error indicates that the request sent by the client is malformed or invalid according to the API schema.

45
MCQhard

You are deploying an HA pair. You need to ensure that the session state is synchronized immediately to prevent drops during a failover. Which setting ensures this?

A.Device > High Availability > Election Settings
B.Device > High Availability > HA1/HA2 configuration
C.Device > High Availability > Link and Path Monitoring
D.Device > High Availability > General
AnswerB

The HA2 link carries the session state synchronization data.

Why this answer

Session synchronization settings within the HA configuration are required to ensure session tables are mirrored across peers.

46
MCQmedium

When using the Panorama XML API for a batch operation, what is the purpose of the 'type=config' parameter?

A.To commit changes.
B.To export configuration.
C.To perform configuration changes.
D.To fetch operational data.
AnswerC

'type=config' is for configuration management.

Why this answer

'type=config' is used to perform create, read, update, or delete operations on the device configuration.

47
MCQeasy

What is the primary function of a Virtual Router?

A.Provide security inspection
B.Manage VPN tunnel encryption
C.Maintain the routing table
D.Store firewall logs
AnswerC

Routing tables are the core of VR functionality.

Why this answer

A Virtual Router maintains the routing table and processes packets based on destination IP, performing route lookups for traffic.

48
Multi-Selecthard

Which THREE routing protocols can be configured on a PAN-OS virtual router?

Select 3 answers
A.RIP
B.BGP
C.OSPF
D.IS-IS
E.EIGRP
AnswersA, B, C

Supported protocol.

Why this answer

PAN-OS supports OSPF, BGP, and RIP as the primary dynamic routing protocols.

49
Multi-Selecthard

Which THREE options are available under the 'Actions' tab of a Security Policy?

Select 3 answers
A.Log at Session Start
B.DNS Server
C.Security Profiles
D.Log at Session End
E.NAT Policy
AnswersA, C, D

Allows logging at the beginning.

Why this answer

Common actions include 'Allow', 'Deny', 'Drop', 'Reset', and log forwarding configuration.

50
MCQmedium

How does the firewall determine which virtual router to use for a packet?

A.Based on the zone of the destination interface
B.Based on the destination port
C.Based on the source IP address
D.Based on the virtual router assigned to the ingress interface
AnswerD

Routing happens within the context of the ingress VR.

Why this answer

The firewall uses the virtual router associated with the ingress interface to perform the routing lookup for the packet.

51
MCQmedium

You are configuring a Security Profile to detect and prevent malware. Which profile is most appropriate for identifying malicious files being downloaded?

A.Data Filtering
B.URL Filtering
C.WildFire Analysis
D.Vulnerability Protection
AnswerC

The WildFire Analysis profile manages how files are submitted to the WildFire cloud for malware detection.

Why this answer

The WildFire Analysis profile is specifically designed to identify and sandbox suspicious files to detect malware.

52
MCQhard

What is the consequence of having overlapping IP subnets on different interfaces?

A.Nothing, the firewall handles it
B.Routing ambiguity and traffic delivery failure
C.Increased performance
D.The firewall will automatically bridge them
AnswerB

The routing table cannot resolve which interface to use for the same subnet.

Why this answer

Overlapping subnets cause routing conflicts, leading to unpredictable traffic flow.

53
MCQhard

When using OSPF, what is the 'Router ID' used for?

A.Identifies the router in the OSPF domain
B.Used to encrypt OSPF packets
C.Sets the path metric for routes
D.Determines the interface speed
AnswerA

Router ID is the identity of the OSPF node.

Why this answer

The Router ID is a unique 32-bit identifier used to identify the router in the OSPF autonomous system and is essential for forming adjacencies and identifying the source of LSAs.

54
MCQmedium

Which configuration object allows you to restrict traffic based on geographic location?

A.Address Group
B.GlobalProtect Portal
C.Service Object
D.Region
AnswerD

Region objects represent countries or geographic areas.

Why this answer

Regions in the address object allow you to define rules based on the source or destination country.

55
MCQmedium

An administrator wants to use a specific user's group membership for policy enforcement. What is the requirement?

A.Create a local user database
B.Increase the policy limit
C.Enable User-ID on the zone
D.Enable SSL decryption
AnswerC

Enabling User-ID on the zone is the prerequisite for using group mappings in policies.

Why this answer

User-ID must be configured to map users to groups for group-based policy enforcement.

56
MCQeasy

Where do you view the system logs to troubleshoot hardware issues?

A.Dashboard
B.Device > Setup
C.Network > Interfaces
D.Monitor > Logs > System
AnswerD

This is the correct path for system logs.

Why this answer

The 'Monitor' tab > 'Logs' > 'System' is the central place to see all system-level events.

57
MCQmedium

You are configuring a Palo Alto Networks firewall to support User-ID. You have successfully installed the User-ID agent on a Windows Server and connected it to the firewall. However, the firewall is not mapping IP addresses to usernames. What is the most likely cause?

A.The App-ID database has not been updated to support Windows Server 2022.
B.The User-ID agent needs to be configured with a static XML API key.
C.The Zone Protection profile is blocking the User-ID protocol.
D.The firewall is not configured with a Server Monitoring entry under Device > User Identification > User-ID Agents.
AnswerD

Without the Server Monitoring entry, the firewall will not know which agent to query for logs or map IPs to users.

Why this answer

The firewall requires a server monitoring configuration to be defined for the specific domain controller or server being monitored by the agent.

58
MCQeasy

Which type of interface is used for connecting to a Layer 3 network?

A.Virtual Wire
B.Layer 2
C.Aggregate
D.Layer 3
AnswerD

Layer 3 interfaces handle IP routing.

Why this answer

A Layer 3 interface is required for routing traffic between subnets.

59
MCQeasy

What is a 'Layer 3' interface in PAN-OS?

A.Interface assigned an IP and virtual router
B.Interface bundled for link aggregation
C.Interface used only for management
D.Interface that passes all traffic without inspection
AnswerA

L3 interfaces operate at the network layer.

Why this answer

A Layer 3 interface is assigned an IP address and is associated with a virtual router to route traffic based on the routing table.

60
Multi-Selecthard

Which THREE actions should be performed during a standard automation failure troubleshooting process?

Select 3 answers
A.Validate API key permissions for the target object.
B.Verify the API service status on the firewall.
C.Review system logs for 'auth' or 'API' errors.
D.Update the hardware firmware.
E.Perform a factory reset of the firewall.
AnswersA, B, C

Authorization is a frequent source of failures.

Why this answer

Check logs, verify credentials, and test connectivity to the management interface.

61
MCQmedium

When managing multiple firewalls through Panorama, what is the best way to ensure an automation script performs the same action on all devices in a device group?

A.Looping through each firewall IP.
B.Targeting the device group via the API.
C.Manually logging into each firewall.
D.Using a broadcast address.
AnswerB

Panorama handles the propagation within the device group.

Why this answer

The API allows targeting the device group directly, which Panorama then propagates to the individual firewalls.

62
MCQeasy

Which component is required to enable a firewall to act as an OSPF Area Border Router (ABR)?

A.Enable BGP on all interfaces
B.Configure multiple virtual routers
C.Configure interfaces in multiple OSPF areas
D.Create a tunnel interface for each area
AnswerC

ABRs connect multiple areas.

Why this answer

To be an ABR, the firewall must have interfaces in Area 0 and at least one other non-zero area, configured within the OSPF protocol settings in the virtual router.

63
Multi-Selectmedium

Which TWO types of logs can be forwarded to an external server?

Select 2 answers
A.Traffic Logs
B.Firmware Logs
C.Threat Logs
D.Hardware Logs
E.Interface Stats
AnswersA, C

Commonly forwarded for audit.

Why this answer

PAN-OS supports forwarding almost all log types (Traffic, Threat, System, etc.) to external log collectors.

64
MCQeasy

How do you add a new interface to an existing zone?

A.Use the CLI to move the interface
B.Recreate the zone with all interfaces
C.Update the virtual router settings
D.Edit the zone and add the interface
E.Edit the interface and add the zone
AnswerD

Interface is added via the Zone edit window.

Why this answer

In the Network > Zones tab, select the desired zone and add the interface to the 'Interfaces' list in the zone configuration window.

65
Multi-Selecthard

Which THREE data sources can an NGFW use to dynamically populate address objects?

Select 3 answers
A.Static IP addresses only.
B.Manual packet captures.
C.External Dynamic Lists.
D.User-ID mapping via agents.
E.API injection.
AnswersC, D, E

Direct URL-based list integration.

Why this answer

EDLs, User-ID mapping, and API-based injection are primary methods.

66
MCQmedium

What is the benefit of using a Loopback interface for a GlobalProtect portal?

A.Provides a stable IP address
B.Automatically encrypts traffic
C.Filters traffic based on source
D.Increases throughput for VPN users
AnswerA

Loopbacks never go 'down' based on cable status.

Why this answer

A loopback interface provides a stable IP address that does not depend on the status of a physical link, ensuring the portal remains reachable even if a physical interface flaps.

67
MCQhard

When configuring OSPF on a PAN-OS firewall, what is the impact of setting the dead interval to a value different from the neighbor?

A.The adjacency will not form
B.The firewall will use the lowest timer value
C.Only LSA type 1 updates are exchanged
D.The adjacency forms but drops packets
AnswerA

OSPF state machine requires matching timers for adjacency.

Why this answer

OSPF requires the Hello interval and Dead interval to match exactly between neighbors; a mismatch prevents adjacency formation.

68
MCQmedium

An administrator wants to trigger a script automatically when a security policy is matched. Which feature can be used to send a notification to an external web server?

A.SNMP Trap Profile
B.Service Route Configuration
C.Syslog Server Profile
D.Log Forwarding Profile (HTTP destination)
AnswerD

HTTP destinations allow for webhook integration.

Why this answer

Log Forwarding Profiles allow for HTTP/S integration to send notifications to webhooks or external servers when a log is generated.

69
Multi-Selecthard

Which THREE components are necessary to successfully implement SSL Forward Proxy?

Select 3 answers
A.Root CA Certificate
B.Decryption Profile
C.App-ID
D.Decryption Policy
E.User-ID
AnswersA, B, D

The firewall acts as an intercepting proxy.

Why this answer

SSL decryption requires a root CA certificate, a profile, and the activation of decryption on the policy.

70
MCQhard

You notice that the firewall is not identifying traffic as 'web-browsing' even though it is on port 80. What is the most likely cause?

A.The traffic is non-compliant with the standard protocol
B.App-ID is disabled on the interface
C.Port 80 is not defined in the service object
D.The security policy is set to 'any' service
AnswerA

If the traffic doesn't match the signature, it won't be identified as web-browsing.

Why this answer

App-ID relies on application signatures. If the traffic is not using standard HTTP, it will not be identified as web-browsing.

71
MCQmedium

Which action in a security policy should be used to drop traffic silently without sending a notification to the client?

A.Reset
B.Drop
C.Reject
D.Deny
AnswerB

Drop discards the traffic without response.

Why this answer

The 'Drop' action silently discards the packet, whereas 'Reset' sends a TCP RST or ICMP unreachable.

72
MCQhard

Why might OSPF adjacency stay in 'ExStart/Exchange' state?

A.MTU mismatch on the interfaces
B.Hello timer mismatch
C.Area ID mismatch
D.Authentication key mismatch
AnswerA

OSPF requires matching MTU to exchange DBDs.

Why this answer

An MTU mismatch between the two OSPF peers prevents them from exchanging large Database Description (DBD) packets, causing the state to hang in ExStart/Exchange.

73
MCQhard

You are troubleshooting GlobalProtect and notice the client cannot reach internal resources. Which routing issue is most likely?

A.Missing certificate on the gateway
B.Missing default route on the client machine
C.Missing route in the virtual router to the internal network
D.Incorrect zone on the tunnel interface
AnswerC

The firewall must know where to send traffic arriving from the tunnel.

Why this answer

If the virtual router handling the tunnel interface does not have a route to the internal network, the firewall cannot route the decrypted traffic to the destination.

74
MCQmedium

You want to implement User-ID without installing agents on every server. What is the most efficient method to map IP addresses to usernames?

A.Use IP-to-User static mapping
B.Enable GlobalProtect for internal users
C.Configure Agentless User-ID via Server Monitoring
D.Use the User-ID Agent on a Windows Server
AnswerC

Agentless User-ID allows the firewall to poll domain controllers directly using WMI or WinRM.

Why this answer

The Palo Alto Networks firewall can leverage User-ID agents or agentless methods like querying Active Directory domain controllers via WMI or Syslog.

75
Multi-Selectmedium

Which TWO settings are required to configure an Interface Management Profile?

Select 2 answers
A.Permitted IP Addresses
B.Permitted Services
C.Default Gateway
D.Zone Assignment
E.DNS Server
AnswersA, B

Restricting access to specific IPs is a best practice.

Why this answer

Management profiles specifically enable services (like HTTP, SSH) and define permitted IP addresses.

Page 1 of 3

Page 2

All pages