Courseiva

Certified Next-Generation Firewall Engineer (NGFW-Engineer) (NGFW-Engineer) — Questions 76150

190 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQmedium

Which feature helps to identify and block traffic from compromised hosts based on suspicious behavior?

A.GlobalProtect
B.Threat Prevention Profiles
C.NAT
D.URL Filtering
AnswerB

These profiles scan for malicious behavior and patterns.

Why this answer

Threat Prevention profiles (specifically Anti-Spyware/Vulnerability Protection) detect command-and-control activity and suspicious traffic patterns.

77
Multi-Selecteasy

Which TWO settings are configured in a Virtual Router?

Select 2 answers
A.Management Profile
B.Static Routes
C.Dynamic Routing Protocols
D.Tunnel Interface IPs
E.Security Zones
AnswersB, C

Core functionality.

Why this answer

Virtual routers handle static routes and dynamic routing protocols (like OSPF/BGP).

78
MCQmedium

Which object type should be used to group multiple IP addresses to simplify security policy management?

A.Service Group
B.Address Object
C.Address Group
D.Tag
AnswerC

Address groups are designed to collect multiple address objects into one entity.

Why this answer

Address Groups allow the grouping of multiple address objects, simplifying policy rules.

79
MCQmedium

A administrator needs to route traffic to an internal network via a tunnel. Where is the static route configured?

A.Tunnel Interface settings
B.Zone settings
C.Security Policy
D.Virtual Router
AnswerD

The VR handles routing logic.

Why this answer

Static routes for tunnel traffic are configured in the Virtual Router associated with the tunnel interface.

80
MCQeasy

Which tab allows you to configure the firewall's hostname and domain?

A.Network > Interfaces
B.Objects > Addresses
C.Device > Setup > Management
D.Policies > Security
AnswerC

This contains general identity settings.

Why this answer

Device > Setup > Management > General Settings is the path for setting the firewall's identity.

81
MCQmedium

Which tab is used to view real-time log activity?

A.Objects
B.Policies
C.Dashboard
D.Monitor
AnswerD

Monitor is for log viewing.

Why this answer

The 'Monitor' tab provides real-time access to traffic, threat, and system logs.

82
MCQmedium

You are integrating an NGFW with Panorama for centralized management. You need to ensure that local firewall configurations are not overwritten when the device is imported into Panorama. Which setting in the Panorama > Setup > Operations tab or import process prevents this?

A.Select 'Merge' during the device configuration import process.
B.Set the device to 'Read-Only' mode in the Panorama Web UI.
C.Configure the local firewall as a 'Shared' device in Panorama.
D.Enable 'Force Template Values' on the device group.
AnswerA

Selecting 'Merge' allows the existing local configuration to be integrated into the Panorama structure rather than being wiped by a push.

Why this answer

When importing a device into Panorama, the 'Import device configuration' process allows you to choose to merge or overwrite. To preserve local policy elements, one should use the 'Import into Template Stack' and 'Import into Device Group' workflows with careful selection of the 'Merge' option.

83
MCQhard

You are configuring an Auto-Scaling Group in AWS with the VM-Series. During the bootstrap process, which file is mandatory to ensure the firewall registers with Panorama successfully?

A.license.txt
B.init-cfg.txt
C.bootstrap.xml
D.config.cfg
AnswerB

This file defines the basic registration parameters for Panorama.

Why this answer

The 'init-cfg.txt' file is required for bootstrapping and contains the Panorama IP and authorization key to register the VM.

84
MCQeasy

Where do you configure the tunnel interface IP address in a Site-to-Site VPN setup?

A.Network > Zones
B.Network > GlobalProtect > Gateways
C.Network > Virtual Routers
D.Network > Interfaces > Tunnel
AnswerD

This is the correct path for assigning tunnel IPs.

Why this answer

Tunnel interfaces act as logical points for VPN traffic and are assigned IP addresses in the Network > Interfaces > Tunnel tab.

85
MCQmedium

How do you verify if a security policy is actually matching the traffic you expect?

A.Run a debug flow filter
B.Check the Policy Hit Count in the Policies tab
C.Restart the management plane
D.Check the Traffic Log for policy hits
AnswerB

The hit count is designed exactly for this purpose.

Why this answer

The 'hit count' feature in the policy list provides real-time information on how many sessions have matched a specific rule.

86
Multi-Selectmedium

Which TWO types of files can be included in a bootstrap package?

Select 2 answers
A.init-cfg.txt
B.Hardware drivers.
C.SSL Certificate private key.
D.Binary user database.
E.Firmware/Software image.
AnswersA, E

The primary configuration bootstrap file.

Why this answer

Init-cfg.txt and software images are common components of bootstrap packages.

87
MCQhard

When automating log forwarding to an external SIEM, what is the best practice regarding the management plane load?

A.Enable debug logging on all policies.
B.Increase the log rate limit on the firewall.
C.Use Log Collectors to offload log processing.
D.Send logs via serial console.
AnswerC

Log Collectors handle log storage and forwarding, reducing load on the firewall.

Why this answer

Offloading log management to dedicated log collectors or using efficient forwarding profiles prevents management plane degradation.

88
MCQmedium

Which object type should you use to handle large lists of URLs that you want to block or allow?

A.External Dynamic List
B.Address Group
C.URL Category
D.Service Group
AnswerA

EDLs efficiently manage external lists of URLs/IPs.

Why this answer

External Dynamic Lists (EDL) are specifically designed to ingest and manage large lists of URLs, IPs, or domains.

89
MCQhard

In BGP, which attribute is used to influence the path selection for outgoing traffic?

A.AS_PATH
B.Local Preference
C.MED
D.Weight
E.None of the above
AnswerB

Local Preference dictates outbound exit points.

Why this answer

The 'Local Preference' attribute is used within an AS to influence the path taken by traffic leaving the AS; a higher value is preferred.

90
Multi-Selectmedium

When integrating an NGFW with an external SIEM for log ingestion, which TWO of the following methods are natively supported for log forwarding?

Select 2 answers
A.SNMP Traps
B.REST API push
C.FTP file push
D.Syslog
E.Direct SQL query
AnswersA, D

SNMP Traps are a valid method for alerting SIEM systems.

Why this answer

NGFWs natively support Syslog and SNMP (for traps) to forward log information to external SIEMs.

91
MCQmedium

What is the purpose of the 'Pre-Rulebase' and 'Post-Rulebase' in Panorama?

A.To group devices by region
B.To enforce global policies that cannot be overridden
C.To increase policy processing speed
D.To manage NAT rules specifically
AnswerB

Pre and Post rules provide mandatory security standards.

Why this answer

These allow administrators to enforce global security policies that cannot be modified by local device administrators.

92
MCQeasy

An administrator wants to use a script to back up firewall configurations daily. Which management interface service must be enabled to allow the script to download the config file?

A.SNMP
B.Telnet
C.XML API
D.SSH
AnswerC

The XML API provides the 'keygen' and 'export' commands necessary for automated backup scripts.

Why this answer

The XML API is the standard method for scripts to programmatically export configurations (running-config).

93
Multi-Selecthard

Which TWO conditions can trigger an HA failover?

Select 2 answers
A.Hardware failure
B.Path monitoring failure
C.BGP session reset
D.Excessive log generation
E.Change in management IP
AnswersA, B

Catastrophic failure triggers failover.

Why this answer

Failovers can be triggered by hardware failure or by the firewall losing reachability to monitored paths.

94
Multi-Selecthard

Which THREE items are part of the 'Device > Setup' configuration?

Select 3 answers
A.Address objects
B.Security Policy rules
C.Services (DNS/NTP)
D.Management Interface settings
E.Operations (Backup/Restore)
AnswersC, D, E

Global system services.

Why this answer

Device > Setup covers global configuration like management interfaces, services, and operations.

95
Multi-Selecthard

Which TWO factors contribute to a successful BGP peer establishment?

Select 2 answers
A.Matching interface speed
B.TCP connectivity on port 179
C.OSPF adjacency
D.Matching router descriptions
E.Matching AS numbers
AnswersB, E

Required for transport.

Why this answer

BGP requires matching Autonomous System numbers and TCP connectivity (port 179) between the peers.

96
MCQeasy

Which option is required to use an interface in a security policy?

A.Configure an IP address
B.Define a management profile
C.Assign a security zone
D.Enable a virtual router
AnswerC

Zone assignment is the fundamental requirement.

Why this answer

You must assign a security zone to an interface; only then can that zone be used in a security policy rule.

97
MCQeasy

An administrator needs to quickly identify if an API call was successful from the firewall side. Which log should be reviewed?

A.Traffic logs
B.System logs
C.Threat logs
D.URL logs
AnswerB

System logs track management and API activity.

Why this answer

The 'System' logs contain entries for web interface and API interactions.

98
Multi-Selecthard

Which THREE parameters are commonly used in the XML API to target specific policy objects?

Select 3 answers
A.location (vsys/dg/template)
B.element (the XML tag)
C.api-key-hash
D.system-serial
E.xpath
AnswersA, B, E

Defines the scope of the configuration change.

Why this answer

XPath, Element Name, and Device Group/Template context are standard.

99
MCQmedium

What is the purpose of a 'Zone' in a Palo Alto Networks firewall?

A.To segment the network for routing
B.To increase bandwidth
C.To manage user identities
D.To define the scope of security policies
AnswerD

Policies are applied to zones, not directly to physical interfaces.

Why this answer

Zones are logical groupings of interfaces that allow for the application of security policies to traffic moving between them.

100
MCQmedium

Which feature allows an NGFW to dynamically update security objects based on an external feed such as an IP list or URL list?

A.User-ID Mapping
B.Log Forwarding Profiles
C.External Dynamic Lists
D.Dynamic Address Objects
AnswerC

EDLs are designed specifically for this purpose.

Why this answer

External Dynamic Lists (EDL) allow the firewall to consume lists from external web servers and use them in policies automatically.

101
MCQeasy

Which tab is used to configure logging settings for a specific security policy?

A.Actions
B.General
C.Source
D.Objects
AnswerA

The Actions tab inside the policy rule defines log settings.

Why this answer

The 'Actions' tab within the security policy edit window is where logging options are configured.

102
Multi-Selectmedium

Which TWO types of NAT are supported in PAN-OS?

Select 2 answers
A.Source NAT
B.Destination NAT
C.Global NAT
D.Layer 2 NAT
E.Application NAT
AnswersA, B

For outgoing traffic.

Why this answer

Source NAT and Destination NAT are the two primary NAT types.

103
MCQhard

When troubleshooting a BGP route that is not appearing in the routing table, which command provides the most insight?

A.show interface all
B.show routing protocol bgp rib-in
C.show system state
D.show routing fib
AnswerB

This shows routes before the RIB filter.

Why this answer

The 'show routing protocol bgp rib-in' command shows the prefixes received from peers before they are filtered and installed in the RIB.

104
MCQmedium

An administrator is using Terraform to manage Palo Alto Networks security policies. Which provider resource is used to create a security rule?

A.panos_firewall_rule
B.panos_policy_rule
C.panos_security_policy
D.panos_security_rule
AnswerD

This is the correct Terraform resource for defining security rules.

Why this answer

The 'panos_security_rule' resource is the standard Terraform resource for managing security policies on Palo Alto Networks devices.

105
MCQhard

In an AWS Lambda function automating firewall changes, why should you use the 'pan-os-python' library with 'xapi' directly rather than the higher-level classes?

A.To avoid installing dependencies.
B.To reduce latency and overhead in serverless environments.
C.Because higher-level classes are not compatible with Python.
D.To bypass authentication requirements.
AnswerB

XAPI provides a lower-overhead, stateless interaction.

Why this answer

In serverless environments like Lambda, managing long-lived sessions or complex object hierarchies is often less efficient than raw XML requests via XAPI.

106
MCQmedium

When utilizing the Panorama plugin for AWS, what is the primary benefit of the 'S3 bucket' integration for log ingestion?

A.It provides a scalable destination for log archival and external analysis.
B.It enables real-time packet inspection of S3 traffic.
C.It automatically updates the device's software version.
D.It acts as a primary firewall policy source.
AnswerA

S3 is designed for high-durability storage, making it ideal for log archival.

Why this answer

The S3 integration allows the firewall to offload logs to cloud storage, providing long-term retention and cost-effective storage for compliance without requiring local disk expansion.

107
MCQmedium

A administrator needs to allow traffic between two zones using a specific sub-interface. Which configuration step is mandatory?

A.Add the sub-interface to the default zone
B.Assign the sub-interface to a security zone
C.Configure the sub-interface as a loopback
D.Enable DHCP server on the sub-interface
AnswerB

Zone assignment is mandatory for all interface types.

Why this answer

Interfaces must be assigned to a security zone before they can be referenced in a security policy.

108
MCQhard

You are automating firewall policy updates using the XML API. You have successfully authenticated and retrieved an API key. When attempting to perform an 'edit' operation on a security policy, the API returns an 'Invalid Object' error, even though the object exists in the GUI. What is the most likely cause?

A.The API key does not have the 'Superuser' role.
B.The XPath in the API call does not correctly specify the Device Group or Vsys context.
C.The XML document must be wrapped in a <request> tag.
D.The API service is disabled on the management interface.
AnswerB

When managing objects via Panorama API, the XPath must reflect the hierarchy of the device group or vsys container.

Why this answer

The XML API requires precise XPath syntax. If the object exists in the GUI but the API fails, it is often due to the object being nested within a specific Device Group or Vsys that was not properly specified in the XPath.

109
MCQeasy

To ensure high availability for an automated script, which Panorama component should the script target?

A.Log Collector
B.Active/Passive Peer
C.Individual Firewall Management Plane
D.Panorama Management Server
AnswerD

Panorama provides a centralized API for all managed devices.

Why this answer

Targeting the Panorama M-series or virtual appliance ensures the script manages the entire policy set for all managed firewalls.

110
MCQmedium

What happens if a packet matches no security policies?

A.It is dropped by default
B.It is sent to the management plane
C.It is allowed by default
D.It is logged as a threat
AnswerA

The implicit 'deny all' action drops unmatched traffic.

Why this answer

The 'intrazone-default' and 'interzone-default' rules define the implicit behavior for unmatched traffic, which is to drop.

111
MCQmedium

Where do you configure the 'Heartbeat' interval for HA?

A.Device > Setup > Management
B.Network > Virtual Routers
C.Device > High Availability > General
D.Network > Interfaces > HA
AnswerC

General HA settings contain link/heartbeat parameters.

Why this answer

The heartbeat interval is configured in the HA > General > Election Settings or Heartbeat settings depending on the specific PAN-OS version and HA mode.

112
MCQmedium

You have configured a GlobalProtect VPN, but users cannot access internal resources. What is the first troubleshooting step?

A.Reboot the firewall
B.Disable the security policy
C.Check if the tunnel interface is in the correct Security Zone
D.Update the GlobalProtect client version
AnswerC

If the tunnel interface is not in a zone, security policies cannot be applied to traffic emerging from the VPN.

Why this answer

Checking the tunnel interface and routing is critical, but verifying the zone assignment is the most frequent configuration oversight.

113
Multi-Selectmedium

Which THREE components are involved in a VPN tunnel setup?

Select 3 answers
A.IKE Gateway
B.IPsec Crypto Profile
C.GlobalProtect Portal
D.Tunnel Interface
E.Aggregate Ethernet
AnswersA, B, D

Core component.

Why this answer

VPNs require IKE gateways, IPsec crypto profiles, and tunnel interfaces.

114
MCQeasy

What is the default port for the Panorama XML API?

A.80
B.22
C.8080
D.443
AnswerD

443 is the standard HTTPS port for the API.

Why this answer

The XML API operates over the standard HTTPS port, 443.

115
MCQeasy

What is the purpose of an Aggregate Ethernet (AE) interface?

A.Connect two virtual routers
B.Increase the number of available VLANs
C.Create a secure VPN tunnel
D.Combine physical links for higher bandwidth and redundancy
AnswerD

That is the definition of LACP/AE.

Why this answer

AE interfaces provide increased bandwidth and link redundancy by bundling multiple physical ports into a single logical interface.

116
Multi-Selecthard

Which TWO methods are used to troubleshoot GlobalProtect connectivity issues?

Select 2 answers
A.Change the encryption algorithm
B.Reload the firewall firmware
C.Restart the management plane
D.Check firewall System and GlobalProtect logs
E.Check GP client logs
AnswersD, E

Essential for server-side issues.

Why this answer

Troubleshooting often involves checking the client logs and reviewing the firewall's GlobalProtect logs.

117
Multi-Selectmedium

Which TWO objects can be used as a source in a Security Policy?

Select 2 answers
A.Service Object
B.Address Object
C.Interface
D.User Group
E.Application
AnswersB, D

Standard method for source matching.

Why this answer

Policies can match traffic based on IP addresses, address groups, regions, or User-ID user groups.

118
MCQeasy

Which feature must be enabled to inspect traffic for threats?

A.NAT policy
B.Security Profile Group
C.Log Forwarding
D.App-ID
AnswerB

Security profiles, when attached to a policy, enable threat inspection.

Why this answer

Security profiles (Vulnerability Protection, Antivirus, etc.) must be attached to security policies to perform threat inspection.

119
MCQeasy

Which file type is required for an External Dynamic List (EDL) to function correctly?

A.Plain text (.txt)
B.Binary (.bin)
C.Executable (.exe)
D.Encrypted (.zip)
AnswerA

Text files are the standard for EDLs.

Why this answer

EDLs expect raw text files formatted appropriately for the list type, accessible via HTTP/HTTPS.

120
MCQeasy

Which object type is required to enable GlobalProtect access for remote users?

A.GlobalProtect Zone
B.GlobalProtect Gateway
C.GlobalProtect Router
D.GlobalProtect Interface
AnswerB

Gateway terminates the connection.

Why this answer

The GlobalProtect Gateway is the entity that terminates the VPN tunnel and applies security policies to remote users.

121
MCQhard

An administrator is using the 'pan-os-python' library to automate address object creation. The script succeeds, but objects do not appear in the GUI. What is missing?

A.The object is hidden in the GUI.
B.The API key has insufficient scope.
C.The object was not defined as a constant.
D.The 'commit()' method was not called.
AnswerD

Changes remain in candidate config until committed.

Why this answer

The script modifies the candidate configuration; a 'commit' must be performed to push those changes to the running configuration.

122
MCQhard

You are configuring a BGP peer. The connection stays in 'Active' state. What is the most likely cause?

A.Keepalive timer mismatch
B.AS number mismatch
C.Router ID is the same
D.TCP port 179 is blocked or no route to peer
AnswerD

BGP requires TCP 179 and reachability.

Why this answer

The 'Active' state in BGP usually indicates the firewall is trying to initiate a TCP connection to the neighbor, but is failing, often due to routing or firewall policy blocking port 179.

123
MCQmedium

What is the recommended way to manage certificates on a Palo Alto Networks firewall?

A.Use the Device > Certificate Management tab
B.Apply them via a security policy
C.Store them in a global address object
D.Manually copy files to the CLI
AnswerA

This is the native GUI tool for certificate management.

Why this answer

The Certificate Management section under Device > Certificate Management allows for importing, generating, and managing certificates.

124
MCQmedium

How do you ensure that the firewall automatically blocks traffic from a list of known malicious IP addresses?

A.Create a static address group
B.Manually update the blocklist every hour
C.Configure an External Dynamic List (EDL)
D.Use a Dynamic Address Group based on a registration API
AnswerC

EDLs allow automatic ingestion of blocklists.

Why this answer

External Dynamic Lists (EDL) allow the firewall to ingest and act upon lists of IPs or URLs from a remote source.

125
MCQeasy

Which Palo Alto Networks tool provides a programmatic interface to automate firewall configuration and operational tasks via Python?

A.GlobalProtect API
B.ACC (Application Command Center)
C.Pan-python
D.Panorama XML CLI
AnswerC

Pan-python is the official library designed for automation via Python scripts.

Why this answer

Pan-python is the standard library provided by Palo Alto Networks for interacting with the XML API using Python.

126
MCQeasy

An administrator needs to automate the deployment of security policy updates using Panorama. Which XML API method should be invoked to commit changes to the candidate configuration?

A./api/?type=commit
B./api/?type=config&action=save
C./api/?type=export
D./api/?type=op&cmd=<commit/>
AnswerA

This is the correct path for triggering a configuration commit via the XML API.

Why this answer

The commit operation is performed via the 'commit' tag in the XML API request to the Panorama management server.

127
Multi-Selecthard

Which THREE items are found under the 'Network' tab?

Select 3 answers
A.Zones
B.Interfaces
C.Security Profiles
D.Certificate Management
E.Virtual Routers
AnswersA, B, E

Zone membership config.

Why this answer

The Network tab covers interfaces, virtual routers, and zones.

128
MCQmedium

An administrator wants to ensure that internal users only access approved websites. Which profile is used?

A.Antivirus Profile
B.URL Filtering Profile
C.Data Filtering Profile
D.Vulnerability Protection Profile
AnswerB

URL filtering profiles allow or block categories of websites.

Why this answer

URL Filtering profiles control access to specific categories of websites.

129
MCQhard

A client is receiving a 'Gateway not reachable' error in GlobalProtect. What is a common troubleshooting step?

A.Increase the tunnel encryption level
B.Check the local PC's DHCP settings
C.Verify security policies allow traffic to the gateway
D.Clear the routing cache on the client
AnswerC

GP traffic must be explicitly permitted.

Why this answer

Check if the portal/gateway IP is reachable via ping and if the correct security policies allow the GP traffic from the external zone.

130
Multi-Selecteasy

Which TWO components are involved in configuring GlobalProtect?

Select 2 answers
A.Management Profile
B.Virtual Router
C.Gateway
D.Aggregate Interface
E.Portal
AnswersC, E

Core component.

Why this answer

GP requires a Portal for distribution and a Gateway for traffic management.

131
MCQmedium

You have configured an IPsec VPN tunnel between two sites, but the tunnel status shows 'init-passive' and never transitions to 'up'. What is the most likely configuration error?

A.The physical interface is not in the correct zone.
B.The IKE Gateway configuration has a mismatched Local/Peer ID.
C.The security policy is missing a rule for IPsec traffic.
D.The tunnel interface is not assigned an IP address.
AnswerB

If the IDs do not match the expected values on the peer, the negotiation will fail to complete, leaving the state at init-passive.

Why this answer

An 'init-passive' state indicates that the firewall is waiting for the peer to initiate the connection, suggesting a mismatch in initiator/responder settings or phase 1 proposal parameters.

132
Multi-Selecthard

Which TWO commands are useful for troubleshooting OSPF?

Select 2 answers
A.show system processes
B.show routing protocol ospf rib
C.show hardware
D.show routing protocol ospf neighbor
E.show log routing
AnswersB, D

Checks OSPF route table.

Why this answer

The 'show routing protocol ospf neighbor' and 'show routing protocol ospf rib' commands are essential for debugging OSPF neighbors and learned routes.

133
MCQeasy

What is the purpose of a Security Zone?

A.Assign IP addresses to subnets
B.Define routing tables
C.Manage firewall firmware
D.Group interfaces for policy control
AnswerD

Zones are the logical containers for policy enforcement.

Why this answer

Security zones group interfaces to apply consistent security policies, acting as the foundation for the firewall's traffic control.

134
MCQeasy

How do you delete a security policy rule?

A.Network > Zones > Delete
B.Device > Setup > Delete
C.Right-click the rule and 'Remove'
D.Policies > Security > Delete
AnswerD

The standard delete action.

Why this answer

In the Policies > Security tab, select the rule and click the 'Delete' button at the bottom of the page.

135
Multi-Selecthard

Which TWO types of failover can be configured in HA?

Select 2 answers
A.Path Monitoring
B.Link Monitoring
C.Interface Speed Monitoring
D.Zone Monitoring
E.Route Monitoring
AnswersA, B

Monitors gateway reachability.

Why this answer

HA failover can be triggered by 'Link Monitoring' (interface status) and 'Path Monitoring' (resource reachability).

136
MCQhard

If you have a primary and secondary firewall, what is the best way to synchronize configuration changes?

A.HA synchronization
B.Manual import/export
C.Panorama device groups
D.Schedule a daily push from the CLI
AnswerA

HA sync is the native method to maintain identical configurations in an HA pair.

Why this answer

High Availability (HA) synchronization ensures that configuration changes made on the primary firewall are mirrored to the secondary firewall.

137
Multi-Selectmedium

Which THREE factors can affect the speed/throughput of a VPN tunnel?

Select 3 answers
A.Encryption algorithm
B.Management IP
C.MTU settings
D.Zone color
E.Firewall CPU load
AnswersA, C, E

Affects processing overhead.

Why this answer

VPN throughput is influenced by the encryption algorithm, the CPU load of the firewall, and the MTU settings.

138
MCQeasy

What is the purpose of an HA Control Link?

A.Synchronize configuration and state
B.Monitor external ISP connectivity
C.Manage the firewall from the internet
D.Forward user traffic
AnswerA

Control links handle control plane sync.

Why this answer

The HA Control Link is used to synchronize configuration and state information between the two firewalls in an HA pair.

139
Multi-Selectmedium

Which TWO items can be configured in a Virtual Router?

Select 2 answers
A.Dynamic Routing Protocols (BGP/OSPF)
B.SSL Decryption
C.URL Filtering
D.DHCP Server
E.Static Routes
AnswersA, E

Automatic routing protocols.

Why this answer

Virtual routers handle routing table lookups, static routes, and dynamic routing protocols (OSPF/BGP).

140
MCQhard

In BGP, what is a 'Route Map' used for?

A.Manipulate BGP attributes
B.Monitor OSPF neighbors
C.Configure static route metrics
D.Limit the number of peers
E.Encrypt BGP sessions
AnswerA

Route maps are used for route manipulation.

Why this answer

A Route Map is used to filter, modify, or manipulate BGP attributes during the import or export of routes, providing granular control over routing policy.

141
MCQmedium

What is the primary function of a Security Profile Group?

A.To manage NAT rules
B.To apply profiles to specific users
C.To bundle multiple security profiles into one object
D.To group multiple security policies
AnswerC

This simplifies the application of security settings to policies.

Why this answer

A Security Profile Group allows you to bundle multiple security profiles (e.g., Antivirus, Anti-Spyware, Vulnerability Protection) into a single object for easy policy assignment.

142
MCQmedium

Which object should be configured for a server that needs to be accessed from the internet via a public IP?

A.Source NAT
B.Static Route
C.Security Policy
D.Destination NAT
AnswerD

Destination NAT allows inbound traffic mapping.

Why this answer

Destination NAT maps a public IP to an internal private IP, enabling access to internal servers.

143
MCQhard

How do you ensure that a specific security policy rule is only active during business hours?

A.Use a Security Profile
B.Use a Dynamic Address Group
C.Manually disable it
D.Create a Schedule object
AnswerD

Schedules allow time-based rule enforcement.

Why this answer

The 'Schedule' object allows you to define time-based constraints for policy rules.

144
Multi-Selectmedium

Which THREE items are required to configure a Site-to-Site VPN?

Select 3 answers
A.Aggregate Ethernet
B.IPsec Tunnel
C.GlobalProtect Portal
D.IKE Gateway
E.Tunnel Interface
AnswersB, D, E

Phase 2 object.

Why this answer

Site-to-Site VPNs require an IKE Gateway (Phase 1), an IPsec Tunnel (Phase 2), and a Tunnel interface to tie them together.

145
Multi-Selectmedium

Which TWO authentication protocols are commonly supported by PAN-OS for VPN user authentication?

Select 2 answers
A.SNMP
B.DHCP
C.RADIUS
D.NTP
E.LDAP
AnswersC, E

Standard auth protocol.

Why this answer

RADIUS and LDAP are standard industry protocols used for VPN authentication.

146
MCQhard

Why might a static route not be visible in the routing table?

A.The firewall is in HA passive mode
B.The destination is a public IP
C.Next hop is unreachable
D.The route has a high metric
E.The interface is in a different zone
AnswerC

Routes require a valid next hop path.

Why this answer

If the next hop is not reachable through an interface associated with the virtual router, the static route is considered invalid and will not be installed in the RIB.

147
MCQeasy

Which interface type is used to manage the firewall over the network?

A.Aggregate Ethernet interface
B.Tunnel interface
C.Loopback interface
D.Management interface
AnswerD

The dedicated MGT port.

Why this answer

The Management interface (MGT) is the dedicated port for out-of-band management of the PAN-OS firewall.

148
Multi-Selecteasy

Which TWO interface modes are commonly used to segment traffic?

Select 2 answers
A.Aggregate Ethernet
B.Layer 3
C.Management
D.Loopback
E.Virtual Wire
AnswersB, E

Standard segmenting mode.

Why this answer

Layer 3 and Virtual Wire modes are common ways to segment and protect traffic.

149
Multi-Selectmedium

You are configuring a new Security Policy. Which TWO settings are required to enable App-ID enforcement for a rule?

Select 2 answers
A.Profile Group
B.Application
C.Service
D.Zone
E.Action
AnswersB, C

You must select specific applications or 'any'.

Why this answer

App-ID is enforced when you specify an Application and a Service (or leave it as application-default).

150
MCQhard

When using the 'pan-os-python' library, which class is primarily used to interact with firewall configuration objects?

A.panos.xapi.Xapi
B.panos.network.Interface
C.panos.base.PanObject
D.panos.objects.AddressObject
AnswerD

This class represents and manipulates address objects in the configuration.

Why this answer

The 'panos.firewall.Firewall' or 'panos.panorama.Panorama' classes are used to connect, but configuration objects are handled by classes within the 'panos.objects' namespace.

Page 1

Page 2 of 3

Page 3

All pages