Courseiva

CCNA Palo Alto Networks Product Integration And Architecture Questions

26 of 101 questions · Page 2/2 · Palo Alto Networks Product Integration And Architecture topic · Answers revealed

76
Multi-Selectmedium

An architect is configuring High Availability (HA) on Palo Alto Networks firewalls. Which TWO data or state tables are synchronized across the HA2 link between active and passive peers? (Choose two)

Select 2 answers
A.Local firewall physical power supply voltage metrics.
B.Panorama admin account SSH private keys.
C.ARP table entries to maintain layer 2 reachability after failover.
D.Active session table entries so ongoing TCP/UDP sessions continue uninterrupted during failover.
E.Administrator password history and failed login lockout counters.
AnswersC, D

ARP synchronization helps the newly active unit respond immediately to local subnet traffic.

Why this answer

HA2 synchronizes active session tables, ARP tables, IPsec security associations, and NAT table mappings.

77
MCQmedium

An architect is troubleshooting a Cortex XDR deployment where agents on endpoints are failing to communicate with the Cortex XDR cloud tenant. Which outbound network connectivity requirement must be verified on the local corporate firewall?

A.Outbound TCP port 443 (HTTPS) access to the Cortex XDR tenant cloud URL.
B.Inbound UDP port 69 (TFTP) from endpoints to Panorama.
C.Inbound TCP port 3389 (RDP) from the cloud backend to every endpoint.
D.Outbound TCP port 3978 to Panorama Collectors.
AnswerA

Cortex XDR agents require outbound HTTPS (port 443) access to communicate with the cloud backend.

Why this answer

Cortex XDR agents communicate with the cloud tenant over outbound HTTPS (TCP port 443).

78
Multi-Selecthard

An architect is designing an automated threat hunting and containment workflow using Cortex XSOAR. Which TWO external or internal data sources can Cortex XSOAR query or integrate with during an investigation? (Choose two)

Select 2 answers
A.Active Directory domain controllers for user account status verification.
B.Local coffee machine IoT sensors via raw Bluetooth packets.
C.FM radio broadcast frequency tuners.
D.Threat intelligence platforms and APIs such as VirusTotal or Palo Alto Networks WildFire for indicator enrichment.
E.Raw analog telephone landline switches via modem dial-up.
AnswersA, D

XSOAR integrates with AD to verify user details and disable compromised accounts.

Why this answer

Cortex XSOAR integrates with threat intelligence platforms (like VirusTotal, MISP), SIEMs, Active Directory, and Palo Alto Networks products (Panorama, XDR, WildFire).

79
MCQhard

An architect is deploying Prisma Access to secure remote workers. The organization uses explicit proxying for web traffic and requires user-ID mapping for explicit proxy connections. Which Prisma Access component and configuration must be deployed to correctly map users authenticated via an explicit proxy to their respective User-ID groups?

A.Deploy the Explicit Proxy feature in Prisma Access, configure proxy authentication, and integrate with Cloud Identity Engine (CIE) to extract user identity from proxy headers.
B.Rely solely on GlobalProtect portal cookies for explicit proxy traffic identification.
C.Configure standard IP-to-User mapping via User-ID agents on the remote user laptops without a proxy.
D.Configure SNMP traps on the proxy server to send ARP tables to Panorama.
AnswerA

Cloud Identity Engine combined with Prisma Access explicit proxy configuration maps authenticated proxy users correctly.

Why this answer

Explicit proxy configurations in Prisma Access require configuring Proxy Settings in Panorama and leveraging the Integration with GlobalProtect or the Explicit Proxy feature along with User-ID agents or Cloud Identity Engine (CIE) to map the source IP or proxy headers.

80
MCQeasy

An architect is configuring User-ID to identify users behind a Microsoft Active Directory domain. Which protocol does the Palo Alto Networks User-ID agent use to query Active Directory security event logs for user login and logoff events?

A.NetFlow v9 templates
B.SNMPv3 polling of Active Directory database tables
C.WMI or Windows RPC/SMB to read Security Event Logs
D.HTTP POST requests sent by the Active Directory DNS service
AnswerC

User-ID agent queries Windows security event logs via WMI or RPC/SMB.

Why this answer

The User-ID agent monitors Active Directory domain controllers using Windows security event logs via WMI or Windows RPC/SMB protocols.

81
Multi-Selectmedium

An architect is troubleshooting a Palo Alto Networks High Availability (HA) cluster where configuration synchronization between active and passive peers is failing. Which TWO locations or settings should the architect check? (Choose two)

Select 2 answers
A.Verify physical and logical connectivity on the HA1 control link interface.
B.Check the DNS server IP address configured on the management interface.
C.Check the URL Filtering cloud license status.
D.Check the GlobalProtect gateway portal certificate expiration date.
E.Verify that both firewalls are running the exact same PAN-OS software version.
AnswersA, E

HA1 handles configuration sync; connectivity failures break config sync.

Why this answer

HA configuration synchronization failure troubleshooting involves checking HA1 link connectivity, ensuring matching PAN-OS versions, and verifying HA settings in Device > High Availability.

82
MCQmedium

A security architect is integrating Cortex XDR with an on-premises Palo Alto Networks NGFW via the Syslog Collector. The XDR agent is installed on endpoints, but network-based detections from the firewall are not appearing in the Cortex XDR Incident Viewer. What is the most likely root cause of this integration failure?

A.The firewall's WildFire public cloud connection is disabled.
B.The firewall management plane CPU is running above 90%, causing it to drop all syslog packets.
C.The firewall Syslog Server profile is missing the correct custom log format or CEF mapping required by Cortex XDR.
D.Cortex XDR requires an explicit PAN-OS XML API credential rather than syslog to ingest firewall alerts.
AnswerC

Cortex XDR requires a specific format (such as CEF or LEEF via a Broker VM) to correctly parse and map network events into incidents.

Why this answer

Integration requires proper forwarding format (LEEFT/CEF) and correct log forwarding profile mapping so the Cortex XDR agent or Broker VM successfully ingests and parses the syslog stream.

83
MCQhard

An architect is designing a high-scale Cortex XDR deployment across 50,000 endpoints. To optimize bandwidth and reduce direct WAN traffic to the cloud backend for agent updates and log collection, which architectural component should be deployed in regional data centers?

A.A standalone Panorama virtual machine acting as an endpoint proxy.
B.Prisma Access Remote Network nodes running the XDR agent directly on gateway hypervisors.
C.A dedicated PA-7080 firewall performing deep packet inspection on all XDR endpoint RAM.
D.Cortex XDR Broker VM deployed in regional data centers to act as a local proxy, content cache, and log collector.
AnswerD

Broker VMs optimize bandwidth by caching agent packages, acting as syslog collectors, and proxying communication.

Why this answer

Cortex XDR Broker VMs act as regional aggregators and proxies for agent updates, syslog collection, and telemetry forwarding.

84
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to block access to known malicious domains and phishing sites. Which security profile should be configured and attached to the security policy?

A.URL Filtering profile
B.WildFire analysis profile
C.Antivirus profile
D.Data Filtering profile
AnswerA

URL Filtering inspects web traffic and blocks malicious, phishing, or restricted websites.

Why this answer

URL Filtering profiles inspect HTTP/HTTPS web traffic and block access to malicious, phishing, or unauthorized web categories.

85
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect outbound traffic for malware. Which security profile should be attached to the security policy rule allowing outbound internet traffic?

A.Decryption profile
B.Zone Protection profile
C.User-ID agent profile
D.Antivirus security profile
AnswerD

Antivirus profiles scan files in transit for malicious signatures.

Why this answer

Antivirus profiles inspect traffic traversing security policies for known malware signatures.

86
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to prevent SYN flood attacks on public-facing web servers. Which security feature should the architect configure?

A.Data Filtering profile.
B.Zone Protection profile configured with SYN flood SYN cookies.
C.URL Filtering profile.
D.WildFire file analysis profile.
AnswerB

Zone Protection profiles mitigate layer 3/4 DoS and SYN flood attacks using SYN cookies.

Why this answer

Zone Protection profiles provide protection against flood attacks (SYN flood, UDP flood, ICMP flood), IP spoofing, and reconnaissance.

87
Multi-Selecthard

An architect is designing a secure architecture using VM-Series on Microsoft Azure. Which TWO Azure-native services or integration components must be configured to achieve high availability with dynamic failover of user traffic across two VM-Series instances? (Choose two)

Select 2 answers
A.Physical HA2 fiber optic cables connected between Azure availability zones.
B.Azure ExpressRoute direct copper cross-connect cables plugged into the firewall physical NICs.
C.Azure Load Balancer (Standard SKU) to distribute inbound and outbound traffic to the VM-Series data interfaces.
D.Azure User Defined Routes (UDR) and the PAN-OS SDN Connector to dynamically update route tables during a failover event.
E.Azure Active Directory Domain Services domain controller deployed inside the firewall data plane.
AnswersC, D

Azure Load Balancers are essential for distributing traffic across VM-Series HA peers in cloud environments.

Why this answer

Azure VM-Series HA typically relies on Azure Load Balancers (ALB) or Azure Route Tables (UDPs/User Defined Routes) with API scripts or SDN connectors running on the firewall to update routing tables upon failover.

88
MCQhard

An architect is designing a large-scale Prisma Access deployment with hundreds of remote networks. To simplify routing management and avoid full-mesh IPsec tunnel complexity between all branch sites, what architectural topology does Prisma Access employ by default?

A.Ring topology relying entirely on legacy Token Ring protocols.
B.Full-mesh BGP peering over physical leased dark fiber lines directly connecting every branch office to all other branch offices.
C.Peer-to-peer BitTorrent distribution of routing tables.
D.Cloud-backed hub-and-spoke architecture where remote networks connect to Prisma Access cloud nodes, which handle backbone routing.
AnswerD

Prisma Access routes traffic through its cloud backbone, eliminating the need for full-mesh branch-to-branch tunnels.

Why this answer

Prisma Access utilizes a cloud-native backbone operating on a hub-and-spoke or cloud-routed backbone architecture where remote networks connect to cloud locations, simplifying branch-to-branch and branch-to-DC routing.

89
Multi-Selectmedium

An architect is configuring Panorama to manage a large deployment of firewalls. Which TWO best practices should be implemented regarding Panorama administrative access and security? (Choose two)

Select 2 answers
A.Expose the Panorama management interface directly to the public internet without an IP whitelist or VPN.
B.Configure Role-Based Access Control (RBAC) using custom Admin Roles and Access Domains to restrict administrators to their assigned device groups.
C.Enforce multi-factor authentication (MFA) for all Panorama administrative logins.
D.Share a single 'admin' superuser account credential among all members of the network team.
E.Disable all logging on Panorama to save disk space.
AnswersB, C

RBAC ensures least-privilege administrative access across device groups.

Why this answer

Panorama admin best practices include enforcing Role-Based Access Control (RBAC) via Admin Roles and Access Domains, and enforcing multi-factor authentication (MFA) for all administrators.

90
Multi-Selecthard

An architect is designing an enterprise security architecture integrating Prisma Access, Cortex XDR, and Cortex XSOAR. Which TWO architectural benefits are realized by this tight integration? (Choose two)

Select 2 answers
A.Using analog telephone lines to transmit high-speed XDR memory dumps.
B.Eliminating the need for any encryption or security policies.
C.Replacing all cloud provider underlying hypervisors with Palo Alto Networks proprietary switches.
D.Automated incident response orchestration and remediation across network and endpoints using Cortex XSOAR playbooks.
E.Unified threat visibility across cloud-secured network traffic (Prisma Access) and endpoint activity (Cortex XDR).
AnswersD, E

XSOAR orchestrates automated remediation across XDR and Prisma Access/firewalls.

Why this answer

Integrating Prisma Access, Cortex XDR, and Cortex XSOAR provides unified threat visibility across network and endpoints, and automated end-to-end incident response orchestration.

91
Multi-Selectmedium

An architect is configuring Palo Alto Networks firewall interfaces. Which TWO interface types are supported in PAN-OS for routing traffic between security zones? (Choose two)

Select 2 answers
A.Bluetooth Low Energy (BLE) antenna interface.
B.Universal Serial Bus (USB) printer interface.
C.Layer 3 interface assigned an IP address and virtual router.
D.Virtual Wire (vwire) interface for transparent inline deployment without IP addressing.
E.HDMI multimedia display interface.
AnswersC, D

Layer 3 interfaces route packets between zones using IP addresses and virtual routers.

Why this answer

PAN-OS supports Layer 3 interfaces, Layer 2 interfaces, Virtual Wire (vwire), Tap, and Loopback/Tunnel interfaces.

92
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to ensure that administrative logins are authenticated against an external RADIUS server with multi-factor authentication. Where should the architect configure the RADIUS server profile?

A.Data Filtering Profile settings.
B.Zone Protection Profile settings.
C.Authentication Profile configured under Device > Authentication Profile referencing a RADIUS Server Profile.
D.URL Filtering Profile settings.
AnswerC

Authentication profiles link external RADIUS server profiles to administrative authentication settings.

Why this answer

Panorama or firewall Authentication Profiles allow defining RADIUS, LDAP, Kerberos, or SAML server connections for administrator and user authentication.

93
MCQhard

An architect is designing a multi-cloud network security architecture where Palo Alto Networks VM-Series firewalls are deployed in AWS, Azure, and GCP. Management and policy enforcement must be centralized. Which architectural design provides the most scalable management plane?

A.Managing each cloud firewall independently via its local web GUI with no central management.
B.Using Cortex XSOAR as a replacement for Panorama configuration management.
C.Centralized Panorama instance managing all multi-cloud VM-Series firewalls using Device Groups and Templates.
D.Relying entirely on AWS CloudWatch to push security rules to Azure firewalls.
AnswerC

Panorama provides unified management, templates, and device groups across multi-cloud VM-Series deployments.

Why this answer

Deploying a centralized Panorama instance (either physical or virtual) managing all VM-Series firewalls across AWS, Azure, and GCP via templates and device groups provides the optimal multi-cloud management architecture.

94
Multi-Selecthard

An architect is designing a Prisma Cloud compliance framework. Which TWO actions or configurations can be implemented in Prisma Cloud to assess and enforce cloud resource security? (Choose two)

Select 2 answers
A.Using SNMPv1 polling to check cloud provider power meters.
B.Writing custom JSON compliance RQL (Resource Query Language) queries to find specific cloud misconfigurations.
C.Directly reflashing cloud provider physical hardware motherboards.
D.Configuring compliance policies mapped to standards such as CIS Benchmarks, NIST, and PCI-DSS.
E.Installing GlobalProtect desktop VPN clients on AWS EC2 virtual machine disks.
AnswersB, D

RQL enables administrators to query cloud resource states and build custom compliance rules.

Why this answer

Prisma Cloud allows creating custom compliance policies, assessing multi-cloud resource configurations against CIS benchmarks, and integrating with IaC scanning pipelines.

95
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect traffic for known malware and spyware. Which security profile should the architect attach to the Security Policy rule?

A.File Blocking profile
B.Antivirus and Anti-Spyware security profiles
C.Data Filtering profile
D.URL Filtering profile
AnswerB

Antivirus and Anti-Spyware profiles inspect data streams for malicious payloads and command-and-control callbacks.

Why this answer

Antivirus and Anti-Spyware security profiles inspect traffic for known malware and command-and-control (C2) signatures.

96
Multi-Selectmedium

An architect is configuring High Availability (HA) on a pair of Palo Alto Networks firewalls. Which TWO settings or parameters must be identical on both HA peers for the HA cluster to form successfully? (Choose two)

Select 2 answers
A.The physical serial number printed on the hardware chassis label.
B.Operating mode (Active/Passive or Active/Active) and license configuration.
C.PAN-OS software version installed on both firewalls.
D.The administrative password for the 'admin' user account.
E.The hostname assigned to each firewall in the setup menu.
AnswersB, C

HA mode and license subscriptions must match across peers.

Why this answer

HA peers require matching device serial numbers/models (or VM models), matching PAN-OS versions, matching license keys, and matching operational modes (Active/Passive).

97
MCQmedium

An architect is troubleshooting a User-ID agent deployment where group mapping information is not being retrieved from Microsoft Active Directory. Which permission or protocol requirement must be verified on the Active Directory domain controller for group mapping to succeed?

A.Verify that SNMPv1 is enabled on the domain controller.
B.Verify that the Domain Controller has the GlobalProtect client installed.
C.Verify LDAP/LDAPS network connectivity and ensure the service account has read permissions to query Active Directory user and group objects.
D.Verify that the firewall management plane CPU is running at 100%.
AnswerC

LDAP connectivity and proper read privileges on AD objects are required for User-ID group mapping.

Why this answer

User-ID agent requires LDAP / LDAPS access and appropriate read permissions on Active Directory to query user and group object attributes.

98
MCQmedium

An architect is designing a multi-tenant Palo Alto Networks firewall deployment using Virtual Systems (vsys). Each vsys requires dedicated administrative access. Which administrative object must be configured to grant a specific administrator access to only one particular vsys?

A.Administrative Role with restricted Access Domain pointing to the specific vsys.
B.GlobalProtect HIP object profiles.
C.Global Superuser account sharing.
D.Panorama Template Stack variables.
AnswerA, D

Access Domains and Admin Roles restrict administrators to specific virtual systems or device groups.

Why this answer

Administrative Roles and Access Domains allow restricting administrators to specific virtual systems (vsys) or device groups.

99
Multi-Selecthard

An architect is integrating Prisma Cloud with a CI/CD pipeline (such as GitHub Actions or Jenkins) to perform Infrastructure as Code (IaC) scanning. Which TWO scanning targets or mechanisms are supported by Prisma Cloud for IaC security? (Choose two)

Select 2 answers
A.Scanning Terraform and AWS CloudFormation templates using the Prisma Cloud IaC CLI or GitHub Actions integration.
B.Scanning Kubernetes YAML manifests and Helm charts in git repositories for misconfigurations.
C.Sniffing active TCP packets traversing a Jenkins build server network switch interface.
D.Querying the Jenkins REST API using raw SNMPv1 strings.
E.Running a Prisma Cloud Defender daemonset inside a developer's local laptop BIOS.
AnswersA, B

Prisma Cloud provides plugins and CLI tools to scan IaC templates before deployment.

Why this answer

Prisma Cloud IaC scanning supports scanning Terraform, CloudFormation, Kubernetes YAML, and ARM templates via CLI tools, IDE plugins, and CI/CD pipeline integrations.

100
Multi-Selecthard

An architect is designing a Prisma Cloud Compute deployment to secure containerized workloads. Which TWO compliance and vulnerability assessment features are provided by Prisma Cloud Compute Defenders? (Choose two)

Select 2 answers
A.Writing custom assembly code for application microservices.
B.Evaluating container configurations and host OS settings against CIS (Center for Internet Security) benchmarks.
C.Analyzing physical power grid load tolerances in data center facilities.
D.Scanning container images and host operating systems for Common Vulnerabilities and Exposures (CVEs).
E.Acting as a Layer 7 DNS root server for enterprise domains.
AnswersB, D

Defenders perform compliance checks against CIS benchmarks for containers and hosts.

Why this answer

Prisma Cloud Compute Defenders perform vulnerability scanning of container images, host OS packages, and compliance checks against CIS benchmarks.

101
MCQeasy

An architect is designing high availability for a Palo Alto Networks firewall deployment and wants to ensure that both firewalls can actively process traffic under normal operating conditions while backing each other up. Which HA mode supports this?

A.Panorama managed standalone mode
B.Standalone clustering with no HA links
C.High Availability Active/Passive mode
D.High Availability Active/Active mode
AnswerD

Active/Active HA allows both peers to process traffic concurrently.

Why this answer

Active/Active HA allows both firewalls to process traffic simultaneously, using device-ID and floating IPs to handle session failover.

← PreviousPage 2 of 2 · 101 questions total

Ready to test yourself?

Try a timed practice session using only Palo Alto Networks Product Integration And Architecture questions.