2 ways to Reset to Factory default - ANS * from CLI with known password
. request system private-data-reset
* from CLI without PW
reboot and type "maint" during bootup
choose Reset to factory default
or load another config into running memory
DNS and NTP are configured where? - AN...
2 ways to Reset to Factory default - ANS * from CLI with known password
. request system private-data-reset
* from CLI without PW
reboot and type "maint" during bootup
choose Reset to factory default
or load another config into running memory
DNS and NTP are configured where? - ANS Device > Setup > Services
where do you configure service routes - ANS device > setup > services > service route
configuration
name of the running config - ANS running-config.xml
where do you manage configurations - ANS device > setup > operations
Steps needed prior to firewall being usable - ANS * register with PA
* activate licenses
* verify update and DNS
* manage content updates
* install software updates
where is Pan-OS software updates - ANS device > software
where do you define an interface management profile - ANS network > network profiles >
interface mgmt > add
What are the four major components that enable threat prevetion - ANS * Natively
integrated technologies that leverage single pass prevention architecture, support open
communication
* Automated creation and delivery of protection mechanisms
*Extensibility and flexibility
, * Threat inelligence sharing
Throughput in a PA 7080 - ANS App-ID firewall throughput 200Gps
Threat prevention throughput 100 Gbps
Throughput of a PA7050 - ANS App-id throughput 120 Gbps
Threat prevention 60 Gbps
throughput of a PA 5280/5260 - ANS App-id thoughput 68 Gbps
threat prevention throughput 30 gbps
throughput of a PA5250 - ANS app-id throughput 39 gbps
threat prevention 20 gbps
throughput of a PA5220 - ANS App-id 18gbps
threat prevention 9 gbps
Describe HA active/passive deployment - ANS recommended, single firewall config
synched between the two firewalls.
Synchronization happens across HA1 connection
Session data is kept on both firewalls via HA2
Describe HA active/active deployment - ANS two firewalls attached with 3 cables, HA1,
HA2, HA3. only recommended for load balancing
Identify ways to mitigate resource exhaustion - ANS *Denial of Service Policy - ,more
granular for specific resources
* Zone Protection Profiles (ZZP) - coveres AE zone
Why are denial of service protections applied by zone? - ANS * DOS protections are
applied very early in the processing before a lot of information is known about the connection
but the ingress interface is already known
* Because DOS protections are only applied when manually turned on to avoid quota overload
(which would make a DOS attack easier)
Which feature never requires a Decryption policy? - ANS Network address translation
How can the NGFW inform web browsers that a web server's certificate is from an unknown
certificate authority (CA)? - ANS Have two certificate authority certificates in the firewall.
One is used to produce certificates for sites whose original certificate is trusted, and the other
for certificates for sites whose original certificate is untrusted.
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller DocLaura. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $10.89. You're not tied to anything after your purchase.