What are two predefined anti-spyware profiles? Correct Ans -
Default
Strict
Which license must an administrator acquire prior to downloading
Antivirus updates for use with the firewall? Correct Ans - Threat
Prevention
Based on the Security policy rules shown, SSH will be allowed on which
port for inter-zone traffic? Correct Ans - Default port
Which two interface types can be used for firewall management?
Correct Ans - Loopback
VLAN
Which interface type uses virtual routers and routing protocols?
Correct Ans - Layer 3
What are three types of address objects that can be created? Correct
Ans - IP Netmask
IP Range
FQDN
The data plane provides which two data processing features of the firewall?
Correct Ans - Signature matching
Network Processing
What is the default metric value of static routes Correct Ans - 10
What does the Save Named Configuration Snapshot option do? Correct
Ans - Creates a candidate configuration snapshot that does not
overwrite the default snapshot (.snapshot.xml)
Which interface type can be used to switch traffic between multiple
interfaces inside the same VLANs? Correct Ans - Layer 2 interfaces
, What is true about Panorama managed firewalls? Correct Ans -
After a commit on a local firewall, a backup of its running config is sent to
Panorama
Which statement is true about the App-ID database? Correct Ans -
Some App-IDs implicitly allow required applications without the need to
explicitly add the parent to the Security policy
Which interface type is used to monitor traffic and cannot be used to block
traffic? Correct Ans - Tap
Which two methods can be used to manage Palo Alto Networks next-
generation firewalls? Correct Ans - XML API
HTTP/HTTPS
If the NGFW reboots before you commit your changes, how can you revert
the candidate configuration to the current snapshot to restore changes you
made between the last commit and the last snapshot? Correct Ans -
Revert to the last saved configuration
Which type of Security policy rule would match traffic that flows between
different zones, but would not match traffic that flows within the same
zones? Correct Ans - Interzone
Given the following information with regards to traffic flow and session
initiation requirements, which NAT type needs to be configured?
Session initiated from DMZ to Internet:Original Packet: Src IP 10.10.10.10
and Dst IP 204.204.204.204
Translated Packet: Src IP 20.20.20.20 and Dst IP 204.204.204.204
Session initiated from Internet to DMZ:
Original Packet: Src IP 204.204.204.204 and Dst IP 20.20.20.20
Translated Packet: Src IP 204.204.204.204 and Dst IP 10.10.10.10
Correct Ans - Bi-Directional NAT
What are two URL Filtering Security Profile actions? Correct Ans -
Continue
Allow
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Studyhall. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $8.99. You're not tied to anything after your purchase.