Weekend Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

Which element protects and hides an internal network in an outbound flow?

A.

DNS sinkholing

B.

User-ID

C.

App-ID

D.

NAT

Full Access
Question # 5

Which three capabilities and characteristics are shared by the deployments of Cloud NGFW for Azure and VM-Series firewalls? (Choose three.)

A.

Panorama management

B.

Inter-VNet inspection through Virtual WAN hub

C.

Transparent inspection of private-to-private east-west traffic that preserves client source IP address

D.

Inter-VNet inspection through a transit VNet

E.

Use of routing intent policies to apply security policies

Full Access
Question # 6

What are two benefits of credit-based flexible licensing for software firewalls? (Choose two.)

A.

Create virtual Panoramas.

B.

Add Cloud-Delivered Security Services (CDSS) subscriptions to CN-Series firewalls.

C.

Create Cloud NGFWs.

D.

Add Cloud-Delivered Security Services (CDSS) subscriptions to PA-Series firewalls.

Full Access
Question # 7

A company needs a repeatable process to streamline the deployment of new VM-Series firewalls on its network by using the complete bootstrap method. Which file is used in the bootstrap package to configure the management interface of the firewall?

A.

init-mgmt-cfg.txt

B.

init-cfg.txt

C.

init-cfg.bat

D.

bootstrap.bat

Full Access
Question # 8

A company wants to make its flexible-license VM-Series firewall, which runs on ESXi, process higher throughput.

Which order of steps should be followed to minimize downtime?

A.

Increase the vCPU within the deployment profile.

Retrieve or fetch license keys on the VM-Series NGFW.

Power-off the VM and increase the vCPUs within the hypervisor.

Power-on the VM-Series NGFW.

Confirm the correct tier level and vCPU appear on the NGFW dashboard.

B.

Power-off the VM and increase the vCPUs within the hypervisor.

Power-on the VM-Series NGFW.

Retrieve or fetch license keys on the VM-Series NGFW.

Increase the vCPU within the deployment profile.

Confirm the correct tier level and vCPU appear on the NGFW dashboard.

C.

Power-off the VM and increase the vCPUs within the hypervisor.

Increase the vCPU within the deployment profile.

Retrieve or fetch license keys on the VM-Series NGFW.

Confirm the correct tier level and vCPU appear on the NGFW dashboard.

Power-on the VM-Series NGFW.

D.

Increase the vCPU within the deployment profile.

Retrieve or fetch license keys on the VM-Series NGFW.

Confirm the correct tier level and vCPU appear on the NGFW dashboard.

Power-off the VM and increase the vCPUs within the hypervisor.

Power-on the VM-Series NGFW.

Full Access
Question # 9

What are three benefits of Palo Alto Networks VM-Series firewalls as they relate to direct integration with third-party network virtualization solution providers? (Choose three.)

A.

Integration with Cisco ACI allows insertion of a virtual firewall and enforcement of dynamic policies between endpoint groups without the need for manual policy adjustments.

B.

Integration with a third-party network virtualization solution allows management and deployment of the entire virtual network and hosts directly from Panorama.

C.

Integration with Nutanix AHV allows the firewall to be dynamically informed of changes in the environment and ensures policy is applied to virtual machines (VMs) as they join the network.

D.

Integration with VMware NSX provides comprehensive visibility and security of all virtualizeddata center traffic including intra-host ESXi virtual machine (VM) communications.

E.

Integration with network virtualization solution providers allows manual deployment and management of firewall rules through multiple interfaces and front ends specific to each technology.

Full Access
Question # 10

Which two products are deployed with Terraform for high levels of automation and integration? (Choose two.)

A.

Cloud NGFW

B.

VM-Series firewall

C.

Cortex XSOAR

D.

Prisma Access

Full Access
Question # 11

Why are VM-Series firewalls now grouped by four tiers?

A.

To obscure the supported hypervisor manufacturer into generic terms

B.

To simplify the portfolio and reduce the number of VM-Series models customers must choose from

C.

To define the maximum limits for key criteria based on allocated memory

D.

To define the priority level of support customers expect when opening a TAC case, from lowest tier 1 to highest tier 4

Full Access
Question # 12

A company has created a custom application that collects URLs from various websites and then lists bad sites. They want to update a custom URL category on the firewall with the URLs collected.

Which tool can automate these updates?

A.

Dynamic User Groups

B.

SNMP SET

C.

Dynamic Address Groups

D.

XMLAPI

Full Access
Question # 13

Which three features are supported by CN-Series firewalls? (Choose three.)

A.

App-ID

B.

Decryption

C.

GlobalProtect

D.

Content-ID

E.

IPSec

Full Access
Question # 14

Which three statements describe the functionality of Panorama plugins? (Choose three.)

A.

Limited to one plugin installation on Panorama

B.

Supports other Palo Alto Networks products and configurations with NGFWs

C.

May be installed on Panorama from the Palo Alto Networks customer support portal

D.

Complies with third-party product/platform integration and configuration with NGFWs

E.

Expands capabilities of hardware and software NGFWs

Full Access
Question # 15

What can a firewall use to automatically update Security policies with new IP address information for a virtual machine (VM) when it has moved from host-A to host-B because host-A is down or undergoing periodic maintenance?

A.

Dynamic Address Groups

B.

Dynamic User Groups

C.

Dynamic Host Groups

D.

Dynamic IP Groups

Full Access
Question # 16

Which three solutions does Strata Cloud Manager (SCM) support? (Choose three.)

A.

Prisma Cloud

B.

CN-Series firewalls

C.

Prisma Access

D.

PA-Series firewalls

E.

VM-Series firewalls

Full Access
Question # 17

Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)

A.

Its update requires "Commit" to enforce membership mapping.

B.

It allows creation and enforcement of consistent Security policy across multiple cloud environments.

C.

Tags cannot be defined statically on the firewall.

D.

It uses tags as filtering criteria to determine IP address mapping to a group.

E.

Its maximum number of registered IP addresses is dependent on the firewall platform.

Full Access
Question # 18

A company is sponsoring a cybersecurity conference for attendees interested in a range of cybersecurity products that include malware protection, SASE, automation products, and firewalls. The company will deliver a single 3–4 hour conference workshop.

Which cybersecurity portfolio tool will give workshop attendees the appropriate exposure to the widest variety of Palo Alto Networks products?

A.

Capture the Flag

B.

Ultimate Lab Environment

C.

Demo Environment

D.

Ultimate Test Drive

Full Access