Which value in the Application column indicates UDP traffic that did not match an App-ID signature?
Which value in the Application column indicates UDP traffic that did not match an App-ID signature?A . not-applicableB . incompleteC . unknown-ipD . unknown-udpView AnswerAnswer: D Explanation: To safely enable applications you must classify all traffic, across all ports, all the time. With App-ID, the only applications that are typically...
Which two solutions can the administrator use to scale this configuration?
An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls. The firewalls will provide access to mobile users and act as edge locations to on-premises infrastructure. The administrator wants to scale the configuration out quickly and wants all of the...
Below are the steps in the workflow for creating a Best Practice Assessment in a firewall and Panorama configuration Place the steps in order
DRAG DROP Below are the steps in the workflow for creating a Best Practice Assessment in a firewall and Panorama configuration Place the steps in order. View AnswerAnswer:
The certificate information displayed in the following image is for which type of certificate?
The certificate information displayed in the following image is for which type of certificate? A . Forward Trust certificateB . Self-Signed Root CA certificateC . Web Server certificateD . Public CA signed certificateView AnswerAnswer: B
Which Panorama objects restrict administrative access to specific device-groups?
Which Panorama objects restrict administrative access to specific device-groups?A . templatesB . admin rolesC . access domainsD . authentication profilesView AnswerAnswer: C
In SSL Forward Proxy decryption, which two certificates can be used for certificate signing? (Choose two.)
In SSL Forward Proxy decryption, which two certificates can be used for certificate signing? (Choose two.)A . wildcard server certificateB . enterprise CA certificateC . client certificateD . server certificateE . self-signed CA certificateView AnswerAnswer: B,E
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)A . TACACS+B . KerberosC . PAPD . LDAPE . SAMLF . RADIUSView AnswerAnswer: B,D,E Explanation: https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication
What are two reasons why the firewall might not use a static route"?
An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used After looking at the configuration, the administrator believes that the firewall is not using a static route What are two reasons why the firewall might not use a static route"? (Choose...
Which upgrade path maintains synchronization of the HA session (and prevents network outage)?
An administrator wants to upgrade a firewall HA pair to PAN-OS 10.1. The firewalls are currently running PAN-OS 8.1.17. Which upgrade path maintains synchronization of the HA session (and prevents network outage)?A . Upgrade directly to the target major versionB . Upgrade one major version at a timeC . Upgrade...
PBF can address which two scenarios? (Select Two)
PBF can address which two scenarios? (Select Two)A . forwarding all traffic by using source port 78249 to a specific egress interfaceB . providing application connectivity the primary circuit failsC . enabling the firewall to bypass Layer 7 inspectionD . routing FTP to a backup ISP link to save bandwidth...