What is the default setting for 'Action' in a Decryption Policy's rule?
What is the default setting for 'Action' in a Decryption Policy's rule?A . No-decryptB . DecryptC . AnyD . NoneView AnswerAnswer: D
What are the three Security Policy rule Type classifications supported in PAN-OS 6.1?
What are the three Security Policy rule Type classifications supported in PAN-OS 6.1?A . Security, NAT, Policy-Based ForwardingB . Intrazone, Interzone, GlobalC . Intrazone, Interzone, UniversalD . Application, User, ContentView AnswerAnswer: C Explanation: Reference: https://www.paloaltonetworks.com/content/dam/paloaltonetworkscom/en_US/assets/pdf/framemaker/61/pan-os/NewFeaturesGuide.pdf page 18-19
Which two interface types can be used when configuring GlobalProtect Portal? Choose 2 answers
Which two interface types can be used when configuring GlobalProtect Portal? Choose 2 answersA . Virtual WireB . LoopbackC . TunnelD . Layer3View AnswerAnswer: B,D Explanation: Reference: https://www.paloaltonetworks.com/content/dam/paloaltonetworkscom/en_US/assets/pdf/framemaker/61/globalprotect/globalprotect-admin-guide.pdf page 10
The URL gatewayl.company.com resolves to the external interface of the firewall on the company’s external DNS server and to the internal interface of the firewall on the company s internal DNS server. This Gateway configuration will have which two outcomes? Choose 2 answers
The URL gatewayl.company.com resolves to the external interface of the firewall on the company’s external DNS server and to the internal interface of the firewall on the company s internal DNS server. This Gateway configuration will have which two outcomes? Choose 2 answersA . Clients outside the network will be...
The following can be configured as a next hop in a Static Route:
The following can be configured as a next hop in a Static Route:A . A Policy-Based Forwarding RuleB . Virtual SystemC . A Dynamic Routing ProtocolD . Virtual RouterView AnswerAnswer: D
Can multiple administrator accounts be configured on a single firewall?
Can multiple administrator accounts be configured on a single firewall?A . YesB . NoView AnswerAnswer: A
In what order are the policies evaluated?
A company has a Palo Alto Networks firewall with a single VSYS that has both locally defined rules as well as shared and device-group rules pushed from Panorama. In what order are the policies evaluated? View AnswerAnswer:
Which two configurations would identify the application while preserving the ability of the firewall to perform content and threat detection on the traffic?
It is discovered that WebandNetTrends Unlimited’s new web server software produces traffic that the Palo Alto Networks firewall sees as "unknown-tcp" traffic. Which two configurations would identify the application while preserving the ability of the firewall to perform content and threat detection on the traffic? Choose 2 answersA . A...
The "Disable Server Return Inspection" option on a security profile:
The "Disable Server Return Inspection" option on a security profile:A . Can only be configured in Tap ModeB . Should only be enabled on security policies allowing traffic to a trusted server.C . Does not perform higher-level inspection of traffic from the side that originated the TCP SYN packetD ....
Configuring a pair of devices into an Active/Active HA pair provides support for:
Configuring a pair of devices into an Active/Active HA pair provides support for:A . Higher session countB . Redundant Virtual RoutersC . Asymmetric routing environmentsD . Lower fail-over timesView AnswerAnswer: B