APP-ID/USER-ID
NAT
Basics
Advanced features
Security general
100

 Which User-ID mapping method should be used for an environment with users that do not authenticate to Active Directory?

    A. Windows session monitoring
    B. passive server monitoring using the Windows-based agent
    C. Captive Portal
    D. passive server monitoring using a PAN-OS integrated User-ID agent




C. Captive Portal

100



  An internal host needs to connect through the firewall using source NAT to servers of the internet.
Which policy is required to enable source NAT on the firewall?

    A. NAT policy with internal zone and internet zone specified
    B. post-NAT policy with external source and any destination address
    C. NAT policy with no internal or internet zone selected
    D. pre-NAT policy with external source and any destination address




A. NAT policy with internal zone and internet zone specified

100

Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor?

    A. management
    B. network processing
    C. data
    D. security processing

    A. management

100

 What must be configured before setting up Credential Phishing Prevention?

    A. Threat Prevention
    B. Anti Phishing Block Page
    C. User-ID
    D. Anti Phishing profiles



  C. User-ID

100

How many zones can an interface be assigned with a Palo Alto Networks firewall?

    A. two
    B. three
    C. four
    D. one
          

  D. one

200

 What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.)

    A. An implicit dependency does not require the dependent application to be added in the security policy
    B. An implicit dependency requires the dependent application to be added in the security policy
    C. An explicit dependency does not require the dependent application to be added in the security policy
    D. An explicit dependency requires the dependent application to be added in the security policy

A. An implicit dependency does not require the dependent application to be added in the security policy

 D. An explicit dependency requires the dependent application to be added in the security policy

200

 An internal host needs to connect through the firewall using source NAT to servers of the internet.
Which policy is required to enable source NAT on the firewall?

    A. NAT policy with internal zone and internet zone specified
    B. post-NAT policy with external source and any destination address
    C. NAT policy with no internal or internet zone selected
    D. pre-NAT policy with external source and any destination address



A. NAT policy with internal zone and internet zone specified

200

 Which Palo Alto Networks firewall security platform provides network security for mobile endpoints by inspecting traffic deployed as internet gateways?

    A. GlobalProtect
    B. AutoFocus
    C. Aperture
    D. Panorama



  A. GlobalProtect

200

 Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?

    A. block
    B. sinkhole
    C. allow
    D. alert



B. sinkhole

200

At which stage of the Cyber-Attack Lifecycle would the attacker attach an infected PDF file to an email? 

 A. Delivery
 B. Reconnaissance
 C. Command and Control
 D. Exploitation

A. Delivery

300

 To use Active Directory to authenticate administrators, which server profile is required in the authentication profile?

    A. domain controller
    B. TACACS+
    C. LDAP
    D. RADIUS


 C. LDAP

300

 What does an administrator use to validate whether a session is matching an expected NAT policy?

    A. system log
    B. test command
    C. threat log
    D. config audit



  B. test command

300

 Which file is used to save the running configuration with a Palo Alto Networks firewall?

    A. running-config.xml
    B. run-config.xml
    C. running-configuration.xml
    D. run-configuration.xml



 A. running-config.xml

300

 You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact command-and-control server.
Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection?

    A. Anti-Spyware Profile
    B. Data Filtering Profile
    C. Antivirus Profile
    D. Vulnerability Protection Profile



A. Anti-Spyware Profile

300

 Which two security profile types can be attached to a security policy? (Choose two.)

    A. antivirus
    B. DDoS protection
    C. threat
    D. vulnerability




A. antivirus

D. vulnerability

400

 What must you configure to enable the firewall to access multiple Authentication Profiles to authenticate a non-local account?

    A. authentication sequence
    B. LDAP server profile
    C. authentication server list
    D. authentication list profile



  A. authentication sequence

400

 An administrator wants to create a No-NAT rule to exempt a flow from the default NAT rule.
What is the best way to do this?

    A. Create a static NAT rule translating to the destination interface.
    B. Create a static NAT rule with an application override.
    C. Create a Security policy rule to allow the traffic.
    D. Create a new NAT rule with the correct parameters and leave the translation type as None.

  D. Create a new NAT rule with the correct parameters and leave the translation type as None.

400

 Which Palo Alto Networks component provides consolidated policy creation and centralized management?

    A. GlobalProtect
    B. Panorama
    C. Prisma SaaS
    D. AutoFocus



 B. Panorama

400

                         An administrator needs to add capability to perform real time signature lookups to block or sinkhole all known malware domains.
Which type of single, unified engine will get this result?

    A. Content ID
    B. App-ID
    C. Security Processing Engine
    D. User-ID


  A. Content ID

400

 An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server.
Which security profile components will detect and prevent this threat after the firewall's signature database has been updated?

    A. antivirus profile applied to outbound security policies
    B. data filtering profile applied to inbound security policies
    C. data filtering profile applied to outbound security policies
    D. vulnerability profile applied to inbound security policies



 A. antivirus profile applied to outbound security policies

500

 Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)

    A. Layer-ID
    B. User-ID
    C. QoS-ID
    D. App-ID



B. User-ID

D. App-ID

500

 Which statement is true regarding NAT rules?

    A. Translation of the IP address and port occurs before security processing.
    B. Firewall supports NAT on Layer 3 interfaces only.
    C. Static NAT rules have precedence over other forms of NAT.
    D. NAT rules are processed in order from top to bottom.

D. NAT rules are processed in order from top to bottom.

500

 Which type of security policy rule will match traffic that flows between the Outside zone and inside zone, but would not match traffic that flows within the zones?

    A. global
    B. intrazone
    C. interzone
    D. universal



    C. interzone

500

 Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis, Unit 42 research, and data gathered from telemetry?

    A. Palo Alto Networks High-Risk IP Addresses
    B. Palo Alto Networks Known Malicious IP Addresses
    C. Palo Alto Networks C&C IP Addresses
    D. Palo Alto Networks Bulletproof IP Addresses



 B. Palo Alto Networks Known Malicious IP Addresses

500

Which Security Profile mitigates attacks based on packet count?

    A. zone protection profile
    B. URL filtering profile
    C. antivirus profile
    D. vulnerability profile


 A. zone protection profile

M
e
n
u