

Q: 11
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
As a best practice, logging at session start should be used in which case?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
When you troubleshoot an SSL Decryption issue, which PAN-OS CL1 command do you use to check
the details of the Forward Trust certificate. Forward Untrust certificate, and SSL Inbound Inspection
certificate?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Which GlobalProtect gateway selling is required to enable split-tunneling by access route,
destination domain, and application?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
An engineer needs to permit XML API access to a firewall for automation on a network segment that
is routed through a Layer 3 sub-interface on a Palo Alto Networks firewall. However, this network
segment cannot access the dedicated management interface due to the Security policy.
Without changing the existing access to the management interface, how can the engineer fulfill this
request?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
An organization is interested in migrating from their existing web proxy architecture to the Web
Proxy feature of their PAN-OS 11.0 firewalls. Currently. HTTP and SSL requests contain the c IP
address of the web server and the client browser is redirected to the proxy
Which PAN-OS proxy method should be configured to maintain this type of traffic flow?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Which User-ID mapping method should be used in a high-security environment where all IP address-
to-user mappings should always be explicitly known?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
An engineer creates a set of rules in a Device Group (Panorama) to permit traffic to various services
for a specific LDAP user group.
What needs to be configured to ensure Panorama can retrieve user and group information for use in
these rules?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2