考试名称
When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, when can the firewall be powered on?
A、During license activation
B、After activating registration and completing license deployment profile
C、After all required installation and setup procedures are completed
D、During installation
Which profile can help prevent the transmission of sensitive information to internet applications?
A、Antivirus
B、Data Filtering
C、Anti-spyware
D、URL Filtering
How do template stacks help manage firewall configurations in Panorama?
A、By grouping templates across multiple firewalls
B、By creating template variables for permanent configurations in firewalls
C、By creating a diagram of the network for a view of all firewalls
D、By handling firmware updates across multiple firewalls
In which order does a next-generation firewall (NGFW) process URL categories for Security policy?
A、1.External dynamic lists2.Custom URL categories3.Predefined categories
B、1.Custom URL categories2.External dynamic lists3.Predefined categories
C、1.Custom URL categories2. Predefined categories3. External dynamic lists
D、1.Predefined categories2. External dynamic lists3. Custom URL categories
When a rule has been set up to block uploading all Portable Executable (PE) files, which type of log will display blocked files that attempt to traverse the network?
A、Traffic
B、Data filtering
C、URL filtering
D、Threat
Which Security policy on a data center NGFW will block intrazone traffic in Zone Colorado for the Dynamic User Group "Testers" and custom application "Payment System"?
A、Source & Destination Zone = Colorado Users = TestersApplication = Payment System Action = Deny
B、Source & Destination Zone = Colorado Users = TestersApplication = Any Action = Deny
C、Source Zone = Colorado Destination Zone = LA Users = TestersApplication = Payment System Action = Deny
D、Source Zone = Colorado Destination Zone = LA Users = Testers Application = AnyAction = Deny
In which order is Prisma SD-WAN dynamic path selection performed?
A、1. Determine potential paths based on policy.2. Determine link quality.3. Measure application performance.4. Measure link capacity.
B、1. Measure link capacity.2. Measure application performance.3. Determine link quality.4. Determine potential paths based on policy.
C、1. Determine potential paths based on policy.2. Measure application performance.3. Determine link quality.4. Measure link capacity.
D、1. Determine link quality.2. Measure link capacity.3. Measure application performance.4. Determine potential paths based on policy.
Which NGFW tool should be reviewed when a management team wants feedback on how to reduce the attack surface of their network security deployment and how it maps to the Center for Internet Security (CIS) Critical Security Controls?
A、Executive summary report
B、Policy Optimizer
C、Best Practice Assessment (BPA)
D、Command Center
In which security profile is credential phishing prevention implemented?
A、URL Filtering
B、Vulnerability Protection
C、Antivirus
D、Anti-spyware
How does PAN-OS identify App-IDs to perform application-layer inspection?
A、From predefined static rules based on IP addresses and ports configured by the administrator
B、From inspection of SSL certificates, cloud-based metadata, and manual application classification by the administrator
C、From periodic updates that categorize web traffic based on domain names, focusing on web-browsing activities
D、From multiple classification mechanisms - application signatures, application protocol decoding, and heuristics
Which file type does Advanced WildFire support for inline analysis to detect advanced malware?
A、PE
B、APK
C、PDF
D、JAR
What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?
A、9.1 --> 11.2
B、9.1 --> 11.0 --> 11.2
C、9.1 --> 10.0 --> 11.0 --> 11.2
D、9.1 --> 10.0 --> 11.0 --> 11.1 --> 11.2
By default, how often are signatures updated for firewalls with Advanced WildFire?
A、In real time
B、 5-10 minutes
C、Within 24-48 hours
D、Once a week
An administrator is responsible for updating which component of Prisma Access?
A、Management plane
B、Content updates
C、Data plane
D、VPN client
A Prisma Access administrator wants to attach the same set of Security policies to each new rule created. How can the administrator automate the profiles to be attached to new rules?
A、Create profiles for each CDSS and name them "default."
B、Create a security profile group and name it "default."
C、Use AIOps to automate the security profile group attachment.
D、Use Policy Analyzer after creating the new rules.
Where does an administrator update the collection of infected hosts in Strata Cloud Manager (SCM) when isolating an identified endpoint from a network?
A、Quarantined device list
B、Quarantine devices
C、Actions
D、Host information profile (HIP)
Why would a packet be processed through the slow path on an NGFW?
A、It does not require application identification or user identification.
B、It is part of an already established session.
C、It is part of a new or unestablished session.
D、It only needs basic NAT and Security policy enforcement.
Within which security profile is the DNS sinkholing action enabled?
A、File Blocking
B、Antivirus
C、Anti-spyware
D、DoS Protection
An organization’s Security policy requires all SSL/TLS traffic using post-quantum cryptography (PQC)algorithms to be identified and logged.Which next-generation firewall (NGFW) feature provides the settings for this purpose?
A、Decryption policy
B、SSL/TLS service profile
C、Decryption profile
D、Anti-spyware profile
In which order of precedence is App-ID evaluated and determined?
A、1. ACE cloud2. Content-based3. Custom
B、1. Custom2. ACE cloud3. Content-based
C、1. Content-based2. Custom3. ACE cloud
D、1. Custom2. Content-based3. ACE cloud
An administrator is configuring an Advanced WildFire Analysis profile on a PAN-OS firewall. The objective is to use inline cloud analysis to prevent unknown malware targeting Windows endpoints from traversing the firewall.Which file type is supported for this analysis?
A、JAR
B、APK
C、PE
D、DMG
An administrator has created a security profile group containing the organization’s standard Antivirus, Anti- Spyware, and Vulnerability Protection profiles. This specific group will be the default applied to any new security rule created in Prisma Access.Which step is required for the group to attach automatically to new rules?
A、Place the group at the top of the security profile groups list.
B、In the Prisma Access settings, specify the group as “Default Security Group”.
C、Name the security profile group “default”.
D、Name each individual profile within the group “default”.
Which tool allows a Prisma Access administrator to gather Active Directory groups to be used in user-to- group mappings?
A、Cloud Identity Engine
B、SAML-based integration
C、Active Directory server profile
D、SCIM-based integration
Which activity only appears under the Content-ID portion of single-pass parallel processing (SP3)?
A、SaaS Security
B、Malware analysis
C、Application decoding
D、Application heuristics
Which combination of techniques does App-ID use to control a specific application, regardless of the port it uses?
A、Heuristics application signatures, and application protocol decoding
B、User-ID agent host information profiles (HIPs), and group mappings
C、SSL/TLS handshake analysis and certificate metadata
D、Threat intelligence feeds and the WildFire signature database
As part of a Zero Trust implementation, a security team has completed defining its micro-perimeters and writing all the initial context-based Security policy rules. Now, it is focused on collecting and analyzing logs to ensure the policies are working as intended.Which step of the Palo Alto Networks five-step methodology is the team now performing?
A、Monitor and Maintain Your Network
B、Architect a Zero Trust Network
C、Map Your Transaction Flows
D、Define Your Attack Surface
An administrator is configuring a new Enterprise DLP policy to unify the data loss prevention (DLP) strategy across the entire infrastructure, which includes physical NGFWs and Prisma Access.In regard to profile configuration, what is the primary advantage of this approach?
A、Each NGFW and Prisma Access gateway requires its own locally defined DLP profile.
B、A single data profile is created in the cloud and applied consistently across enforcement points.
C、The NGFW profile is first exported and then imported into the Prisma Access configuration.
D、Profiles are created on Panorama and synced securely to a separate cloud instance for Prisma Access.
Which Prisma Access solution provides the ability to inspect traffic from all applications on user devices?
A、Explicit proxy
B、GlobalProtect
C、Clientless VPN
D、Prisma Browser
An administrator is configuring Security policies in a cloud-managed Prisma Access environment and needs to create a rule specifically for traffic generated by users accessing internal applications through the Clientless VPN portal.Which predefined zone must the administrator use as the source zone for this policy?
A、Trust
B、Untrust
C、Web-access
D、Clientless VPN
Which two frameworks are compared in the Compliance Summary dashboard of Strata Cloud Manager (SCM)? (Choose two.)
A、GDPR
B、NIST
C、PCI-DSS
D、CIS
A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs. Which two report types achieve this goal? (Choose two.)
A、AI
B、PDF summary
C、Custom
D、SNMP
Which two modes should be enabled on the GlobalProtect agent to allow a subset of users to connect directly to SaaS and internal applications while allowing the remaining users to connect through third-party VPN? (Choose two.)
A、Remote desktop protocol (RDP)
B、Proxy
C、Tunnel
D、Clientless
What are two indications that a packet has been processed into a fast path session? (Choose two.)
A、Content and application inspection is recognized.
B、Initial forwarding look is using a FIB.
C、Previous packets of the same session have been identified.
D、Security policy lookup is initiated.
Which two features are supported when using traffic steering rules for remote network deployment on Prisma Access? (Choose two.)
A、Bidirectional Forwarding Detection (BFD)
B、External dynamic list
C、Remote desktop protocol (RDP)
D、Dynamic Address Group
When physical ION devices are allocated, in which two states are they displayed on the Prisma SD-WAN web interface under "Devices"? (Choose two.)
A、Offline
B、Standby
C、Unclaimed
D、Needs attention
A firewall administrator wants to enable host information profiles (HIPs) to collect information from corporate hosts by using GlobalProtect.Which two details will the administrator be able to collect from the host? (Choose two.)
A、WAN statistics
B、Antivirus definitions
C、Host memory consumption
D、Disk encryption
Which two tools can be used to configure Cloud NGFWs for AWS? (Choose two.)
A. Prisma Cloud management console
B. Cortex XSIAM
C. Cloud service provider (CSP) management console
D. Panorama
In which two applications can Prisma Access threat logs for mobile user traffic be reviewed? (Choose two.)
A. Prisma Cloud dashboard
B. Strata Cloud Manager (SCM)
C. Strata Logging Service
D. Service connection firewall
A network security engineer needs to implement segmentation but is under strict compliance requirementsto place security enforcement as close as possible to the private applications hosted in Azure.Which deployment style is valid and meets the requirements in this scenario?
A. On a PA-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logicallysegment the network.
B. On a VM-Series NGFW, configure several Layer 3 zones with Layer 3 interfaces assigned to logicallysegment the network.
C. On a VM-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logicallysegment the network.
D. On a PA-Series NGFW, configure several Layer 2 zones with Layer 2 interfaces assigned to logicallysegment the network.
When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, when can the firewall be poweredon?
A. During license activation
B. After activating registration and completing license deployment profile
C. After all required installation and setup procedures are completed
D. During installation
Which profile can help prevent the transmission of sensitive information to internet applications?
A. Antivirus
B. Data Filtering
C. Anti-spyware
D. URL Filtering
How do template stacks help manage firewall configurations in Panorama?
A. By grouping templates across multiple firewalls
B. By creating template variables for permanent configurations in firewalls
C. By creating a diagram of the network for a view of all firewalls
D. By handling firmware updates across multiple firewalls
Which subscription sends non-file format-based traffic that matches Data Filtering profile criteria to a cloudservice to render a verdict?
A. SaaS Security Inline
B. Enterprise DLP
C. Advanced URL Filtering
D. Advanced WildFire
A cloud security architect is designing a certificate management strategy for Strata Cloud Manager (SCM)across hybrid environments.Which practice ensures optimal security with low management overhead?
A. Implement separate certificate authorities with independent validation rules for each cloudenvironment.
B. Configure manual certificate deployment with quarterly reviews and environment-specific securityprotocols.
C. Use cloud provider default certificates with scheduled synchronization and localized renewalprocesses.
D. Deploy centralized certificate automation with standardized protocols and continuous monitoring.
Which two prerequisites must be evaluated when decrypting internet-bound traffic? (Choose two.)
A. Incomplete certificate chains
B. RADIUS profile
C. Certificate pinning
D. SAML certificate
In which order does a next-generation firewall (NGFW) process URL categories for Security policy?
A. 1. External dynamic lists2. Custom URL categories3. Predefined categories
B. 1. Custom URL categories2. External dynamic lists3. Predefined categories
C. 1. Custom URL categories2. Predefined categories3. External dynamic lists
D. 1. Predefined categories2. External dynamic lists3. Custom URL categories
What must be configured to successfully onboard a Prisma Access remote network using Strata CloudManager (SCM)?
A. Cloud Identity Engine
B. GlobalProtect agent
C. IPSec termination node
D. Autonomous Digital Experience Manager (ADEM)
Which zone is available for use in Prisma Access?
A. Clientless VPN
B. DMZ
C. Interzone
D. Intrazone
Which firewall attribute simplifies rule creation and automatically adapts to changes in server roles orsecurity posture based on log events?
A. Dynamic Address Groups
B. Dynamic User Groups
C. Predefined IP addresses
D. Address objects
What is a necessary step for creation of a custom Prisma Access report on Strata Cloud Manager (SCM)?
A. Open a support ticket.
B. Configure a dashboard.
C. Generate a PDF summary report.
D. Set up Cloud Identity Engine.
Which feature of SaaS Security will allow a firewall administrator to identify unknown SaaS applications inan environment?
A. App-ID Cloud Engine
B. SaaS Data Security
C. Cloud Identity Engine
D. App-ID
When a rule has been set up to block uploading all Portable Executable (PE) files, which type of log willdisplay blocked files that attempt to traverse the network?
A. Traffic
B. Data filtering
C. URL filtering
D. Threat
A network security engineer wants to forward Strata Logging Service data to tools used by the securityoperations center (SOC) for further investigation.In which best practice step of Palo Alto Networks Zero Trust does this fit?
A. Implementation
B. Standards and Designs
C. Map and Verify Transactions
D. Report and Maintenance
Using Prisma Access, which solution provides the most security coverage of network protocols for themobile workforce?
A. Enterprise browser
B. Explicit proxy
C. Client-based VPN
D. Clientless VPN
Which Security policy on a data center NGFW will block intrazone traffic in Zone Colorado for the DynamicUser Group "Testers" and custom application "Payment System"?
A. Source & Destination Zone = ColoradoUsers = TestersApplication = Payment SystemAction = Deny
B. Source & Destination Zone = ColoradoUsers = TestersApplication = AnyAction = Deny
C. Source Zone = ColoradoDestination Zone = LAUsers = TestersApplication = Payment SystemAction = Deny
D. Source Zone = ColoradoDestination Zone = LAUsers = TestersApplication = AnyAction = Deny
A primary firewall in a high availability (HA) pair is experiencing a current failover issue with ICMP pings toa secondary device.Which metric should be reviewed for proper ICMP pings between the firewall pair?
A. Non-functional state
B. Bidirectional Forwarding Detection (BFD)
C. Link monitoring
D. Heartbeat polling
After a firewall is associated with Strata Cloud Manager (SCM), which two additional actions are requiredto enable management of the firewall from SCM? (Choose two.)
A. Install a device certificate.
B. Configure a Security policy allowing "stratacloudmanager.paloaltonetworks.com" for all users.
C. Configure NTP and DNS servers for the firewall.
D. Deploy a service connection for each branch site and connect with SCM.
In which order is Prisma SD-WAN dynamic path selection performed?
A. 1. Determine potential paths based on policy.2. Determine link quality.3. Measure application performance.4. Measure link capacity.
B. 1. Measure link capacity.2. Measure application performance.3. Determine link quality.4. Determine potential paths based on policy.
C. 1. Determine potential paths based on policy.2. Measure application performance.3. Determine link quality.4. Measure link capacity.
D. 1. Determine link quality.2. Measure link capacity.3. Measure application performance.4. Determine potential paths based on policy
Which two frameworks are compared in the Compliance Summary dashboard of Strata Cloud Manager(SCM)? (Choose two.)
A. GDPR
B. NIST
C. PCI-DSS
D. CIS
Which NGFW tool should be reviewed when a management team wants feedback on how to reduce theattack surface of their network security deployment and how it maps to the Center for Internet Security(CIS) Critical Security Controls?
A. Executive summary report
B. Policy Optimizer
C. Best Practice Assessment (BPA)
D. Command Center
A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs.Which two report types achieve this goal? (Choose two.)
A. AI
B. PDF summary
C. Custom
D. SNMP
Which two types of logs must be forwarded to Strata Logging Service for IoT Security to function? (Choosetwo.)
A. WildFire
B. Enhanced application
C. Threa
D. Traffic
Which two modes should be enabled on the GlobalProtect agent to allow a subset of users to connectdirectly to SaaS and internal applications while allowing the remaining users to connect through third-partyVPN? (Choose two.)
A. Remote desktop protocol (RDP)
B. Proxy
C. Tunnel
D. Clientless
In which security profile is credential phishing prevention implemented?
A. URL Filtering
B. Vulnerability Protection
C. Antivirus
D. Anti-spyware
How does PAN-OS identify App-IDs to perform application-layer inspection?
A. From predefined static rules based on IP addresses and ports configured by the administrator
B. From inspection of SSL certificates, cloud-based metadata, and manual application classification bythe administrator
C. From periodic updates that categorize web traffic based on domain names, focusing on web-browsingactivities
D. From multiple classification mechanisms - application signatures, application protocol decoding, andheuristics
Which GlobalProtect configuration is recommended for granular security enforcement of remote userdevice posture?
A. Applying log at session end to all GlobalProtect Security policies
B. Configuring host information profile (HIP) checks for all mobile users
C. Configuring a rule that blocks the ability of users to disable GlobalProtect while accessing internalapplications
D. Implementing multi-factor authentication (MFA) for all users attempting to access internal applications
Which two features can a network administrator use to troubleshoot the issue of a Prisma Access mobileuser who is unable to access SaaS applications? (Choose two.)
A. Autonomous Digital Experience Manager (ADEM) console
B. Capacity Analyzer
C. Global Protect logs
D. SaaS Application Risk Portal
Which file type does Advanced WildFire support for inline analysis to detect advanced malware?
A. PE
B. APK
C. PDF
D. JAR
An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a datacenter NGFW that already has one enabled.What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?
A. It allows for traffic inspection at the application level.
B. There will be only a minor reduction in performance.
C. There will be no additional performance degradation.
D. It allows additional security inspection devices to be added inline.
What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?
A. 9.1 --> 11.2
B. 9.1 --> 11.0 --> 11.2
C. 9.1 --> 10.0 --> 11.0 --> 11.2
D. 9.1 --> 10.0 --> 11.0 --> 11.1 --> 11.2
By default, how often are signatures updated for firewalls with Advanced WildFire?
A. In real time
B. Within 5-10 minutes
C. Within 24-48 hours
D. Once a week
Which functionality does an NGFW use to determine whether new session setups are legitimate orillegitimate?
A. SYN bit
B. SYN flood protection
C. SYN cookies
D. Random Early Detection (RED)
Which set of attributes is used by IoT Security to identify and classify appliances on a network whendetermining Device-ID?
A. IP address, network traffic patterns, device type
B. MAC address, device manufacturer, operating system
C. Hostname, application usage, encryption method
D. Device model, firmware version, user credential
How does a firewall behave when SSL Inbound Inspection is enabled?
A. It decrypts inbound and outbound SSH connections.
B. It acts as meddler-in-the-middle between the client and the internal server.
C. It acts transparently between the client and the internal server.
D. It decrypts traffic between the client and the external server.
In a service provider environment, what key advantage does implementing virtual systems provide formanaging multiple customer environments?
A. Shared threat prevention policies across all tenants
B. Centralized authentication for all customer domains
C. Unified logging across all virtual systems
D. Logical separation of control and Security policy
What are two indications that a packet has been processed into a fast path session? (Choose two.)
A. Content and application inspection is recognized.
B. Initial forwarding look is using a FIB.
C. Previous packets of the same session have been identified
D. Security policy lookup is initiated.
Which two content updates can be pushed to NGFWs from Panorama? (Choose two.)
A. WildFire
B. Applications and threats
C. Advanced URL Filtering
D. GlobalProtect data file
An administrator is responsible for updating which component of Prisma Access?
A. Management plane
B. Content updates
C. Data plane
D. VPN client
A Prisma Access administrator wants to attach the same set of Security policies to each new rule created.How can the administrator automate the profiles to be attached to new rules?
A. Create profiles for each CDSS and name them "default."
B. Create a security profile group and name it "default."
C. Use AIOps to automate the security profile group attachment.
D. Use Policy Analyzer after creating the new rules.
Which two components of a Security policy, when configured, allow third-party contractors access tointernal applications outside business hours? (Choose two.)
A. User-ID
B. Service
C. Schedule
D. App-ID
Which two features are supported when using traffic steering rules for remote network deployment onPrisma Access? (Choose two.)
A. Bidirectional Forwarding Detection (BFD)
B. External dynamic list
C. Remote desktop protocol (RDP)
D. Dynamic Address Group
Where does an administrator update the collection of infected hosts in Strata Cloud Manager (SCM) whenisolating an identified endpoint from a network?
A. Quarantined device list
B. Quarantine devices
C. Actions
D. Host information profile (HIP)
How does Strata Logging Service help resolve ever-increasing log retention needs for a company usingPrisma Access?
A. Log traffic using the licensed bandwidth purchased for Prisma Access reduces overhead.
B. Automatic selection of physical data storage regions decreases adoption time.
C. It scales to meet the capacity needs of new locations as business grows.
D. It increases resilience due to decentralized collection and storage of logs.
When physical ION devices are allocated, in which two states are they displayed on the Prisma SD-WANweb interface under "Devices"? (Choose two.)
A. Offline
B. Standby
C. Unclaimed
D. Needs attention
Which step is necessary to ensure an organization is using the inline cloud analysis features in itsAdvanced Threat Prevention subscription?
A. Update or create a new Anti-spyware security profile and enable the appropriate local deep learningmodels.
B. Enable SSL decryption in Security policies to inspect and analyze encrypted traffic for threats.
C. Disable anti-spyware to avoid performance impacts and rely solely on external threat intelligence.
D. Configure Advanced Threat Prevention profiles with default settings and only focus on high-risk trafficto avoid affecting network performance.
How do Cloud NGFW instances get created when using AWS centralized deployments?
A. A security VPC will be created as transit gateways to push all traffic through the area.
B. They are placed in a vWAN with a virtual hub.
C. Selected VPCs will have Cloud NGFW workloads added to them.
D. They replace the internet gateway service.
Why would a packet be processed through the slow path on an NGFW?
A. It does not require application identification or user identification.
B. It is part of an already established session.
C. It is part of a new or unestablished session.
D. It only needs basic NAT and Security policy enforcement.
A company has an ongoing initiative to monitor and control IT-sanctioned SaaS applications. To besuccessful, it will require configuration of decryption policies, along with data filtering and URL Filteringprofiles used in Security policies.Based on the need to decrypt SaaS applications, which two steps are appropriate to ensure success?(Choose two.)
A. Validate which certificates will be used to establish trust.
B. Configure SSL Inbound Inspection.
C. Create new self-signed certificates to use for decryption.
D. Configure SSL Forward Proxy.
Which security profile provides real-time protection against threat actors who exploit the misconfigurationsof DNS infrastructure and redirect traffic to malicious domains?
A. Intelligent Run-time Memory Analysis
B. Machine learning (ML)
C. Dynamic analysis
D. Static analysis
Which security profile provides real-time protection against threat actors who exploit the misconfigurationsof DNS infrastructure and redirect traffic to malicious domains?
A. Anti-spyware
B. URL Filtering
C. Antivirus
D. Vulnerability Protection
How many places will a firewall administrator need to create and configure a custom data loss prevention(DLP) profile across Prisma Access and the NGFW?
A. One
B. Two
C. Three
D. Four
Within which security profile is the DNS sinkholing action enabled?
A. File Blocking
B. Antivirus
C. Anti-spyware
D. DoS Protection
When a firewall acts as an application-level gateway (ALG), what does it require in order to establish aconnection?
A. Dynamic IP and Port (DIPP)
B. Session Initiation Protocol (SIP)
C. Payload
D. Pinholes
Which two configurations are required when creating deployment profiles to migrate a perpetual VM-Seriesfirewall to a flexible VM? (Choose two.)
A. Allow only the same security services as the perpetual VM.
B. Deploy virtual Panorama for management.
C. Choose "Fixed vCPU Models" for configuration type
D. Allocate the same number of vCPUs as the perpetual VM.
A firewall administrator wants to enable host information profiles (HIPs) to collect information fromcorporate hosts by using GlobalProtect.Which two details will the administrator be able to collect from the host? (Choose two.)
A. WAN statistics
B. Antivirus definitions
C. Host memory consumption
D. Disk encryption
Which NGFW function can be used to enhance visibility, protect, block, and log the use of Post-quantumCryptography (PQC)?
A. DNS Security profile
B. Decryption profile
C. Security policy
D. Decryption policy
An organization’s Security policy requires all SSL/TLS traffic using post-quantum cryptography (PQC)algorithms to be identified and logged.Which next-generation firewall (NGFW) feature provides the settings for this purpose?
A. Decryption policy
B. SSL/TLS service profile
C. Decryption profile
D. Anti-spyware profile
In which order of precedence is App-ID evaluated and determined?
A. 1. ACE cloud2. Content-based3. Custom
B. 1. Custom2. ACE cloud3. Content-based
C. 1. Content-based2. Custom3. ACE cloud
D. 1. Custom2. Content-based3. ACE cloud
An administrator is configuring an Advanced WildFire Analysis profile on a PAN-OS firewall. The objectiveis to use inline cloud analysis to prevent unknown malware targeting Windows endpoints from traversingthe firewall.Which file type is supported for this analysis?
A. JAR
B. APK
C. PE
D. DMG
An administrator has created a security profile group containing the organization’s standard Antivirus, Anti Spyware, and Vulnerability Protection profiles. This specific group will be the default applied to any newsecurity rule created in Prisma Access.Which step is required for the group to attach automatically to new rules?
A. Place the group at the top of the security profile groups list.
B. In the Prisma Access settings, specify the group as “Default Security Group”.
C. Name the security profile group “default”.
D. Name each individual profile within the group “default”.
Which tool allows a Prisma Access administrator to gather Active Directory groups to be used in user-to group mappings?
A. Cloud Identity Engine
B. SAML-based integration
C. Active Directory server profile
D. SCIM-based integration
Which activity only appears under the Content-ID portion of single-pass parallel processing (SP3)?
A. SaaS Security
B. Malware analysis
C. Application decoding
D. Application heuristics
Which combination of techniques does App-ID use to control a specific application, regardless of the port ituses?
A. Heuristics application signatures, and application protocol decoding
B. User-ID agent host information profiles (HIPs), and group mappings
C. SSL/TLS handshake analysis and certificate metadata
D. Threat intelligence feeds and the WildFire signature database
Which mechanism in a PAN-OS high availability (HA) configuration enables the firewalls to continuouslyexchange ICMP-based keep-alive messages over the HA1 (control) link to verify that the peer device isoperational?
A. Heartbeat backup
B. HA state synchronization
C. Link state monitoring
D. Bidirectional Forwarding Detection (BFD)
What role does a firewall play in the communication flow when SSL Inbound Inspection is configured toprotect an internally hosted web server from encrypted threats originating from the internet?
A. It inspects the initial SSL handshake to block malicious server names while passing on other data tothe internal server.
B. It acts as a forward proxy for outbound client connections.
C. It transparently passes the encrypted session to the server for inspection.
D. It acts as a meddler-in-the-middle to decrypt traffic from the external client before sending it on.
As part of a Zero Trust implementation, a security team has completed defining its micro-perimeters andwriting all the initial context-based Security policy rules. Now, it is focused on collecting and analyzing logsto ensure the policies are working as intended.Which step of the Palo Alto Networks five-step methodology is the team now performing?
A. Monitor and Maintain Your Network
B. Architect a Zero Trust Network
C. Map Your Transaction Flows
D. Define Your Attack Surface
An administrator has configured a Data Filtering profile to detect credit card numbers and wants to preventthis sensitive data from being exfiltrated not only through file uploads, but also when users type it into webforms or SaaS application text fields.Which subscription will enable this inspection of non-file traffic?
A. Advanced URL Filtering
B. Enterprise DLP
C. Predefined Data Pattern
D. Threat Prevention
An administrator is configuring a new Enterprise DLP policy to unify the data loss prevention (DLP)strategy across the entire infrastructure, which includes physical NGFWs and Prisma Access.In regard to profile configuration, what is the primary advantage of this approach?
A. Each NGFW and Prisma Access gateway requires its own locally defined DLP profile.
B. A single data profile is created in the cloud and applied consistently across enforcement points.
C. The NGFW profile is first exported and then imported into the Prisma Access configuration.
D. Profiles are created on Panorama and synced securely to a separate cloud instance for PrismaAccess.
An organization is deploying Prisma Access managed by Strata Cloud Manager (SCM) and the networkengineer is onboarding a remote network that uses a non-Palo Alto Networks firewall.What must be configured in SCM to terminate the secure connection from the remote network?
A. IPSec termination node
B. GlobalProtect agent
C. Autonomous Digital Experience Management (ADEM)
D. ZTNA Connector
Which feature can be used as a policy source or destination object that is automatically populated basedon IP-to-tag mapping actions initiated by log events?
A. Dynamic User Group
B. Log Forwarding profile
C. Auto-tagging
D. Dynamic Address Group
An organization is deploying Cloud NGFW on AWS and has chosen a centralized model to inspect trafficbetween multiple VPCs and the internet.Which statement describes the deployment of Cloud NGFW instances in this model?
A. Cloud NGFW instances are configured as a virtual hub within an AWS vWAN
B. A security VPC is created to host Cloud NGFW endpoints, and an AWS Transit Gateway routes VPCtraffic
C. Each spoke VPC is deployed with a Cloud NGFW instance and then managed by a centralized AWSaccount
D. Cloud NGFW instances are placed inline with the AWS internet security gateway, automaticallyinspecting all traffic.
Which Prisma Access solution provides the ability to inspect traffic from all applications on user devices?
A. Explicit proxy
B. GlobalProtect
C. Clientless VPN
D. Prisma Browser
An administrator is configuring Security policies in a cloud-managed Prisma Access environment andneeds to create a rule specifically for traffic generated by users accessing internal applications through theClientless VPN portal.Which predefined zone must the administrator use as the source zone for this policy?
A. Trust
B. Untrust
C. Web-acces
D. Clientless VPN
Which method in the WildFire analysis report detonates unknown submissions to provide visibility into real world effects and behavior?
A. Machine learning (ML)
B. Intelligent Run-time Memory Analysis
C. Static analysis
D. Dynamic analysis
Which Strata Cloud Manager for Prisma Access component specifically functions as the cloud-basedendpoint for a secure connection from a remote branch site?
A. IPSec termination node
B. Service connection
C. Cloud-managed SD-WAN branch
D. GlobalProtect gateway
A security engineer is reviewing the data collected in Strata Logging Service. The goal is to continuouslyvalidate that all traffic is being inspected, that Zero Trust policies are being enforced correctly, and to huntfor potential threats.This ongoing process of inspection and analysis corresponds to which step of the five-step Zero Trustmethodology?
A. Create Your Zero Trust Policy
B. Architect a Zero Trust Network
C. Monitor and Maintain Your Network
D. Map Your Transaction Flows
Which configuration ensures a baseline profile group is attached to all new rules automatically?
A. Set the required profile group in the Monitor --> PDF Reports --> Report Groups settings.
B. Enable AI Ops for Security Policy to add the profiles.
C. Define a security profile group with the specific name “default”.
D. Use a “default” tag on the security profile group and apply a dynamic policy.
An administrator is configuring URL filtering and needs to ensure that a specific list of partner websites isalways allowed, while a list of known malicious domains from a threat feed is blocked. All other web trafficshould be categorized by the firewall’s built-in categories.In which order will the firewall evaluate these different URL category types in its Security policy?
A. Predefined categoriesCustom URL categoriesExternal dynamic lists
B. External dynamic listsCustom URL categoriesPredefined categories
C. Predefined categoriesExternal dynamic listsCustom URL categories
D. Custom URL categoriesExternal dynamic listsPredefined categories
A security team wants to implement a centralized deployment of Cloud NGFW for AWS. The designrequires that all traffic from spoke VPCs is routed through a single point of inspection.Which configuration will meet the requirement?
A. Cloud NGFW endpoints are attached to each individual spoke VPC.
B. Cloud NGFW instances are deployed into a vWAN hub.
C. The security gateway in each spoke VPC is replaced by a Cloud NGFW instance
D. A security VPC is created, and a transit gateway is used to route traffic to it for inspection
A security team wants to gain visibility into the use of post-quantum cryptography (PQC) on their network.They want to log all instances of PQC algorithm negotiation in TLS traffic.Which component must be configured to achieve this logging?
A. Decryption policy rule
B. Security policy with logging enabled for a PQC application
C. Custom threat signature for PQC
D. Decryption profile
An organization has implemented Palo Alto Networks Enterprise DLP and needs to apply a specific datapattern to inspect traffic on both the on-premises NGFWs and the Prisma Access deployment for remoteusers.How many unique data profiles must the administrator build to enforce this policy in both locations?
A. Two, one for each platform
B. One, only for the second platform
C. Two, a primary and a backup
D. One, for a unified platform
An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a datacenter NGFW that already has one enabled.What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?
A. There will be only a minor reduction in performance
B. There will be no additional performance degradation
C. It allows additional security inspection devices to be added inline
D. It allows for traffic inspection at the application level.
A Panorama administrator is managing a large number of firewalls that share some commonconfigurations but also have unique settings based on their function (e.g., datacenter versus branch) andhas created separate templates for each set of configurations.What is the primary purpose of using a template stack in this scenario?
A. To apply different Security policy rulebases to different firewalls
B. To define specific IP addresses for firewalls within a single template
C. To group firewalls that will receive the same software version
D. To create an ordered, merged configuration from multiple templates
A security administrator wants to enhance a firewall’s command-and-control (C2) and phishing detectionby using the Advanced Threat Prevention subscription’s real-time cloud-based analysis.Which configuration step is required to activate inline cloud analysis?
A. Create a custom URL Filtering profile to block C2 and phishing categories
B. Enable SSL decryption on the Security policy rule processing the traffic.
C. Enable the inline-cloud-analysis action within the organization’s active anti-spyware profile.
D. Install the latest Advanced Threat Prevention content update from the software center.
An administrator has enabled a feature that submits metadata for unknown application traffic to the PaloAlto Networks cloud for analysis. This process results in the firewall receiving new application signatureswithout waiting for the next scheduled content update.Which component facilitates this rapid, cloud-based application identification?
A. Strata Logging Service
B. WildFire
C. Content-ID
D. App-ID Cloud Engine
What are the primary classification mechanisms used by PAN-OS App-ID to identify applications?
A. Predefined static rulesDNS lookupsPort number
B. IP addressPort numberProtocol
C. URL filtering databaseDNS lookupsSSL certificate properties
D. Application signaturesApplication protocol decodingHeuristics
An administrator is using Strata Cloud Manager (SCM) to configure Prisma Access for a new branchoffice. The goal is to connect the branch office’s existing third-party router to the Prisma Access cloud.Which component must be configured in SCM to serve as the Prisma Access endpoint for the secureconnection from the office router?
A. GlobalProtect portal
B. IPSec termination node
C. Cloud Identity Engine
D. Service connection
Which design principle enables Palo Alto Networks Next-Generation Trust Security (NGTS) to deliverorganization-wide visibility and control over machine identities?
A. Routing all certificate validation queries through a dedicated Secure Web Gateway (SWG) usingspecialized DNS filtering.
B. Deploying decentralized cryptographic mesh networks that handle identity mapping independently ofthe cloud management console.
C. Embedding automated lifecycle workflows and SaaS-based private public key infrastructure (PKI)directly into network enforcement and control systems.
D. Using agent-based scanning utilities that sync local cloud keystores directly to a third-party SecurityInformation and Event Management (SIEM) system.
An administrator is checking the health of an active/passive high availability (HA) pair to verify the specificmechanism that sends ICMP pings over the HA control link (HA1) and to ensure the passive device isresponsive.Which HA mechanism is responsible for this ICMP-based health check?
A. Heartbeat backup
B. Path monitoring
C. Session synchronization
D. Link monitoring
To support adaptive security decisions during the industry shift to shorter certificate lifecycles, how doesNext-Generation Trust Security (NGTS) enforce compliance across the enterprise platform?
A. It uses continuous monitoring and policy-driven automation embedded within Strata Cloud Manager(SCM) to discover and refresh credentials automatically.
B. It requires the deployment of standalone signature-based endpoint agents to discover shadowcertificates on private networks.
C. It routes all traffic associated with expiring certificates through an isolated sandbox until a networkadministrator initiates a manual reset.
D. It automatically disables TLS decryption on next-generation firewalls when an internal certificate entersan expired state.
An administrator is using Zero Touch Provisioning (ZTP) to onboard a new PA-Series firewall toPanorama. The device has been registered, and all necessary licenses and subscriptions have beenactivated in the Customer Support Portal.At which point in the ZTP workflow should the firewall be physically powered on at the remote location?
A. As soon as the firewall receives a DHCP address at the remote site
B. Before registering it in the Customer Support Portal
C. After adding its serial number to Panorama and assigning its device group and template
D. While the administrator is activating the firewall licenses in the Customer Support Portal
Under the Palo Alto Networks Quantum-Safe Security framework, what is the operational distinctionbetween selecting PQC-Standard versus PQC-Experimental key exchange profiles within IKEv2configurations?
A. PQC-Standard mandates a complete transition to AES-512 symmetric blocks, while PQC-Experimentalpermits legacy AES-256 configurations.
B. PQC-Standard applies exclusively to site-to-site IPSec tunnels, whereas PQC-Experimental isreserved for remote workforce mobile access agents.
C. PQC-Standard relies on hardware-based asymmetric key storage, while PQC-Experimental usescloud-native software-defined tokens.
D. PQC-Standard uses validated algorithm families such as ML-KEM and Kyber, while PQC-Experimentalincorporates families like Frodo, BIKE, or HQC.
Which Palo Alto Networks platform capability should be deployed to protect custom AI models andproduction applications from complex runtime threats such as prompt injections, insecure outputs, andmodel denial-of-service (DoS) attacks?
A. Prisma AIRS AI Runtime Firewall, which monitors prompts, responses, and data flows across theworkload infrastructure in real time
B. Advanced DNS Security, which implements inline domain-level certificate pinning during nameresolution
C. Strata Device Security, which uses passive IoT telemetry signatures to profile unauthorized physicalcomputing nodes
D. Cortex XDR Agentic Assistant, which relies on behavioral biometric analytics to verify the identity ofautomated microservices
Why do harvest now, decrypt later tactics pose an immediate cybersecurity threat to organizations, even ifpractical quantum computers do not yet exist?
A. Legacy networks are vulnerable to immediate, automated key-exfiltration webhooks triggered byquantum-resistant endpoint agents.
B. Adversaries are currently capturing and archiving encrypted organization traffic with the intent todecrypt it once quantum capabilities mature.
C. Adversaries are using primitive quantum processors to inject real-time side-channel faults into currentAES-256 active data sessions.
D. The threat vector uses specialized quantum entangled particles to bypass classical perimeter packetfiltering rules passively.
When configuring PAN-OS decryption policies to control post-quantum cryptography (PQC) traffic, howdoes the next-generation firewall handle unsupported or experimental PQC algorithms in an inbound ClientHello?
A. It redirects the handshake to a localized Hardware Security Module (HSM) cluster to execute real-timecipher synthesis.
B. It automatically applies a dedicated Advanced DNS Security rule to block the destination domain’s IPaddress mapping.
C. It strips the unsupported PQC options from the "supported_groups" extension to force the session tonegotiate using verified classical algorithms.
D. It encapsulates the Client Hello inside an isolated Zero Trust microperimeters tunnel for cloudvalidation.
An administrator needs to apply a common set of global settings, which are defined in two separatetemplates, and a specific set of regional settings to a group of firewalls by using Panorama.Which Panorama feature allows the administrator to combine and apply both templates in a specific,prioritized order to the firewalls?
A. Collector Group
B. Device group
C. Template variables
D. Template stack
A significant amount of traffic is classified as "unknown-tcp" and "unknown-udp" in an organization’s trafficlogs. The security administrator needs to gain visibility into these applications to enforce proper Securitypolicies.Which SaaS Security feature is designed to analyze this traffic and provide specific application identities?
A. Anti-Spyware profile
B. App-ID Cloud Engine
C. Cloud Identity Engine
D. Enterprise DLP
An organization wants to enforce its data loss prevention (DLP) policy on traffic that is not in a file format,such as text entered into webmail or generative AI prompts. A Data Filtering profile has been created toidentify the sensitive data.Which cloud-based subscription is needed to receive this non-file traffic from the firewall and render averdict?
A. Advanced WildFire
B. SaaS Security Inline
C. Predefined Data Pattern
D. Enterprise DLP
An organization requires that all network traffic from corporate-managed devices, including non-webapplications and custom protocols, is routed through Prisma Access for full security inspection.Which mobile user connection method fulfills this requirement?
A. Clientless VPN
B. Client-based VPN
C. Secure web gateway (SWG)
D. Explicit proxy
Which specific metadata capability does Palo Alto Networks AI Access Security provide to help anorganization determine whether an obscure AI application presents an acceptable security risk?
A. Continuous fuzzing tool that executes remote denial-of-service (DoS) tests against the applicationprovider's API endpoints
B. Automated code audit that scans the external vendor’s public GitHub repository for supply chain flaws
C. Secure multiparty computation framework that replicates the vendor’s model weights within a localcloud account
D. Extensive application dictionary tracking multiple GenAI-specific attributes and risk scoring metrics
Which zone is predefined in cloud-managed Prisma Access but is not a default zone on an on-premisesPAN-OS firewall?
A. DMZ
B. Outside
C. Clientless VPN
D. Inside
A network security administrator is using Panorama to manage an organization's NGFWs. To ensure allnew Security policies have a consistent baseline of security profiles, such as Antivirus and Anti-Spyware,the administrator wants to automatically apply these profiles to every new rule.How can this automation be achieved?
A. Run a Best Practice Assessment (BPA) after committing the new rules.
B. Configure a "default" profile in each individual security profile type.
C. Write a commit script to append the profile group to all new rules.
D. Create a security profile group named "default."
In which location should an administrator implement a control on a next-generation firewall (NGFW) toblock any SSL/TLS sessions that use post-quantum cryptography (PQC) algorithms?
A. Security policy rule action
B. Decryption profile
C. DNS Security profile
D. Decryption policy rule
Which technical architectural component allows Palo Alto Networks Next-Generation Firewalls and PrismaAccess to perform deep text-level analysis of user prompt submissions against thousands of sensitive datacategories?
A. Forwarding policies that redirect matching traffic streams to the Enterprise Data Loss Prevention (DLP)service for inline Inspection
B. Local execution of dedicated Hardware Security Modules (HSMs) that rewrite outbound naturallanguage strings into secure hash structures
C. Integration with localized cloud identity engines to restrict prompt generation based on user groupauthorization tiers
D. Synchronization of global network logs with public certificate authority (CA) registries via automatedAPI webhooks
关闭
更多问卷
复制此问卷