考试名称

When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, when can the firewall be powered on?
Which profile can help prevent the transmission of sensitive information to internet applications?
How do template stacks help manage firewall configurations in Panorama?
In which order does a next-generation firewall (NGFW) process URL categories for Security policy?
When a rule has been set up to block uploading all Portable Executable (PE) files, which type of log will display blocked files that attempt to traverse the network?
Which Security policy on a data center NGFW will block intrazone traffic in Zone Colorado for the Dynamic User Group "Testers" and custom application "Payment System"?
In which order is Prisma SD-WAN dynamic path selection performed?
Which NGFW tool should be reviewed when a management team wants feedback on how to reduce the attack surface of their network security deployment and how it maps to the Center for Internet Security (CIS) Critical Security Controls?
In which security profile is credential phishing prevention implemented?
How does PAN-OS identify App-IDs to perform application-layer inspection?
Which file type does Advanced WildFire support for inline analysis to detect advanced malware?
What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?
By default, how often are signatures updated for firewalls with Advanced WildFire?
An administrator is responsible for updating which component of Prisma Access?
A Prisma Access administrator wants to attach the same set of Security policies to each new rule created. How can the administrator automate the profiles to be attached to new rules?
Where does an administrator update the collection of infected hosts in Strata Cloud Manager (SCM) when isolating an identified endpoint from a network?
Why would a packet be processed through the slow path on an NGFW?
Within which security profile is the DNS sinkholing action enabled?
An organization’s Security policy requires all SSL/TLS traffic using post-quantum cryptography (PQC)algorithms to be identified and logged.Which next-generation firewall (NGFW) feature provides the settings for this purpose?
In which order of precedence is App-ID evaluated and determined?
An administrator is configuring an Advanced WildFire Analysis profile on a PAN-OS firewall. The objective is to use inline cloud analysis to prevent unknown malware targeting Windows endpoints from traversing the firewall.Which file type is supported for this analysis?
An administrator has created a security profile group containing the organization’s standard Antivirus, Anti- Spyware, and Vulnerability Protection profiles. This specific group will be the default applied to any new security rule created in Prisma Access.Which step is required for the group to attach automatically to new rules?
Which tool allows a Prisma Access administrator to gather Active Directory groups to be used in user-to- group mappings?
Which activity only appears under the Content-ID portion of single-pass parallel processing (SP3)?
Which combination of techniques does App-ID use to control a specific application, regardless of the port it uses?
As part of a Zero Trust implementation, a security team has completed defining its micro-perimeters and writing all the initial context-based Security policy rules. Now, it is focused on collecting and analyzing logs to ensure the policies are working as intended.Which step of the Palo Alto Networks five-step methodology is the team now performing?
An administrator is configuring a new Enterprise DLP policy to unify the data loss prevention (DLP) strategy across the entire infrastructure, which includes physical NGFWs and Prisma Access.In regard to profile configuration, what is the primary advantage of this approach?
Which Prisma Access solution provides the ability to inspect traffic from all applications on user devices?
An administrator is configuring Security policies in a cloud-managed Prisma Access environment and needs to create a rule specifically for traffic generated by users accessing internal applications through the Clientless VPN portal.Which predefined zone must the administrator use as the source zone for this policy?
Which two frameworks are compared in the Compliance Summary dashboard of Strata Cloud Manager (SCM)? (Choose two.)
A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs. Which two report types achieve this goal? (Choose two.)
Which two modes should be enabled on the GlobalProtect agent to allow a subset of users to connect directly to SaaS and internal applications while allowing the remaining users to connect through third-party VPN? (Choose two.)
What are two indications that a packet has been processed into a fast path session? (Choose two.)
Which two features are supported when using traffic steering rules for remote network deployment on Prisma Access? (Choose two.)
When physical ION devices are allocated, in which two states are they displayed on the Prisma SD-WAN web interface under "Devices"? (Choose two.)
A firewall administrator wants to enable host information profiles (HIPs) to collect information from corporate hosts by using GlobalProtect.Which two details will the administrator be able to collect from the host? (Choose two.)
Which two tools can be used to configure Cloud NGFWs for AWS? (Choose two.)
In which two applications can Prisma Access threat logs for mobile user traffic be reviewed? (Choose two.)
A network security engineer needs to implement segmentation but is under strict compliance requirementsto place security enforcement as close as possible to the private applications hosted in Azure.Which deployment style is valid and meets the requirements in this scenario?
When adding a Zero Touch Provisioning (ZTP) firewall to Panorama, when can the firewall be poweredon?
Which profile can help prevent the transmission of sensitive information to internet applications?
How do template stacks help manage firewall configurations in Panorama?
Which subscription sends non-file format-based traffic that matches Data Filtering profile criteria to a cloudservice to render a verdict?
A cloud security architect is designing a certificate management strategy for Strata Cloud Manager (SCM)across hybrid environments.Which practice ensures optimal security with low management overhead?
Which two prerequisites must be evaluated when decrypting internet-bound traffic? (Choose two.)
In which order does a next-generation firewall (NGFW) process URL categories for Security policy?
What must be configured to successfully onboard a Prisma Access remote network using Strata CloudManager (SCM)?
Which zone is available for use in Prisma Access?
Which firewall attribute simplifies rule creation and automatically adapts to changes in server roles orsecurity posture based on log events?
What is a necessary step for creation of a custom Prisma Access report on Strata Cloud Manager (SCM)?
Which feature of SaaS Security will allow a firewall administrator to identify unknown SaaS applications inan environment?
When a rule has been set up to block uploading all Portable Executable (PE) files, which type of log willdisplay blocked files that attempt to traverse the network?
A network security engineer wants to forward Strata Logging Service data to tools used by the securityoperations center (SOC) for further investigation.In which best practice step of Palo Alto Networks Zero Trust does this fit?
Using Prisma Access, which solution provides the most security coverage of network protocols for themobile workforce?
Which Security policy on a data center NGFW will block intrazone traffic in Zone Colorado for the DynamicUser Group "Testers" and custom application "Payment System"?
A primary firewall in a high availability (HA) pair is experiencing a current failover issue with ICMP pings toa secondary device.Which metric should be reviewed for proper ICMP pings between the firewall pair?
After a firewall is associated with Strata Cloud Manager (SCM), which two additional actions are requiredto enable management of the firewall from SCM? (Choose two.)
In which order is Prisma SD-WAN dynamic path selection performed?
Which two frameworks are compared in the Compliance Summary dashboard of Strata Cloud Manager(SCM)? (Choose two.)
Which NGFW tool should be reviewed when a management team wants feedback on how to reduce theattack surface of their network security deployment and how it maps to the Center for Internet Security(CIS) Critical Security Controls?
A network engineer pushes specific Panorama reports of new AI URL category types to branch NGFWs.Which two report types achieve this goal? (Choose two.)
Which two types of logs must be forwarded to Strata Logging Service for IoT Security to function? (Choosetwo.)
Which two modes should be enabled on the GlobalProtect agent to allow a subset of users to connectdirectly to SaaS and internal applications while allowing the remaining users to connect through third-partyVPN? (Choose two.)
In which security profile is credential phishing prevention implemented?
How does PAN-OS identify App-IDs to perform application-layer inspection?
Which GlobalProtect configuration is recommended for granular security enforcement of remote userdevice posture?
Which two features can a network administrator use to troubleshoot the issue of a Prisma Access mobileuser who is unable to access SaaS applications? (Choose two.)
Which file type does Advanced WildFire support for inline analysis to detect advanced malware?
An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a datacenter NGFW that already has one enabled.What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?
What is the recommended upgrade path from PAN-OS 9.1 to PAN-OS 11.2?
By default, how often are signatures updated for firewalls with Advanced WildFire?
Which functionality does an NGFW use to determine whether new session setups are legitimate orillegitimate?
Which set of attributes is used by IoT Security to identify and classify appliances on a network whendetermining Device-ID?
How does a firewall behave when SSL Inbound Inspection is enabled?
In a service provider environment, what key advantage does implementing virtual systems provide formanaging multiple customer environments?
What are two indications that a packet has been processed into a fast path session? (Choose two.)
Which two content updates can be pushed to NGFWs from Panorama? (Choose two.)
An administrator is responsible for updating which component of Prisma Access?
A Prisma Access administrator wants to attach the same set of Security policies to each new rule created.How can the administrator automate the profiles to be attached to new rules?
Which two components of a Security policy, when configured, allow third-party contractors access tointernal applications outside business hours? (Choose two.)
Which two features are supported when using traffic steering rules for remote network deployment onPrisma Access? (Choose two.)
Where does an administrator update the collection of infected hosts in Strata Cloud Manager (SCM) whenisolating an identified endpoint from a network?
How does Strata Logging Service help resolve ever-increasing log retention needs for a company usingPrisma Access?
When physical ION devices are allocated, in which two states are they displayed on the Prisma SD-WANweb interface under "Devices"? (Choose two.)
Which step is necessary to ensure an organization is using the inline cloud analysis features in itsAdvanced Threat Prevention subscription?
How do Cloud NGFW instances get created when using AWS centralized deployments?
Why would a packet be processed through the slow path on an NGFW?
A company has an ongoing initiative to monitor and control IT-sanctioned SaaS applications. To besuccessful, it will require configuration of decryption policies, along with data filtering and URL Filteringprofiles used in Security policies.Based on the need to decrypt SaaS applications, which two steps are appropriate to ensure success?(Choose two.)
Which security profile provides real-time protection against threat actors who exploit the misconfigurationsof DNS infrastructure and redirect traffic to malicious domains?
Which security profile provides real-time protection against threat actors who exploit the misconfigurationsof DNS infrastructure and redirect traffic to malicious domains?
How many places will a firewall administrator need to create and configure a custom data loss prevention(DLP) profile across Prisma Access and the NGFW?
Within which security profile is the DNS sinkholing action enabled?
When a firewall acts as an application-level gateway (ALG), what does it require in order to establish aconnection?
Which two configurations are required when creating deployment profiles to migrate a perpetual VM-Seriesfirewall to a flexible VM? (Choose two.)
A firewall administrator wants to enable host information profiles (HIPs) to collect information fromcorporate hosts by using GlobalProtect.Which two details will the administrator be able to collect from the host? (Choose two.)
Which NGFW function can be used to enhance visibility, protect, block, and log the use of Post-quantumCryptography (PQC)?
An organization’s Security policy requires all SSL/TLS traffic using post-quantum cryptography (PQC)algorithms to be identified and logged.Which next-generation firewall (NGFW) feature provides the settings for this purpose?
In which order of precedence is App-ID evaluated and determined?
An administrator is configuring an Advanced WildFire Analysis profile on a PAN-OS firewall. The objectiveis to use inline cloud analysis to prevent unknown malware targeting Windows endpoints from traversingthe firewall.Which file type is supported for this analysis?
An administrator has created a security profile group containing the organization’s standard Antivirus, Anti Spyware, and Vulnerability Protection profiles. This specific group will be the default applied to any newsecurity rule created in Prisma Access.Which step is required for the group to attach automatically to new rules?
Which tool allows a Prisma Access administrator to gather Active Directory groups to be used in user-to group mappings?
Which activity only appears under the Content-ID portion of single-pass parallel processing (SP3)?
Which combination of techniques does App-ID use to control a specific application, regardless of the port ituses?
Which mechanism in a PAN-OS high availability (HA) configuration enables the firewalls to continuouslyexchange ICMP-based keep-alive messages over the HA1 (control) link to verify that the peer device isoperational?
What role does a firewall play in the communication flow when SSL Inbound Inspection is configured toprotect an internally hosted web server from encrypted threats originating from the internet?
As part of a Zero Trust implementation, a security team has completed defining its micro-perimeters andwriting all the initial context-based Security policy rules. Now, it is focused on collecting and analyzing logsto ensure the policies are working as intended.Which step of the Palo Alto Networks five-step methodology is the team now performing?
An administrator has configured a Data Filtering profile to detect credit card numbers and wants to preventthis sensitive data from being exfiltrated not only through file uploads, but also when users type it into webforms or SaaS application text fields.Which subscription will enable this inspection of non-file traffic?
An administrator is configuring a new Enterprise DLP policy to unify the data loss prevention (DLP)strategy across the entire infrastructure, which includes physical NGFWs and Prisma Access.In regard to profile configuration, what is the primary advantage of this approach?
An organization is deploying Prisma Access managed by Strata Cloud Manager (SCM) and the networkengineer is onboarding a remote network that uses a non-Palo Alto Networks firewall.What must be configured in SCM to terminate the secure connection from the remote network?
Which feature can be used as a policy source or destination object that is automatically populated basedon IP-to-tag mapping actions initiated by log events?
An organization is deploying Cloud NGFW on AWS and has chosen a centralized model to inspect trafficbetween multiple VPCs and the internet.Which statement describes the deployment of Cloud NGFW instances in this model?
Which Prisma Access solution provides the ability to inspect traffic from all applications on user devices?
An administrator is configuring Security policies in a cloud-managed Prisma Access environment andneeds to create a rule specifically for traffic generated by users accessing internal applications through theClientless VPN portal.Which predefined zone must the administrator use as the source zone for this policy?
Which method in the WildFire analysis report detonates unknown submissions to provide visibility into real world effects and behavior?
Which Strata Cloud Manager for Prisma Access component specifically functions as the cloud-basedendpoint for a secure connection from a remote branch site?
A security engineer is reviewing the data collected in Strata Logging Service. The goal is to continuouslyvalidate that all traffic is being inspected, that Zero Trust policies are being enforced correctly, and to huntfor potential threats.This ongoing process of inspection and analysis corresponds to which step of the five-step Zero Trustmethodology?
Which configuration ensures a baseline profile group is attached to all new rules automatically?
An administrator is configuring URL filtering and needs to ensure that a specific list of partner websites isalways allowed, while a list of known malicious domains from a threat feed is blocked. All other web trafficshould be categorized by the firewall’s built-in categories.In which order will the firewall evaluate these different URL category types in its Security policy?
A security team wants to implement a centralized deployment of Cloud NGFW for AWS. The designrequires that all traffic from spoke VPCs is routed through a single point of inspection.Which configuration will meet the requirement?
A security team wants to gain visibility into the use of post-quantum cryptography (PQC) on their network.They want to log all instances of PQC algorithm negotiation in TLS traffic.Which component must be configured to achieve this logging?
An organization has implemented Palo Alto Networks Enterprise DLP and needs to apply a specific datapattern to inspect traffic on both the on-premises NGFWs and the Prisma Access deployment for remoteusers.How many unique data profiles must the administrator build to enforce this policy in both locations?
An administrator wants to implement additional Cloud-Delivered Security Services (CDSS) on a datacenter NGFW that already has one enabled.What benefit does the NGFW’s single-pass parallel processing (SP3) architecture provide?
A Panorama administrator is managing a large number of firewalls that share some commonconfigurations but also have unique settings based on their function (e.g., datacenter versus branch) andhas created separate templates for each set of configurations.What is the primary purpose of using a template stack in this scenario?
A security administrator wants to enhance a firewall’s command-and-control (C2) and phishing detectionby using the Advanced Threat Prevention subscription’s real-time cloud-based analysis.Which configuration step is required to activate inline cloud analysis?
An administrator has enabled a feature that submits metadata for unknown application traffic to the PaloAlto Networks cloud for analysis. This process results in the firewall receiving new application signatureswithout waiting for the next scheduled content update.Which component facilitates this rapid, cloud-based application identification?
What are the primary classification mechanisms used by PAN-OS App-ID to identify applications?
An administrator is using Strata Cloud Manager (SCM) to configure Prisma Access for a new branchoffice. The goal is to connect the branch office’s existing third-party router to the Prisma Access cloud.Which component must be configured in SCM to serve as the Prisma Access endpoint for the secureconnection from the office router?
Which design principle enables Palo Alto Networks Next-Generation Trust Security (NGTS) to deliverorganization-wide visibility and control over machine identities?
An administrator is checking the health of an active/passive high availability (HA) pair to verify the specificmechanism that sends ICMP pings over the HA control link (HA1) and to ensure the passive device isresponsive.Which HA mechanism is responsible for this ICMP-based health check?
To support adaptive security decisions during the industry shift to shorter certificate lifecycles, how doesNext-Generation Trust Security (NGTS) enforce compliance across the enterprise platform?
An administrator is using Zero Touch Provisioning (ZTP) to onboard a new PA-Series firewall toPanorama. The device has been registered, and all necessary licenses and subscriptions have beenactivated in the Customer Support Portal.At which point in the ZTP workflow should the firewall be physically powered on at the remote location?
Under the Palo Alto Networks Quantum-Safe Security framework, what is the operational distinctionbetween selecting PQC-Standard versus PQC-Experimental key exchange profiles within IKEv2configurations?
Which Palo Alto Networks platform capability should be deployed to protect custom AI models andproduction applications from complex runtime threats such as prompt injections, insecure outputs, andmodel denial-of-service (DoS) attacks?
Why do harvest now, decrypt later tactics pose an immediate cybersecurity threat to organizations, even ifpractical quantum computers do not yet exist?
When configuring PAN-OS decryption policies to control post-quantum cryptography (PQC) traffic, howdoes the next-generation firewall handle unsupported or experimental PQC algorithms in an inbound ClientHello?
An administrator needs to apply a common set of global settings, which are defined in two separatetemplates, and a specific set of regional settings to a group of firewalls by using Panorama.Which Panorama feature allows the administrator to combine and apply both templates in a specific,prioritized order to the firewalls?
A significant amount of traffic is classified as "unknown-tcp" and "unknown-udp" in an organization’s trafficlogs. The security administrator needs to gain visibility into these applications to enforce proper Securitypolicies.Which SaaS Security feature is designed to analyze this traffic and provide specific application identities?
An organization wants to enforce its data loss prevention (DLP) policy on traffic that is not in a file format,such as text entered into webmail or generative AI prompts. A Data Filtering profile has been created toidentify the sensitive data.Which cloud-based subscription is needed to receive this non-file traffic from the firewall and render averdict?
An organization requires that all network traffic from corporate-managed devices, including non-webapplications and custom protocols, is routed through Prisma Access for full security inspection.Which mobile user connection method fulfills this requirement?
Which specific metadata capability does Palo Alto Networks AI Access Security provide to help anorganization determine whether an obscure AI application presents an acceptable security risk?
Which zone is predefined in cloud-managed Prisma Access but is not a default zone on an on-premisesPAN-OS firewall?
A network security administrator is using Panorama to manage an organization's NGFWs. To ensure allnew Security policies have a consistent baseline of security profiles, such as Antivirus and Anti-Spyware,the administrator wants to automatically apply these profiles to every new rule.How can this automation be achieved?
In which location should an administrator implement a control on a next-generation firewall (NGFW) toblock any SSL/TLS sessions that use post-quantum cryptography (PQC) algorithms?
Which technical architectural component allows Palo Alto Networks Next-Generation Firewalls and PrismaAccess to perform deep text-level analysis of user prompt submissions against thousands of sensitive datacategories?
更多问卷 复制此问卷