1.
A network security engineer is asked to perform a Return Merchandise Authorization (RMA) on a firewall.
Which pair of files needs to be imported back into the replacement firewall that is using Panorama?
2.
A company has a web server behind a Palo Alto Networks next-generation firewall that it wants to make accessible to the public at 1.1.1.1. The company has decided to configure a destination NAT Policy rule.
Given the following zone information:
DMZ zone: DMZ-L3
Public zone: Untrust-L3
Guest zone: Guest-L3
Web server zone: Trust-L3
Public IP address (Untrust-L3): 1.1.1.1
Private IP address (Trust-L3): 192.168.1.50
What should be configured as the destination zone on the Original Packet tab of the NAT Policy rule?
3.
Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application is very sensitive and all traffic being identified needs to be inspected by the Content-ID engine.
Which method should company.com use to immediately address this traffic on a Palo Alto Networks device?
4.
What must be used in Security Policy Rules that contain addresses where NAT policy applies?
5.
A network security engineer is asked to provide a report on bandwidth usage. Which tab in the ACC provides the information needed to create the report?
6.
A network security engineer has been asked to analyze WildFire activity. However, the WildFire Submissions item is not visible from the Monitor tab.
What could cause this condition?
7.
A network administrator uses Panorama to push security policies to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrator wants to allow local administrators at the branch office sites to override these policies?
8.
What can cause missing SSL packets when performing a packet capture on dataplane interfaces?
9.
Which Security Policy Rule configuration option disables antivirus and anti-spyware scanning of server-to-client flows only?
10.
How are IPv6 DNS queries configured to use interface ethernet1/3?