NGFW-Engineer Palo Alto Networks Next-Generation Firewall Engineer Questions and Answers
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
In a hybrid cloud deployment, what is the primary function of Ansible in managing Palo Alto Networks NGFWs?
An organization has configured GlobalProtect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user logon.
How does the GlobalProtect agent process the authentication flow on Windows endpoints?
What is a result of enabling split tunneling in the GlobalProtect portal configuration with the “Both Network Traffic and DNS” option?
Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?
According to dynamic updates best practices, what is the recommended threshold value for content updates in a mission- critical network?
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
What are two valid zone types that can be selected from the zone configuration menu, per Palo Alto Networks best practices? (Choose two answers)
Which networking technology can be configured on Layer 3 interfaces but not on Layer 2 interfaces?
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish.
Which of the following actions will resolve this issue?
By default, which type of traffic is configured by service route configuration to use the management interface?
What are the phases of the Palo Alto Networks AI Runtime Security: Network Intercept solution?
Which two services are configured by applying an SSL/TLS service profile? (Choose two answers)
An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service.
Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?
An administrator needs to perform several maintenance tasks on a managed firewall directly from the Panorama console, without using the Context Switch feature. Which set of tasks can the administrator fully execute from the Panorama UI? (Choose one answer)