問題1
Which two types of security profiles are recommended to protect against known and unknown threats?
(Choose two)
Which two types of security profiles are recommended to protect against known and unknown threats?
(Choose two)
正確答案: B,D
問題2
Match the App-ID adoption task with its order in the process.

Match the App-ID adoption task with its order in the process.

正確答案:

Explanation:
To match the App-ID adoption task with its order in the process, follow these steps:
* Perform a like-for-like (Layer 3/4) migration from the legacy firewall to the Palo Alto Networks NGFW.
* This is the initial step to ensure that the Palo Alto Networks NGFW is in place and functioning with the existing security policies.
* Capture, retain, and verify that all traffic has been logged for a period of time.
* This step involves enabling logging and monitoring traffic to understand the application usage and to ensure that all traffic is being logged.
* Clone the legacy rules and add application information to the intended application-based rules.
* This step involves creating copies of the existing rules and enhancing them with application-specific information using App-ID.
* Verify that no traffic is hitting the legacy rules.
* After creating application-based rules, ensure that traffic is now hitting these new rules instead of the legacy rules. This indicates that the transition to App-ID based policies is successful.
* Remove the legacy rules.
* Once it is confirmed that no traffic is hitting the legacy rules and the new App-ID based rules are effectively managing the traffic, the legacy rules can be safely removed.
Order in Process:
* Perform a like-for-like (Layer 3/4) migration from the legacy firewall to the Palo Alto Networks NGFW.
* Capture, retain, and verify that all traffic has been logged for a period of time.
* Clone the legacy rules and add application information to the intended application-based rules.
* Verify that no traffic is hitting the legacy rules.
* Remove the legacy rules.
References:
* Palo Alto Networks - App-ID Best Practices: https://docs.paloaltonetworks.com/best-practices
* Palo Alto Networks - Migration from Legacy Firewalls: https://docs.paloaltonetworks.com/migration
問題3
Which GlobalProtect feature ensures that only trusted endpoints can connect to the network?
Which GlobalProtect feature ensures that only trusted endpoints can connect to the network?
正確答案: D
問題4
What happens when a packet from an existing session is received by a firewall that
What happens when a packet from an existing session is received by a firewall that
正確答案: C
說明:(僅 NewDumps 成員可見)
問題5
SSL Forward Proxy decryption is enabled on (he firewall When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates Which two options will satisfy this requirement? (Choose two.)
SSL Forward Proxy decryption is enabled on (he firewall When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates Which two options will satisfy this requirement? (Choose two.)
正確答案: B,C
說明:(僅 NewDumps 成員可見)
問題6
Which Panorama operational mode is necessary to manage a large number of firewalls and also act as a log collector?
Which Panorama operational mode is necessary to manage a large number of firewalls and also act as a log collector?
正確答案: D
問題7
Which category of Vulnerability Signatures is most likely to trigger false positive alerts?
Which category of Vulnerability Signatures is most likely to trigger false positive alerts?
正確答案: D
說明:(僅 NewDumps 成員可見)