10 free sample questions from a bank of 164, with the correct answers and explanations. No signup required — start practising right now.
1How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?
By using contracts between endpoint groups that send traffic to the firewall using a shared policy
Through a virtual machine (VM) monitor domain
Through a policy-based redirect (PBR)
By creating an access policy
Answer: C
2What are the two appropriate routing settings required to deploy software firewall integration with Amazon Web Service (AWS) GWLB? (Choose two.)
Route table with ALB subnet association - Add route destined to 0.0.0.0/0 with target as NAT Gateway
Route table with ALB subnet association - Add route destined to 0.0.0.0/0 with target as IGW
Route table with IGW edge association - Add route destined to ALB with target as GWLBE
Route table with GWLBE subnet association - Add route destined to 0.0.0.0/0 with target as IGW
Answer: A, D
3A user must be assigned one of which two roles in order to create local rulestacks in the Cloud NGFW for AWS tenant? (Choose two.)
LocalRuleStackAdmin
FirewallRulestackAdmin
GlobalRulestackAdmin
GlobalFirewallAdmin
Answer: A, B
4Which deployment method should a GCP administrator use to deploy a VM-Series firewall to secure east-west traffic between Virtual Private Clouds (VPCs)?
Internet gateway
Hybrid IPSec VPN
Segmentation gateway
GlobalProtect
Answer: C
5What are three attributes monitored by the Panorama AWS plugin? (Choose three.)
Private DNS name
Subnet ID
IAM instance profile
VPC ID
Public DNS name
Answer: B, C, D
6In the Cloud NGFW for AWS distributed outbound architecture model, what is the first hop the traffic takes from the source?
Internet gateway
Cloud NGFW
NGFW endpoint
NAT gateway
Answer: C
7Which port / interface must be assigned as the HA2 link when deploying VM-Series firewalls in High Availability (HA) on Amazon Web Services (AWS)?
HA2
MGT port
HSCI port
Ethernet1/1
Answer: D
8A system engineer is working on the Proof of Concept (POC) for Cloud Next-Generation Firewall (NGFW) for Azure using an existing Panorama setup. However, connection with the Cloud NGFW instance. What could be the cause of this issue?
There has not been an upgrade to the PAN-OS 10.2.
Cloud NGFW plugin has not been installed.
Valid device certificate is missing.
Necessary ports 8443 and 443 for communication between Cloud NGFW and Panorama are blocked.
Answer: A
9A system engineer managing a deployment of CN-Series with Panorama (software version 11.0) installs the Kubernetes Plugin. When the installation is complete, templates are present. What are the names of two of these templates and for what are they used? (Choose two.)
K8S-Network-Setup used for daemonset
K8S-Network-Setup-V2 used for Kubernetes as a service deployment
K8S-Network-Setup-V3 used for Kubernetes as a service deployment
K8S-Network-Setup-V3 used for CNF daemonset
Answer: A, B
10Which two statements apply to the management Cloud NGFW by AWS firewall manager? (Choose two.)
Availability Zone can be created.
Firewall policy can be included only with specified accounts and OUs.
Firewall policy must be applied to all accounts under the Amazon Web Services (AWS) organization.
Endpoints will be created via the firewall manager.