10 free sample questions from a bank of 116, with the correct answers and explanations. No signup required — start practising right now.
1What is the key benefit of Palo Alto Networks Single Pass Parallel Processing design?
There are no benefits other than slight performance upgrades
It allows Palo Alto Networks to add new functions to existing hardware
Only one processor is needed to complete all the functions within the box
It allows Palo Alto Networks to add new devices to existing hardware
Answer: B
2A customer requests that a known spyware threat signature be triggered based on a rate of occurrence, for example, 10 hits in 5 seconds.
How is this goal accomplished?
Create a custom spyware signature matching the known signature with the time attribute
Add a correlation object that tracks the occurrences and triggers above the desired threshold
Submit a request to Palo Alto Networks to change the behavior at the next update
Configure the Anti-Spyware profile with the number of rule counts to match the occurrence frequency
Answer: A
3In Panorama, which three reports or logs will help identify the inclusion of a host / source in a command-and-control (C2) incident? (Choose three.)
WildFire analysis reports
data filtering logs
hotnet reports
threat logs
SaaS reports
Answer:
4Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)
Enable App-ID.
Define a uniform resource locator (URL) Filtering profile.
Enable User-ID.
Enable User Credential Detection.
Define a Secure Sockets Layer (SSL) decryption rule base.
Answer:
5Which two statements correctly describe what a Network Packet Broker does for a Palo Alto Networks NGFW? (Choose two.)
It provides a third-party SSL decryption option, which can increase the total number of third-party devices performing analysis and enforcement.
It allows SSL decryption to be offloaded to the NGFW and traffic to be decrypted only once.
It eliminates the need for a third-party SSL decryption option, which reduces the total number of third-party devices performing decryption.
It allows SSL decryption to be offloaded to the NGFW and traffic to be decrypted multiple times.
Answer:
6A customer with a legacy firewall architecture focused on port-and-protocol-level security has heard that NGFWs open all ports by default.
Which of the following statements regarding Palo Alto Networks NGFWs is an appropriate rebuttal that explains an advantage over legacy firewalls?
They do not consider port information, instead relying on App-ID signatures that do not reference ports.
They protect all applications on all ports while leaving all ports open by default.
They can control applications by application-default service ports or a configurable list of approved ports on a per-policy basis.
They keep ports closed by default, only opening after understanding the application request, and then opening only the application-specified ports.
Answer: C
7Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
multi-factor authentication (MFA)
URL Filtering Profiles
WildFire analysis
dynamic user groups (DUGs)
Answer:
8A Fortune 500 customer has expressed interest in purchasing WildFire; however, they do not want to send discovered malware outside of their network.
Which version of WildFire will meet this customer’s requirements?
WildFire Government Cloud
WildFire Public Cloud
WildFire Private Cloud
WildFire Secure Cloud
Answer: C
9What will a Palo Alto Networks next-generation firewall (NGFW) do when it is unable to retrieve a DNS verdict from the DNS cloud service in the configured lookup time?
block the query
allow the request and all subsequent responses
temporarily disable the DNS Security function
discard the request and all subsequent responses
Answer: B
10What will best enhance security of a production online system while minimizing the impact for the existing network?