版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
A"Continue"actioncanbeconfiguredonwhichofthefollowingSecurityProfiles?
URLFilteringandFileBlocking
URLFilteringonly
URLFilteringandAnti-virus
AConfigLockmayberemovedbywhichofthefollowingusers?(Selectallcorrectanswers.)
Theadministratorwhosetit
Anyadministrator
Deviceadministrators
Superusers
AftertheinstallationofanewApplicationandThreatdatabase,thefirewallmustberebooted.
True
False
AsaPaloAltoNetworksfirewalladministrator,youhavemadeunwantedchangestotheCandidateconfiguration.ThesechangesmaybeundonebyDevice>Setup>Operations>ConfigurationManagement>andthenwhatoperation?
ReverttoRunningConfiguration
ReverttolastSavedConfiguration
LoadConfigurationVersion
ImportNamedConfigurationSnapshot
AsthePaloAltoNetworksAdministratoryouhaveenabledApplicationBlockpages.Afterwards,notknowingtheyareattemptingtoaccessablockedweb-basedapplication,userscalltheHelpDesktocomplainaboutnetworkconnectivityissues.Whatisthecauseoftheincreasednumberofhelpdeskcalls?
Thefirewalladmindidnotcreateacustomresponsepagetonotifypotentialusersthattheirattempttoaccesstheweb-basedapplicationisbeingblockedduetocompanypolicy.
SomeApp-ID'saresetwithaSessionTimeoutvaluethatistoolow.
TheFileBlockingBlockPagewasdisabled.
ApplicationBlockPageswillonlybedisplayedwhenCaptivePortalisconfigured.
BothSSLdecryptionandSSHdecryptionaredisabledbydefault.
True
False
InaDestinationNATconfiguration,theTranslatedAddressfieldmaybepopulatedwitheitheranIPaddressoranAddressObject.
True
False
PaloAltoNetworksfirewallssupporttheuseofbothDynamic(built-inuserroles)andRole-Based(customizeduserroles)forAdministratorAccounts.
True
False
ReconnaissanceProtectionisafeatureusedtoprotectthePaloAltoNetworksfirewallfromportscans.ToenablethisfeaturewithintheGUIgoto…
Network>NetworkProfiles>ZoneProtection
Objects>ZoneProtection
Interfaces>InterfaceNumber>ZoneProtection
Policies>Profile>ZoneProtection
WhataretwosourcesofinformationfordeterminingwhetherthefirewallhasbeensuccessfulincommunicatingwithanexternalUser-IDAgent?
SystemLogsandtheindicatorlightundertheUser-IDAgentsettingsinthefirewall.
SystemLogsandanindicatorlightonthechassis.
TrafficLogsandAuthenticationLogs.
SystemLogsandAuthenticationLogs.
Whatisthemaximumfilesizeof.EXEfilesuploadedfromthefirewalltoWildFire?
Always2megabytes.
Always10megabytes.
Configurableupto2megabytes.
Configurableupto10megabytes
WhatwilltheuserexperiencewhenattemptingtoaccessablockedhackingwebsitethroughatranslationservicesuchasGoogleTranslateorBingTranslator?
A“Blocked”pageresponsewhentheURLfilteringpolicytoblockisenforced.
A“Success”pageresponsewhenthesiteissuccessfullytranslated.
Thebrowserwillberedirectedtotheoriginalwebsiteaddress.
An"HTTPError503-Serviceunavailable"message.
WhenaninterfaceisinTapmodeandaPolicy’sactionissetto“block”,theinterfacewillsendaTCPreset.
True
False
WhenusingConfigAudit,thecoloryellowindicateswhichofthefollowing?
Asettinghasbeenchangedbetweenthetwoconfigfiles
Asettinghasbeendeletedfromaconfigfile.
Asettinghasbeenaddedtoaconfigfile
Aninvalidvaluehasbeenusedinaconfigfile.
WhichofthefollowingmostaccuratelydescribesDynamicIPinaSourceNATconfiguration?
ThenextavailableIPaddressintheconfiguredpoolisused,butthesourceportnumberisunchanged.
AsingleIPaddressisused,andthesourceportnumberischanged.
Thenextavailableaddressintheconfiguredpoolisused,andthesourceportnumberischanged.
AsingleIPaddressisused,andthesourceportnumberisunchanged.
WhichofthefollowingservicesareenabledontheMGTinterfacebydefault?(Selectallcorrectanswers.)
HTTPS
SSH
Telnet
HTTP
WildFiremaybeusedforidentifyingwhichofthefollowingtypesoftraffic?
DHCP
OSPF
RIPv2
Malware
WillanexportedconfigurationcontainManagementInterfacesettings?
Yes
No
WithIKEPhase1,eachdeviceisidentifiedtotheotherbyaPeerID.Inmostcases,thePeerIDisjustthepublicIPaddressofthedevice.InsituationswherethepublicIPaddressisnotstatic,thePeerIDcanbeatextvalue.
True
False
TrueorFalse:ThePAN-DBURLFilteringServiceisofferedasbothaPrivateCloudsolutionandaPublicCloudsolution.
True
False
TrueorFalse:TheWildFireAnalysisProfilecanonlybeconfiguredtosendunknownfilestotheWildFirePublicCloudonly.
True
False
PAN-OS7.0introducedanewSecurityProfiletype.Whatisthenameofthisnewsecurityprofiletype?
ThreatAnalysis
MalwareAnalysis
WildFireAnalysis
FileAnalysis
AftertheinstallationofanewversionofPAN-OS,thefirewallmustberebooted.
True
False
Consideringtheinformationinthescreenshotabove,whatistheorderofevaluationforthisURLFilteringProfile?
BlockList,AllowList,CustomCategories,URLCategories(BrightCloudorPAN-DB).
AllowList,BlockList,CustomCategories,URLCategories(BrightCloudorPAN-DB).
Enabling"HighlightUnusedRules"intheSecurityPolicywindowwill:
DisplayrulesthatcausedavalidationerrortooccuratthetimeaCommitwasperformed.
Highlightallrulesthathavenotmatchedtrafficsincetherulewascreatedorsincethelastrebootofthefirewall.
Choosethebestanswer:InPAN-OS,theWildFireSubscriptionServiceallowsupdatesformalwaresignaturestobedistributedasoftenas…
Onceevery15minutes
Takingintoaccountonlytheinformationinthescreenshotabove,answerthefollowingquestion:Aspanportoraswitchisconnectedtoe1/4,buttherearenotrafficlogs.Whichofthefollowingconditionsmostlikelyexplainsthisbehavior?
Thereisnozoneassignedtotheinterface.
TrafficgoingtoapublicIPaddressisbeingtranslatedbyaPaloAltoNetworksfirewalltoaninternalserver’sprivateIPaddress.WhichIPaddressshouldtheSecurityPolicyuseasthe"DestinationIP"inordertoallowtraffictotheserver?
Theserver’spublicIP
Thefirewall’sMGTIP
Theserver’sprivateIP
Usersmaybeauthenticatedsequentiallytomultipleauthenticationserversbyconfiguring:
AnAuthenticationProfile.
AnAuthenticationSequence.
WhatisthedefaultDNSsinkholeaddressusedbythePaloAltoNetworksFirewalltocutoffcommunication?
Anylayer3interfaceaddressspecifiedbythefirewalladministrator.
Thedefaultgatewayofthefirewall.
Thelocalloopbackaddress.
WhatwillbetheuserexperiencewhenthesafesearchoptionisNOTenabledforGooglesearchbutthefirewallhas"SafeSearchEnforcement"Enabled?
AblockpagewillbepresentedwithinstructionsonhowtosetthestrictSafeSearchoptionfortheGooglesearch.
Ataskbarpop-upmessagewillbepresentedtoenableSafeSearch.
TheFirewallwillenforceSafeSearchiftheURLfilteringlicenseisstillvalid.
WhenconfiguringaDecryptionPolicyrule,whichoptionallowsafirewalladministratortocontrolSSHv2tunnelinginpoliciesbyspecifyingtheSSH-tunnelApp-ID?
SSHProxy
SSLForwardProxy
SSLReverseProxy
WhenconfiguringaSecurityPolicyRulebasedonFQDNAddressObjects,whichofthefollowingstatementsisTrue?
InordertocreateFQDN-basedobjects,youneedtomanuallydefinealistofassociatedIPaddresses.
ThefirewallresolvestheFQDNfirstwhenthepolicyiscommitted,andresolvestheFQDNagainatDNSTTLexpiration
WhenconfiguringthefirewallforUser-ID,whatisthemaximumnumberofDomainControllersthatcanbeconfigured?
50
10
100
WhentroubleshootingPhase1ofanIPsecVPNtunnel,whichlocationandlogwillbemostinformative?
Respondingside,Trafficlog
Respondingside,SystemLog
Whenusingremoteauthenticationforusers(LDAP,RADIUS,ActiveDirectory,etc.),whatmustbedonetoallowausertoauthenticatethroughmultiplemethods?
Createmultipleauthenticationprofilesforthesameuser.
CreateanAuthenticationSequence,dictatingtheorderofauthenticationprofiles.
Whichfeaturecanbeconfiguredtoblocksessionsthatthefirewallcannotdecrypt?
DecryptionProfileinDecryptionPolicy
WhichlinkisusedbyanActive/Passiveclustertosynchronizesessioninformation?
TheDataLink
TheUplink
TheManagementLink
WhichofthefollowingisNOTavalidoptionforbuilt-inCLIAdminroles?
deviceadmin
read/write
WhichofthefollowingmustbeenabledinorderforUser-IDtofunction?
CaptivePortalPoliciesmustbeenabled.
User-IDmustbeenabledforthesourcezoneofthetrafficthatistobeidentified
WhichroutingprotocolissupportedonthePaloAltoNetworksplatform?
BGP
RIPv1
RSTP
WhichstatementaboutconfiglocksisTrue?
Aconfiglockcanberemovedonlybyasuperuser.
Aconfiglockcanberemovedonlybytheadministratorwhosetit.
Aconfiglockcanonlyberemovedbytheadministratorwhosetitorbyasuperuser.
WhichstatementbelowisTrue?
PAN-OSusesPAN-DBasthedefaultURLFilteringdatabase,butalsosupportsBrightCloud.
WithoutaWildFiresubscription,whichofthefollowingfilescanbesubmittedbytheFirewalltothehostedWildFirevirtualizedsandbox?
PEfilesonly
Attackerswillemployanumberoftacticstohidemalware.Onesuchtacticistoencodeand/orcompressthefilesoastohidethemalware.WithPAN-OS7.0thefirewallcandecodeuptofourlevels.Butifanattackerhasencodedthefilebeyondfourlevels,whatcanyouasanadministerdotoprotectyourusers?
CreateaDecryptionPolicyformulti-levelencodedfilesandsettheactiontoblock.
CreateaFileBlockingProfileformulti-levelencodedfileswiththeactionsettoblock.
CreateaDecryptionProfileformulti-levelencodedfilesandapplyittoaDecryptionPolicy.
AsofPAN-OS7.0,whenconfiguringaDecryptionPolicyRule,whichofthefollowingisNOTanavailableoptionasmatchingcriteriaintherule?
Application
SourceUser
SourceZone
AftertheinstallationoftheThreatPreventionlicense,thefirewallmustberebooted.
True
False
AninterfaceinVirtualWiremodemustbeassignedanIPaddress.
True
False
Canmultipleadministratoraccountsbeconfiguredonasinglefirewall?
Yes
No
HowdoyoureducetheamountofinformationrecordedintheURLContentFilteringLogs?
Enable"Logcontainerpageonly".
DisableURLpacketcaptures.
EnableURLlogcaching.
EnableDSRI.
InPAN-OS6.0andlater,rulenumbersare:
Numbersthatspecifytheorderinwhichsecuritypoliciesareevaluated.
Numberscreatedtobeuniqueidentifiersineachfirewall’spolicydatabase.
Numberscreatedtomakeiteasierforuserstodiscussacomplicatedordifficultsequenceofrules.
Takingintoaccountonlytheinformationinthescreenshotabove,answerthefollowingquestion.Anadministratorispingingandfailstoreceivearesponse.Whatisthemostlikelyreasonforthelackofresponse?
Theinterfaceisdown.
ThereisnoManagementProfile.
Thereisnoroutebacktothemachineoriginatingtheping.
Takingintoaccountonlytheinformationinthescreenshotabove,answerthefollowingquestion.Whichapplicationswillbeallowedontheirstandardports?(Selectallcorrectanswers.)
Gnutella
BitTorrent
SSH
Skype
Thefollowingcanbeconfiguredasanexthopinastaticroute:
APolicy-BasedForwardingRule
VirtualSystems
VirtualSwitch
VirtualRouter
Thescreenshotaboveshowspartofafirewall’sconfiguration.Ifpingtrafficcantraversethisdevicefrome1/2toe1/1,whichofthefollowingstatementsmustbeTrueaboutthisfirewall’sconfiguration?(Selectallcorrectanswers.)
TheremustbeasecuritypolicyrulefromInternetzonetotrustzonethatallowsping.
Theremustbeappropriateroutesinthedefaultvirtualrouter.
TheremustbeasecuritypolicyrulefromtrustzonetoInternetzonethatallowsping.
TheremustbeaManagementProfilethatallowsping.(ThenassignthatManagementProfiletoe1/1ande1/2.)
WhenDestinationNetworkAddressTranslationisbeingperformed,thedestinationinthecorrespondingSecurityPolicyRuleshoulduse:
ThePre-NATdestinationzoneandPre-NATIPaddresses.
ThePost-NATdestinationzoneandPost-NATIPaddresses.
ThePost-NATdestinationzoneandPre-NATIPaddresses.
ThePre-NATdestinationzoneandPost-NATIPaddresses.
WhichofthefollowingcanprovideinformationtoaPaloAltoNetworksfirewallforthepurposesofUser-ID?(Selectallcorrectanswers.)
NetworkAccessControl(NAC)device
DomainController
RIPv2
SSLCertificates
PaloAltoNetworksoffersWildFireusersthreesolutiontypes.ThesesolutiontypesaretheWildFirePublicCloud,TheWF-500PrivateAppliance,andtheWildFireHybridsolution.WhatisthemainreasonandpurposefortheWildFireHybridsolution?
TheWildFireHybridsolutionenablescompaniestosendtotheWF-500PrivateAppliancekeepingtheminternaltotheirnetwork,aswellprovidingtheoptiontosendother,generalfilestotheWildFirePublicCloudforanalysis.
TheWildFireHybridsolutionplacesWF-500satmultipleplacesinthecloud,sothatfirewallappliancesdistributedthroughoutanenterprise'snetworkreceiveWildFireverdictswithminimallatencywhileretainingdataprivacy.
TheWildFireHybridsolutionenablesoutsidecompaniestosharethesameWF-500AppliancewhileatthesametimeallowingthemtosendonlytheirprivatefilestotheprivateWF-500.
TheWildFireHybridsolutionisonlyofferedtocompaniesthathavesensitivefilestoprotectanddoesnotrequireaWildFiresubscription.
InwhichofthefollowingcanUser-IDbeusedtoprovideamatchcondition?(Selectallcorrectanswers.)
SecurityPolicies
NATPolicies
ZoneProtectionPolicies
ThreatProfiles
AnenterprisePKIsystemisrequiredtodeploySSLForwardProxydecryptioncapabilities.
True
False
Aninterfaceintapmodecantransmitpacketsonthewire.
True
False
WhichofthefollowingCANNOTusethesourceuserasamatchcriterion?
Anti-virusProfile
Securitypolicyrulesspecifyasourceinterfaceandadestinationinterface.
True
False
The"Drive-ByDownload"protectionfeature,underFileBlockingprofilesinContent-ID,provides:
Protectionagainstunwanteddownloadsbyshowingtheuseraresponsepageindicatingthatafileisgoingtobedownloaded.
User-IDisenabledintheconfigurationof…
AnInterface.
AZone.
ASecurityPolicy.
Whichofthefollowingfactsaboutdynamicupdatesiscorrect?
ThreatandURLFilteringupdatesarereleaseddaily.ApplicationandAnti-virusupdatesarereleasedweekly.
Anti-virusupdatesarereleaseddaily.ApplicationandThreatupdatesarereleasedweekly.
WhichofthefollowinginterfacetypescanhaveanIPaddressassignedtoit?
Layer3
Layer2
Tap
WhichofthefollowingwouldbeareasontousethePAN-OSXMLAPItocommunicatewithaPaloAltoNetworksfirewall?
TopullinformationfromothernetworkresourcesforUser-ID.
YoucanassignanIPaddresstoaninterfaceinVirtualWiremode.
True
False
InPAN-OS7.0whichoftheavailablechoicesservesasanalertwarningbydefiningpatternsofsuspicioustrafficandnetworkanomaliesthatmayindicateahosthasbeencompromised?
CorrelationObjects
CorrelationEvents
CustomSignatures
PrevioustoPAN-OS7.0thefirewallwasabletodecodeuptotwolevels.WithPAN-OS7.0thefirewallcannowdecodeuptohowmanylevels?
Four
Three
Color-codedtagscanbeusedonalloftheitemslistedbelowEXCEPT:
VulnerabilityProfiles
ServiceGroups
AddressObjects
InPaloAltoNetworksterms,anapplicationis:
Aspecificprogramdetectedwithinanidentifiedstreamthatcanbedetected,monitored,and/orblocked.
Acombinationofportandprotocolthatcanbedetected,monitored,and/orblocked.
Afileinstalledonalocalmachinethatcanbedetected,monitored,and/orblocked.
Web-basedtrafficfromaspecificIPaddressthatcanbedetected,monitored,and/orblocked.
WhichofthefollowingplatformssupportstheDecryptionPortMirrorfunction?
PA-3000
VM-Series100
PA-2000
PA-4000
UsingtheAPIinPAN-OS6.1,WildFiresubscriberscanuploaduptohowmanysamplesperday?
10
500
1000
50
AlloftheinterfacesonaPaloAltoNetworksdevicemustbeofthesameinterfacetype.
True
False
Whatisthedefaultsettingfor'Action'inaDecryptionPolicy'srule?
No-Decrypt
None
Decrypt
WhenconfiguringAdminRolesforWebUIaccess,whataretheavailableaccesslevels?
AllowandDenyonly
Enable,Read-Only,andDisable
EnableandDisableonly
WhichofthefollowingaremethodsthatHAclustersusetoidentifynetworkoutages?
PathandLinkMonitoring
LinkandSessionMonitors
WhichofthefollowingisTrueofanapplicationfilter?
Anapplicationfilterautomaticallyincludesanewapplicationwhenoneofthenewapplication’scharacteristicsareincludedinthefilter.
AnapplicationfilterautomaticallyadaptswhenanapplicationmovesfromoneIPaddresstoanother.
Anapplicationfilterspecifiestheusersallowedtoaccessanapplication.
Whichpre-definedAdminRolehasallrightsexcepttherightstocreateadministrativeaccountsandvirtualsystems?
DeviceAdministrator
vsysadmin
WhenyouhavecreatedaSecurityPolicyRulethatallowsFacebook,whatmustyoudotoblockallotherweb-browsingtraffic?
EnsurethattheServicecolumnisdefinedas"application-default"forthisSecuritypolicy.Doingthiswillautomaticallyincludetheimplicitweb-browsingapplicationdependency.
Nothing.YoucandependonPAN-OStoblocktheweb-browsingtrafficthatisnotneededforFacebookuse.
Whencreatingthepolicy,ensurethatweb-browsingisincludedinthesamerule.
AsthePaloAltoNetworksAdministratorresponsibleforUser-ID,youneedtoenablemappingofnetworkusersthatdonotsign-inusin
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2024年简化版居家养老照护合同
- 2024甲方委托乙方可再生能源项目的建设与运营合同
- 2024年重点中学校长任用合同范本3篇
- 2025年度家禽养殖废弃物处理设施运营管理买卖合同书3篇
- 2025年度财务会计软件定制开发与授权使用合同3篇
- 2024年度商铺租赁合同提前解除及清退协议3篇
- 2025年70米烟囱拆除工程风险评估与安全防护设计合同3篇
- 2024年经销商双方合作协议版B版
- 2024年项目管理服务协议:工程监理与咨询服务
- 2024年财务风险评估与管理合同
- 人民日报出版社有限责任公司招聘笔试题库2024
- 《船舶建造安全监理技术规范》(征求意见稿)
- 燃烧仿真.燃烧数值模拟方法:化学反应动力学模型:燃烧仿真前沿技术与研究
- 线性代数考试练习题带答案大全(二)
- 排水管网溯源排查项目专项培训
- 重症超声与休克-课件
- 电梯工程师在电梯设计中的工作内容
- 二年级数学上册口算天天练
- 2024国家开放大学电大本科《液压气动技术》期末试题及答案
- GB/T 30306-2024家用和类似用途饮用水处理滤芯
- 08D800-5 民用建筑电气设计与施工 常用电气设备安装与控制
评论
0/150
提交评论