Which element of a network’s current health is provided by the Strata Cloud Manager (SCM) Device Health dashboard?
AHealth trends based on which CVEs are not remediated.
BHealth score based on current physical hardware issues detected.
CHealth score based on security profile feature adoption.
DHealth trends for firewalls filtered by how long the issue has been experienced.
A Palo Alto Networks NGFW is being configured for a high-security environment and requires a security profile group that includes vulnerability protection.
When configuring the action according to the severity of the threat types, what does Palo Alto Networks recommend?
AUse action "allow" for critical high, and medium vulnerabilities.
BUse action "alert" for critical, high, and medium vulnerabilities.
CUse action "default" for critical, high, and medium vulnerabilities.
DUse action "reset-both" for critical, high, and medium vulnerabilities.
A NAT policy is configured to permit internet access to an internal server, but the traffic does not match the Security policy intended to allow that access.
The current Security policy configuration is:
Source Zone: Pre-NAT Zone
Source Address: Any
Destination Zone: Post-NATZone
Destination Address: Post-NAT Address
Which configuration element must be corrected to resolve the issue?
ADestination Zone should be the Pre-NAT Zone.
BSource Address should be the original client IP address.
CDestination Address should be the Pre-NAT Address.
DSource Zone should be the Post-NAT Zone.
Apart from operating as a SaaS-based delivery platform, what advantage does Strata Cloud Manager (SCM) have over Panorama?
ALive, inline best practice checks
BNGFW and Prisma Access management
CCustomizable dashboards
DReal-time alerting
QuestionQ6
Management and Operations
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Management and Operations
QuestionQ8
Object Configuration Creation and Application
QuestionQ9
Troubleshooting
QuestionQ10
Troubleshooting
QuestionQ11
Policy Creation and Application
QuestionQ12
Troubleshooting
QuestionQ13
Policy Creation and Application
QuestionQ14
Troubleshooting
QuestionQ15
Object Configuration Creation and Application
QuestionQ16
Troubleshooting
QuestionQ17
Troubleshooting
QuestionQ18
Troubleshooting
QuestionQ19
Object Configuration Creation and Application
QuestionQ20
Management and Operations
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which CLI command provides an overview of the CPU resources used by the data plane of a Palo Alto Networks firewall?
Ashow system state
Bshow system resources
Cshow running resource-monitor
Dshow running statistics
A security manager requests automated guidance for several OS security advisories issued by Palo Alto Networks.
Which actions can be performed in Strata Cloud Manager (SCM) to address this request?
AInsights → Activity Insights → Threats, add a filter for threat category, review the logs, generate a weekly report.
BDashboard → PAN-OS CVEs, select the CVEs to review, generate upgrade recommendations.
CInsights → Application Experience → Application Domains, add a filter for usage source, generate a weekly report.
DDashboard → Security Posture Insights, set time range to past 90 days, look at regressing scores in particular, generate a weekly report.
What is the most granular way to ensure that traffic sent to a firewall’s public IP address on its public interface is translated to the web server’s private IP address?
ACreate one NAT policy, ensure the policy has original packet destination IP as the public IP address and translated packet destination IP as the private IP address, and mark Bi-directional as "Yes."
BCreate one NAT policy, set the source address to the public IP address and destination address to the private IP address, and ensure Bi-directional is checked.
CCreate two static NAT policies, ensure one policy has original packet destination IP as the public IP address and translated packet destination IP as the private IP address, ensure the other policy has original packet source IP as the private IP address and the translated packet source IP as the public IP address.
DCreate one NAT policy, ensure the policy has original packet source IP as the private IP address and the translated packet source IP as the public IP address, and mark Bi-directional as "Yes."
Two distinct IP addresses are flooding a company website with SYN-flood packets, resulting in slow performance.
What is the most efficient way to use DoS Protection profiles to mitigate this attack while minimizing disruption to legitimate traffic?
AApply a classified DoS Protection profile to limit the number of SYN packets from the identified IP addresses. Set the action to SYN Cookies.
BApply an aggregate DoS Protection profile to limit the number of SYN packets from the identified IP addresses. Set the action to SYN Cookies.
CApply a classified DoS Protection profile to limit the number of SYN packets from the identified IP addresses Set the action to Random Early Drop.
DApply an aggregate DoS Protection profile to limit the number of SYN packets from the identified IP addresses. Set the action to Random Early Drop.
Which action prevents a Panorama push from failing because of pending local firewall changes?
ACommit configurations locally on the device and then repeat the same configuration from Panorama.
BDisable "Merge with Device Candidate Config."
CEnable "Force Template Values."
DEnable both options "Include Device and Network Templates" and "Include Firewall Clusters."
A financial company is deploying NGFWs with the Advanced SD-WAN subscription to improve availability and bandwidth across thousands of ATMs. The company requires traffic to the internal application required by the ATMs to always use the path with the lowest latency and packet loss.
Which unique SD-WAN rule parameters satisfy these criteria?
AApplication/Service: "Internal Application for ATMs" → Path Selection: "Best Available Path" in Traffic Distribution Profile.
BApplication/Service: "Internal Application for ATMs" & "Management" in Path Quality Profile → Path Selection "Any."
CApplication/Service: "Internal Application for ATMs" → Path Selection "Weighted Distribution" in Traffic Distribution Profile.
DApplication/Service: "Internal Application for ATMs" & "ATM Path(Custom)" in Path Quality Profile → Path Selection "Any."
In an environment that has SSL Forward Proxy decryption policies and applications using certificate pinning, which configuration step is necessary to prevent application failures caused by strict certificate validation?
AIncrease the key length of the SSL Forward Proxy certificate to enhance security.
BEnable SSL/TLS 1.3 to ensure compatibility with modern applications.
CUse a wildcard certificate to bypass certificate validation issues.
DCreate SSL decryption exclusions for applications that use certificate pinning.
A security administrator needs to determine the action that a URL Filtering profile will apply to the URL www.chatgpt.com. The firewall contains a custom URL object named Permitted-AI with www.chatgpt.com/ as a member. The URL www.chatgpt.com is also categorized as Artificial-Intelligence, Computer-and-Internet-Info, and Low-Risk.
The URL Filtering profile contains the following settings, in descending order:
Artificial-Intelligence set to continue
Computer-and-Internet-Info set to block
Low-Risk set to alert
Permitted-AI set to allow
Which action will the URL Filtering profile apply when traffic matches the www.chatgpt.com URL on a rule with this profile attached?
AContinue
BAlert
CAllow
DBlock
A firewall administrator who is applying Palo Alto Networks best practices on the company firewall reviews NGFW alerts in Strata Cloud Manager (SCM) and determines that one alert is not applicable to this environment.
If the administrator does not intend to resolve the underlying issue, what is the appropriate next step?
AClick "Copilot” in the top right, and ask the Copilot to make an exception for the NGFW alert.
BChange the NGFW alert priority to "Not Set."
CAssign the NGFW alert to the "Dismiss" user.
DOpen the NGFW alert and click "Suppress" under "Actions."
Which two pattern types are valid in a Data Filtering profile?
Choose two
ACustom Dictionary
BProximity Pattern
CFile Properties
DRegular Expression
An analyst observes latency on the firewall and wants to improve performance.
Which steps can be taken to reduce management-plane CPU while working to identify the underlying problem?
ADisable log at session start and only log at session end.
BEnable logging for intrazone-default and interzone-default security rules.
CDisable log at session end and only log at session start.
DEnable log forwarding from the firewall to an external destination.
An alert shows that several internal endpoints are communicating with a known malicious IP address, and the analyst must use Log Viewer to identify the scope of this activity.
What is the initial step to identify the internal hosts that communicated with the malicious IP address and determine the extent of that communication?
AFilter the traffic logs by the known endpoint IP addresses.
BFilter the traffic logs by the DNS Server's IP address.
CFilter the traffic logs by the NGFWs IP addresses.
DFilter the traffic logs by the malicious IP address.
A team of analysts works with four NGWFs using the Precision Al Bundle, SaaS Security Inline, and Strata Cloud Manager Pro. Together, these secure all company assets across the data center and two remote sites. A security incident requires the team to review a mobile user, John Doe.
During the audit, the team asks, “How was the application experience for John Doe over the past 60 days?”
What response is expected from Strata Copilot?
A"The average application test score for 'john doe’ over the past 60 days is 37 67."
BThe user ’John Doe' encountered a total of 219 threats in the last 3 hours."
CThe top three threats impacting John Doe are phishing, SQL injections, and ransomware."
D"Your organization doesn’t have ADEM."
DNS rewrite can be configured only on a NAT rule using which destination address translation type?
ADynamic IP and Port (DIPP)
BDynamic IP (with session distribution)
CStatic IP
DDynamic IP
What is the processing order when both Policy Based Forwarding (PBF) policies and routing-table entries apply?
AThe firewall evaluates the routing table that is using the longest prefix match and then applies any matching PBF rule to override the next-hop.
BThe firewall evaluates PBF policies first; if a packet matches a PBF rule, the specified next-hop in that rule overrides the routing table.
CThe firewall performs a simultaneous evaluation of both PBF policies and the routing table, and then it chooses the route with the lowest metric.
DThe firewall evaluates static routes, then dynamic routes, and then it applies PBF policies to adjust the next-hop.
Community Discussion