QuestionQ1
PAN-OS Networking ConfigurationIn an active/active high-availability (HA) deployment using two PA-Series firewalls, how is the HA3 interface used by the firewalls?
- A To forward packets to the HA peer during session setup and asymmetric traffic flow
- B To exchange hellos, heartbeats, HA state information, and management plane synchronization for routing and User-ID information
- C To synchronize sessions, forwarding tables, IPSec security associations, and ARP tables between firewalls in an HA pair
- D To perform session cache synchronization among all HA peers having the same cluster ID
QuestionQ2
PAN-OS Networking ConfigurationWhile upgrading routing infrastructure in a customer environment, a network administrator plans to implement the Advanced Routing Engine (ARE) on a Palo Alto Networks firewall.
Which firewall models support this configuration?
- A PA-5280, PA-7080, PA-3250, VM-Series
- B PA-455, VM-Series, PA-1410, PA-5450
- C PA-3260, PA-5410, PA-850, PA-460
- D PA-7050, PA-1420, VM-Series, CN-Series
Community Discussion
QuestionQ3
PAN-OS Networking ConfigurationAn organization is deploying VM-Series firewalls in Microsoft Azure to protect its VNets. A key requirement is for the security infrastructure to withstand the failure of an entire Azure Availability Zone.
What is the recommended approach to meet this objective?
- A Deploy multiple, independent VM-Series firewalls in different Availability Zones and use an Azure Load Balancer to distribute traffic to them.
- B Implement a Terraform configuration that automatically redeploys the firewall in a new zone if the original one fails.
- C Use Azure Traffic Manager to direct traffic to a primary VM-Series firewall, with a second firewall in another zone as a failover target.
- D Configure PAN-OS active/passive high availability (HA) between two VM-Series instances in separate Availability Zones using HA links over a VNet peering connection.
Community Discussion
QuestionQ4
PAN-OS Networking ConfigurationWhen configuring a Zone Protection profile, under which section (protection type) would an NGFW engineer set options to defend against activities such as spoofed IP addresses and split-handshake session-establishment attempts?
- A Flood Protection
- B Protocol Protection
- C Packet-Based Attack Protection
- D Reconnaissance Protection
Community Discussion
QuestionQ5
PAN-OS Networking ConfigurationWhich feature can be enabled on a Layer 3 interface but is unavailable on Layer 2 interfaces?
- A NetFlow profile
- B LLDP profile
- C QoS profile
- D DHCP client
Community Discussion