Question 1 of 25
Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
Show answer
How others answered
- C100%
Practice workspace
Try 25 supported questions from the 107-question bank. Check each answer when you are ready and keep this preview’s progress privately in your browser.
Free preview
This sample includes answers, available explanations, official references and curated community discussion. An Exam Pass unlocks the private complete bank for this exam.
Answer support
Unexplained marked answers are community claims, not independently verified teaching. Check uncertain or contested items against the official sources below.
25 questions in this bank
Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
How others answered
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers. Resources exist on AWS and Azure: The AWS deployment is architected with AWS Transit Gateway, to which all resources connect The Azure deployment is architected with each application independently routing traffic The engineer deploying Cloud NGFW in these two cloud environments must account for the following: Minimize changes to the two cloud environments Scale to the demands of the applications while using the least amount of compute resources Allow the company to unify the Security policies across all protected areas Which two implementations will meet these requirements? (Choose two.)
How others answered
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)
How others answered
Only 52% agreed on this answer — treat it as contested rather than settled.
During an upgrade to the routing infrastructure in a customer environment, the network administrator wants to implement Advanced Routing Engine (ARE) on a Palo Alto Networks firewall. Which firewall models support this configuration?
How others answered
Only 45% agreed on this answer — treat it as contested rather than settled.
By default, which type of traffic is configured by service route configuration to use the management interface?
How others answered
In regard to the Advanced Routing Engine (ARE), what must be enabled first when configuring a logical router on a PAN-OS firewall?
How others answered
Which two zone types are valid when configuring a new security zone? (Choose two.)
How others answered
An organization has configured GlobalProtect in a hybrid authentication model using both certificate-based authentication for the pre-logon stage and SAML-based multi-factor authentication (MFA) for user logon. How does the GlobalProtect agent process the authentication flow on Windows endpoints?
How others answered
An NGFW engineer is configuring multiple Layer 2 interfaces on a Palo Alto Networks firewall, and all interfaces must be assigned to the same VLAN. During initial testing, it is reported that clients located behind the various interfaces cannot communicate with each other. Which action taken by the engineer will resolve this issue?
How others answered
An NGFW engineer is configuring multiple Panorama-managed firewalls to start sending all logs to Strata Logging Service. The Strata Logging Service instance has been provisioned, the required device certificates have been installed, and Panorama and the firewalls have been successfully onboarded to Strata Logging Service. Which configuration task must be performed to start sending the logs to Strata Logging Service and continue forwarding them to the Panorama log collectors as well?
How others answered
In a Palo Alto Networks environment, GlobalProtect has been enabled using certificate-based authentication for both users and devices. To ensure proper validation of certificates, one or more certificate profiles are configured. What function do certificate profiles serve in this context?
How others answered
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
How others answered
Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?
How others answered
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish. Which of the following actions will resolve this issue?
How others answered
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
How others answered
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
How others answered
For which two purposes is an IP address configured on a tunnel interface? (Choose two.)
How others answered
Which PAN-OS method of mapping users to IP addresses is the most reliable?
How others answered
In an active/active high availability (HA) configuration with two PA-Series firewalls, how do the firewalls use the HA3 interface?
How others answered
A PA-Series firewall with all licensable features is being installed. The customer’s Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions. Which action meets the requirements in this scenario?
How others answered
Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?
How others answered
Which networking technology can be configured on Layer 3 interfaces but not on Layer 2 interfaces?
How others answered
What must be configured before a firewall administrator can define policy rules based on users and groups?
How others answered
Only 52% agreed on this answer — treat it as contested rather than settled.
What is a result of enabling split tunneling in the GlobalProtect portal configuration with the “Both Network Traffic and DNS” option?
How others answered
According to dynamic updates best practices, what is the recommended threshold value for content updates in a mission- critical network?
How others answered
Keyboard:J Kmove between questionsA–Dselect an answerRshow or hide the answer← →change page
NGFW-ENGINEER practice, question 1 of 25
Compiled from exam discussions posted publicly by other people on ExamTopics. Copyright in each contribution rests with its original author; it is reproduced here for study. Not verified by us — most items carry no explanation. To request removal, see our content policy.
Compiled from ExamTopics community discussions
Compiled from publicly posted community exam discussions. Contributed by third parties rather than written here, so accuracy varies and most items carry no explanation.
Across the private full bank: 0 explanations, 107 questions with candidate context and 0 questions with direct citations.
Version 1.0.0 · bank updated . How we source questions