Palo Alto Networks NGFW-Engineer - Palo Alto Networks Certified Next-Generation Firewall Engineer Exam
Page: 3 / 25
Total 121 questions
Question #11 (Topic: Exam A)
In a Palo Alto Networks environment, GlobalProtect has been enabled using certificate-based authentication for both users and devices. To ensure proper validation of certificates, one or more certificate profiles are configured.
What function do certificate profiles serve in this context?
What function do certificate profiles serve in this context?
A. They store private keys for users and devices, effectively allowing the firewall to issue or reissue certificates if the primary Certificate Authority (CA) becomes unavailable, providing a built-in fallback CA to maintain continuous certificate issuance and authentication.
B. They define trust anchors (root / intermediate Certificate Authorities (CAs)), specify revocation checks (CRL/OCSP), and map certificate attributes (e.g., CN) for user or device authentication.
C. They allow the firewall to bypass certificate validation entirely, focusing only on username / password-based authentication.
D. They provide a one-click mechanism to distribute certificates to all endpoints without relying on external enrollment methods.
Answer: B
Question #12 (Topic: Exam A)
How does a Palo Alto Networks NGFW respond when the preemptive hold time is set to 0 minutes during configuration of route monitoring?
A. It does not accept the configuration.
B. It accepts the configuration but throws a warning message.
C. It removes the static route because 0 is a NULL value.
D. It reinstalls the route into the routing information base (RIB) as soon as the path comes up.
Answer: D
Question #13 (Topic: Exam A)
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish.
Which of the following actions will resolve this issue?
Which of the following actions will resolve this issue?
A. Ensure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel interface.
B. Configure the Proxy IDs to match the Cisco ASA configuration.
C. Check that IPSec is enabled in the management profile on the external interface.
D. Validate the tunnel interface VLAN against the peer’s configuration.
Answer: B
Question #14 (Topic: Exam A)
Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?
A. Set Transmission Rate to “fast.”
B. Set passive link state to “Auto.”
C. Set “Enable in HA Passive State.”
D. Set LACP mode to “Active.”
Answer: C
Question #15 (Topic: Exam A)
When integrating Kubernetes with Palo Alto Networks NGFWs, what is used to secure traffic between microservices?
A. Service graph
B. Ansible automation modules
C. Panorama role-based access control (RBAC)
D. CN-Series firewalls
Answer: D