Question: 1

Which authentication method can provide role-based administrative access to firewalls running PAN-OS?

B. Certificate-based authentication
C. Kerberos
D. RADIUS with Vendor Specific Attributes

Answer: D

Question: 2

Assuming that the default antivirus profile is installed, match each decoder with its default action.
Answer options may be used more than once or not at all.


FTP, SMB – Block HTTP – Block POP3, SMTP – Alert IMAP – Alert

Question: 3
Which three engines are built into the Single-Pass Parallel Processing Architecture? Choose 3 answers

A. Application Identification (App-ID)
B. Group Identification (Group-ID)
C. User Identification (User-ID)
D. Threat Identification (Threat-ID)
E. Content Identification (Content-ID)

Answer: A,C,E

Reference: page 5

Question: 4

Within a Zone Protection Profile, under the Reconnaissance Protection tab, there are several possible values for Action:

Match each Reconnaissance Protection Action to its description. Answer options may be used more than once or not at all.


Allow: Permits the port scan attempts. Alert: Generates an alert for each scan that matches the threshold within the specified time interval. Block: Drops all traffic from the source to the destination. Block IP: Drops all traffic for a specific period of time (in seconds). There are two options:
Source: Blocks traffic from the source
Source-and-Destination: Blocks traffic for the source-destination pair

Question: 5
What is a prerequisite for configuring a pair of Palo Alto Networks firewalls in an Active/Passive High Availability (HA) pair?

A. The peer HA1 IP address must be the same on both firewalls.
B. The management interfaces must be on the same network.
C. The firewalls must have the same set of licenses.
D. The HA interfaces must be directly connected to each other.

Answer: C

Reference: page 134


