An engineer needs to configure administrator authentication using both TACACS+ and SAML simultaneously during a migration period.
Which configuration meets this requirement?
Show answer and explanation
Correct answer: B
PAN-NGFE Real Exam Questions
83 questions available · Page 1 of 9
Updated Exam DumpsVerified AnswersPass Guarantee
An engineer needs to configure administrator authentication using both TACACS+ and SAML simultaneously during a migration period.
Which configuration meets this requirement?
Correct answer: B
A firewall administrator wants to be able to see all NAT sessions that are going through a firewall with source NAT.
Which CLI command can the administrator use?
Correct answer: A
Which two actions must an engineer take to configure SSL Forward Proxy decryption? (Choose two.)
Correct answers: B, C
A PA-Series firewall with all licensable features is being installed. The customer's Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions.
Which action meets the requirements in this scenario?
Correct answer: D
An administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized.
What is the recommended upgrade process for minimal disruption in this high availability (HA) scenario?
Correct answer: A
An engineer configures multiple Layer 3 interfaces in the same subnet but cannot achieve communication between hosts.
What is the most likely reason?
Correct answer: B
Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?
Correct answer: C
A company is expanding its existing log storage and alerting solutions. All company Palo Alto Networks firewalls currently forward logs to Panorama.
Which two additional log forwarding methods will PAN-OS support? (Choose two.)
Correct answers: C, D
A firewall engineer creates a source NAT rule to allow the company's internal private network 10.0.0.0/23 to access the internet. However, for security reasons, one server in that subnet (10.0.0.10/32) should not be allowed to access the internet, and therefore should not be translated with the NAT rule.
Which set of steps should the engineer take to accomplish this objective?
Correct answer: C
An organization runs multiple Kubernetes clusters both on-premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within each cluster, maintain consistent Security policies across all environments, and dynamically scale as containerized workloads spin up or down. They also plan to use a centralized Panorama instance for policy management and visibility.
Which approach meets these requirements?
Correct answer: C