PaloAlto_ACE认证考试题库及答案2016-1月 下载本文

Device Administrator

A custom admin role must be created for this specific combination of rights. vsysadmin

Mark for follow up

Question 42 of 50.

When using Config Audit, the color yellow indicates which of the following? *

A setting has been changed between the two config files

A setting has been deleted from a config file. A setting has been added to a config file An invalid value has been used in a config file.

Mark for follow up

Question 43 of 50.

In which of the following can User-ID be used to provide a match condition? *

Security Policies

NAT Policies Zone

Policies

Protection

Threat Profiles

Mark for follow up

Question 44 of 50.

Using the API in PAN-OS 6.1, WildFire subscribers can upload up to how many samples per day? *

1000 50 10 500

Mark for follow up

Question 45 of 50.

When configuring a Security Policy Rule based on FQDN Address Objects, which of the following statements is True? *

The firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again at DNS TTL expiration.

The firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again each time Security Profiles are evaluated.

In order to create FQDN-based objects, you need to manually define a list of associated IP addresses.

Mark for follow up

Question 46 of 50.

In a Destination NAT configuration, the Translated Address field may be populated with either an IP address or an Address Object. True

Mark for follow up

Question 47 of 50.

An interface in tap mode can transmit packets on the wire. True

Mark for follow up

Question 48 of 50.

WildFire may be used for identifying which of the following types of traffic?

False

False

*

DHCP RIPv2 Malware OSPF

Mark for follow up

Question 49 of 50.

When an interface is in Tap mode and a Policy’s action is set to “block”, the interface will send a TCP reset. True

Mark for follow up

Question 50 of 50.

After the installation of the Threat Prevention license, the firewall must be rebooted. True

Mark for follow up

False

False