[Free] Download New Updated (February 2016) Palo Alto Networks ACE Practice Tests 41-50

Ensurepass

QUESTION 41

A “Continue” action can be configured on the following Security Profiles:

 

A.

URL Filtering, File Blocking, and Data Filtering

B.

URL Filteringn

C.

URL Filtering and Antivirus

D.

URL Filtering and File Blocking

 

Correct Answer: D

 

 

QUESTION 42

What are the benefits gained when the “Enable Passive DNS Monitoring” checkbox is ch
osen on the firewall? (Select all correct answers.)

 

A.

Improved DNSbased C&C signatures.

B.

Improved PANDB malware detection.

C.

Improved BrightCloud malware detection.

D.

Improved malware detection in WildFire.

 

Correct Answer: ABD

 

 

QUESTION 43

To properly configure DOS protection to limit the number of sessions individually from specific source IPs you would configure a DOS Protection rule with the following characteristics:

 

A.

Action: Protect, Classified Profile with “Resources Protection” configured, and Classified Address with “source-ip-only” configured

B.

Action: Deny, Aggregate Profile with “Resources Protection” configured

C.

Action: Protect, Aggregate Profile with “Resources Protection” configured

D.

Action: Deny, Classified Profile with “Resources Protection” configured, and Classified Address with “source-ip-only” configured

 

Correct Answer: A

 

 

QUESTION 44

When employing the BrightCloud URL filtering database in a Palo Alto Networks firewall, the order of evaluation within a profile is:

 

A.

Block list, Custom Categories, Predefined categories, Dynamic URL filtering, Allow list, Cache files.

B.

Block list, Allow list, Custom Categories, Cache files, Local URL DB file.

C.

Block list, Custom Categories, Cache files, Predefined categories, Dynamic URL filtering, Allow list.

D.

Dynamic URL filtering, Block list, Allow list, Cache files, Custom categories, Predefined categories.

 

Correct Answer: A

QUESTION 45

When employing the Brightcloud URL filtering database on the Palo Alto Networks firewalls, the order of checking within a profile is:

 

A.

Block List, Allow List, Custom Categories, Cache Files, Predefined Categories, Dynamic URL Filtering

B.

Block List, Allow List, Cache Files, Custom Categories, Predefined Categories, Dynamic URL Filtering

C.

Dynamic URL Filtering, Block List, Allow List, Cache Files, Custom Categories, Predefined Categories

D.

None of the above

 

Correct Answer: A

 

 

QUESTION 46

What built-in administrator role allows all rights except for the creation of administrative accounts and virtual systems?

 

A.

superuser

B.

vsysadmin

C.

A custom role is required for this level of access

D.

deviceadmin

 

Correct Answer: D

 

 

QUESTION 47

When creating an application filter, which of the following is true?

 

A.

They are used by malware

B.

Excessive bandwidth may be used as a filter match criteria

C.

They are called dynamic because they automatically adapt to new IP addresses

D.

They are called dynamic because they will automatically include new applications from an application signature update if the new application’s type is included in the filter

 

Correct Answer: D

 

 

QUESTION 48

When setting up GlobalProtect, what is the job of the GlobalProtect Portal? Select the best answer

 

A.

To maintain the list of remote GlobalProtect Portals and list of categories for checking the client machine

B.

To maintain the list of GlobalProtect Gateways and list of categories for checking the client machine

C.

To load balance GlobalProtect client connections to GlobalProtect Gateways

D.

None of the above

 

Correct Answer: B

 

 

QUESTION 49

In PANOS 6.0, rule numbers are:

 

A.

Numbers that specify the order in which security policies are evaluated.

B.

Numbers created to be unique identifiers in each firewall’s policy database.

C.

Numbers on a scale of 0 to 99 that specify priorities when two or more rules are in conflict.

D.

Numbers created to make it easier for users to discuss a complicated or difficult sequence of rules.

 

Correct Answer: A

 

 

QUESTION 50

In PAN-OS 5.0, how is Wildfire enabled?

 

A.

Via the URL-Filtering “Continue” Action

B.

Wildfire is automaticaly enabled with a valid URL-Filtering license

C.

A custom file blocking action must be enabled for all PDF and PE type files

D.

Via the “Forward” and “Continue and Forward” File-Blocking actions

 

Correct Answer: A

 

Free VCE & PDF File for Palo Alto Networks ACE Real Exam

Instant Access to Free VCE Files: CompTIA | VMware | SAP …
Instant Access to Free PDF Files: CompTIA | VMware | SAP …

This entry was posted in ACE Practice Tests (February 2016) and tagged , , , , , , , . Bookmark the permalink.