Question 61

An administrator is designing a public key infrastructure (PKI) integration for a large-scale deployment with thousands of users authenticating via client certificates. A key design goal is to ensure that certificate revocation status is checked efficiently with minimal impact on firewall performance and minimal delay for the connecting user.
What is the primary advantage of using the Online Certificate Status Protocol (OCSP) instead of certificate revocation lists (CRLs) in this scenario?
  • Question 62

    An organization is securing its cloud workloads using the Palo Alto Networks platform. The goal is to use a fully managed firewall service that integrates with Panorama for consistent policy management. The solution must be scalable and require minimal changes to the existing routing fabric.
    * The AWS cloud uses a distributed architecture where each application virtual private cloud (VPC) routes internet traffic through its own internet gateway.
    * The Azure cloud is built around a Virtual WAN (vWAN) hub for centralized connectivity.
    Which two deployments meet these criteria? (Choose two.)
  • Question 63

    In an enterprise network, security administrators want to control traffic based on application behavior rather than only using IP addresses and TCP/UDP ports.
    Which NGFW capability MOST directly enables this requirement?
  • Question 64

    A network administrator is configuring an Aggregate Ethernet (AE) interface on an active/passive high availability (HA) pair. To reduce network downtime during a failover, the administrator wants the passive firewall's AE interface to be fully negotiated with the switch before it becomes active.
    Which Link Aggregation Control Protocol (LACP) setting achieves this administrator's goal?
  • Question 65

    When configuring a physical interface on a Palo Alto Networks firewall, which IP-based service is only available if the interface is set to Layer 3 mode?