Question 71

A large enterprise wants to implement certificate-based authentication for both users and devices, using an on-premises Microsoft Active Directory Certificate Services (AD CS) hierarchy as the primary certificate authority (CA). The enterprise also requires Online Certificate Status Protocol (OCSP) checks to ensure efficient revocation status updates and reduce the overhead on its NGFWs. The environment includes multiple Active Directory forests, Panorama management for several geographically dispersed firewalls, GlobalProtect portals and gateways needing distinct certificate profiles for users and devices, and strict Security policies demanding frequent revocation checks with minimal latency.
Which approach best addresses these requirements while maintaining consistent policy enforcement?
  • Question 72

    A network administrator needs to replace the default self-signed certificate on a firewall with one signed by the company's internal certificate authority (CA).
    Which two firewall features would require this new certificate to be assigned via an SSL/TLS service profile?
    (Choose two.)
  • Question 73

    Which zone type allows traffic between zones in different virtual systems (VSYS), without the traffic leaving the firewall?
  • Question 74

    When considering the various methods for User-ID to learn user-to-IP address mappings, which source is considered the most accurate due to the mapping being explicitly created through an authentication event directly with the firewall?
  • Question 75

    An administrator must perform several actions on a fleet of firewalls from a central Panorama instance. To maintain efficiency, the administrator wants to only perform actions that do not require switching context into each firewall's individual web interface.
    Which set of actions is available to the administrator directly from the Panorama UI?