Question 81

An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy.
Which approach ensures continuous, secure connectivity and consistent policy enforcement?
  • Question 82

    An administrator is configuring a site-to-site IPSec VPN and assigns an IP address to the tunnel interface.
    Which two abilities are enabled by this specific configuration step? (Choose two.)
  • Question 83

    An enterprise uses GlobalProtect with both user- and machine-based certificate authentication and requires pre-logon, OCSP checks, and minimal user disruption. They manage multiple firewalls via Panorama and deploy domain-issued machine certificates via Group Policy.
    Which approach ensures continuous, secure connectivity and consistent policy enforcement?
  • Question 84

    An administrator is designing a public key infrastructure (PKI) integration for a large-scale deployment with thousands of users authenticating via client certificates. A key design goal is to ensure that certificate revocation status is checked efficiently with minimal impact on firewall performance and minimal delay for the connecting user.
    What is the primary advantage of using the Online Certificate Status Protocol (OCSP) instead of certificate revocation lists (CRLs) in this scenario?
  • Question 85

    An administrator needs to ensure that a firewall can download threat prevention and software updates, but the management port is on an isolated network without internet access.
    Which service must be rerouted through a data plane interface using a service route to allow the firewall to download these updates?