Question 6

An organization runs multiple Kubernetes clusters both on-premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within each cluster, maintain consistent Security policies across all environments, and dynamically scale as containerized workloads spin up or down. They also plan to use a centralized Panorama instance for policy management and visibility.
Which approach meets these requirements?
  • Question 7

    An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The requirement is to route DNS queries for "https://www.google.com/search?q=corp.internal.com" to the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's locally configured DNS.
    What is the effect of configuring this split DNS policy?
  • Question 8

    A Palo Alto Networks firewall has the following interfaces configured:
    - ethernet1/1 (Layer 3)
    - ethernet1/2 (TAP)
    - ethernet1/3 (Layer 2)
    - ethernet1/4 (virtual wire)
    An administrator needs to create a link group to monitor upstream connectivity for high availability (HA) failover.
    Which set of interfaces can be added to the link group?
  • Question 9

    Which statement describes the role of Terraform in deploying Palo Alto Networks NGFWs?
  • Question 10

    A network engineer observes a pattern of anomalous traffic hitting an external-facing zone, including a high volume of TCP packets that are not part of a new session handshake (non-SYN), and a large number of ICMP fragments. The engineer decides to apply a Zone Protection profile to mitigate these potential threats.
    Which protection type within the profile must be configured?