Question 41

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and- control (C2) servers.
Which Security Profile type will prevent these behaviors?
  • Question 42

    A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port
    443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server hosts its contents over HTTP(S). Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule.
    Which combination of service and application, and order of Security policy rules, needs to be configured to allow cleartext web-browsing traffic to this server on tcp/443?
  • Question 43

    What is a key step in implementing WildFire best practices?
  • Question 44

    What are three possible verdicts that WildFire can provide for an analyzed sample? (Choose three)
  • Question 45

    Only two Trust to Untrust allow rules have been created in the Security policy
    - Rule1 allows google-base
    - Rule2 allows youtube-base
    The youtube-base App-ID depends on google-base to function. The google-base App-ID implicitly uses SSL and web-browsing. When user try to accesss https://www.youtube.com in a web browser, they get an error indecating that the server cannot be found.
    Which action will allow youtube.com display in the browser correctly?