Question 86

An existing NGFW customer requires direct internet access offload locally at each site, and IPSec connectivity to all branches over public internet. One requirement is that no new SD-WAN hardware be introduced to the environment.
What is the best solution for the customer?
  • Question 87

    Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.
    Given the rule below, what change should be made to make sure the NAT works as expected?

  • Question 88

    An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.
    What is one way the administrator can meet this requirement?
  • Question 89

    Where can an administrator see both the management plane and data plane CPU utilization in the WebUI?
  • Question 90

    After configuring HA in Active/Passive mode on a pair of firewalls the administrator gets a failed commit with the following details.

    What are two explanations for this type of issue? (Choose two)