A company plans to deploy identity for improved visibility and identity-based controls for least privilege access to applications and data. The company does not have an on-premises Active Directory (AD) deployment, and devices are connected and managed by using a combination of Entra ID and Jamf. Which two supported sources for identity are appropriate for this environment? (Choose two.)
Correct Answer: C,D
In this scenario, the company does not use on-premises Active Directory and manages devices with Entra ID and Jamf, which implies a cloud-native and modern management setup. Below is the evaluation of each option: * Option A: Captive portal * Captive portal is typically used in environments where identity mapping is needed for unmanaged devices or guest users. It provides a mechanism for users to authenticate themselves through a web interface. * However, in this case, the company is managing devices using Entra ID and Jamf, which means identity information can already be centralized through other means. Captive portal is not an ideal solution here. * This option is not appropriate. * Option B: User-ID agents configured for WMI client probing * WMI (Windows Management Instrumentation) client probing is a mechanism used to map IP addresses to usernames in a Windows environment. This approach is specific to on-premises Active Directory deployments and requires direct communication with Windows endpoints. * Since the company does not have an on-premises AD and is using Entra ID and Jamf, this method is not applicable. * This option is not appropriate. * Option C: GlobalProtect with an internal gateway deployment * GlobalProtect is Palo Alto Networks' VPN solution, which allows for secure remote access. It also supports identity-based mapping when deployed with internal gateways. * In this case, GlobalProtect with an internal gateway can serve as a mechanism to provide user and device visibility based on the managed devices connecting through the gateway. * This option is appropriate. * Option D: Cloud Identity Engine synchronized with Entra ID * The Cloud Identity Engine provides a cloud-based approach to synchronize identity information from identity providers like Entra ID (formerly Azure AD). * In a cloud-native environment with Entra ID and Jamf, the Cloud Identity Engine is a natural fit as it integrates seamlessly to provide identity visibility for applicationsand data. * This option is appropriate. References: * Palo Alto Networks documentation on Cloud Identity Engine * GlobalProtect configuration and use cases in Palo Alto Knowledge Base
Question 2
A prospective customer has provided specific requirements for an upcoming firewall purchase, including the need to process a minimum of 200,000 connections per second while maintaining at least 15 Gbps of throughput with App-ID and Threat Prevention enabled. What should a systems engineer do to determine the most suitable firewall for the customer?
Correct Answer: A
The prospective customer has provided precise performance requirements for their firewall purchase, and the systems engineer must recommend a suitable Palo Alto Networks Strata Hardware Firewall (e. g., PA-Series) model. The requirements include a minimum of 200,000 connections per second (CPS) and 15 Gbps of throughput with App-ID and Threat Prevention enabled. Let's evaluate the best approach to meet these needs. Step 1: Understand the Requirements * Connections per Second (CPS): 200,000 new sessions per second, indicating the firewall's ability to handle high transaction rates (e.g., web traffic, API calls). * Throughput with App-ID and Threat Prevention: 15 Gbps, measured with application identification and threat prevention features active, reflecting real-world NGFW performance. * Goal: Identify a PA-Series model that meets or exceeds these specs while considering the customer's actual traffic profile for optimal sizing.
Question 3
A prospective customer is interested in Palo Alto Networks NGFWs and wants to evaluate the ability to segregate its internal network into unique BGP environments. Which statement describes the ability of NGFWs to address this need?
Correct Answer: C
Step 1: Understand the Requirement and Context * Customer Need: Segregate the internal network into unique BGP environments, suggesting multiple isolated or semi-isolated routing domains within a single organization. * BGP Basics: * BGP is a routing protocol used to exchange routing information between autonomous systems (ASes). * eBGP: External BGP, used between different ASes. * iBGP: Internal BGP, used within a single AS, typically requiring a full mesh of peers unless mitigated by techniques like confederations or route reflectors. * Palo Alto NGFW: Supports BGP on virtual routers (VRs) within PAN-OS, enabling advanced routing capabilities for Strata hardware firewalls (e.g., PA-Series). * "PAN-OS supports BGP for dynamic routing and network segmentation" (docs.paloaltonetworks.com/pan-os /10-2/pan-os-networking-admin/bgp). Step 2: Evaluate Each Option Option A: It cannot be addressed because PAN-OS does not support it Analysis: PAN-OS fully supports BGP, including eBGP, iBGP, confederations, and route reflectors, configurable under "Network > Virtual Routers > BGP." Features like multiple virtual routers and BGP allow network segregation and routing policy control. This statement contradicts documented capabilities. Verification: "Configure BGP on a virtual router for dynamic routing" (docs.paloaltonetworks.com/pan-os/10-2/pan-os- networking-admin/bgp/configure-bgp). Conclusion: Incorrect-PAN-OS supports BGP and segregation techniques. Not Applicable. Option B: It can be addressed by creating multiple eBGP autonomous systems Analysis: eBGP: Used between distinct ASes, each with a unique AS number (e.g., AS 65001, AS 65002). Within a single organization, creating multiple eBGP ASes would require: Assigning unique AS numbers (public or private) to each internal segment. Treating each segment as a separate AS, peering externally with other segments via eBGP. Challenges: Internally, this isn't practical for a single network-it's more suited to external peering (e.g., with ISPs). Requires complex management and public/private AS number allocation, not ideal for internal segregation. Doesn't leverage iBGP or confederations, which are designed for internal AS management. PAN-OS supports eBGP, but this approach misaligns with the intent of internal network segregation. Verification: "eBGP peers connect different ASes" (docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/bgp /bgp-concepts). Conclusion: Possible but impractical and not the intended BGP solution for internal segregation. Not Optimal
Question 4
While a quote is being finalized for a customer that is purchasing multiple PA-5400 series firewalls, the customer specifies the need for protection against zero-day malware attacks. Which Cloud-Delivered Security Services (CDSS) subscription add-on license should be included in the quote?
Correct Answer: C
Zero-day malware attacks are sophisticated threats that exploit previously unknown vulnerabilities or malware signatures. To provide protection against such attacks, the appropriate Cloud-Delivered Security Service subscription must be included. * Why "Advanced WildFire" (Correct Answer C)?Advanced WildFire is Palo Alto Networks' sandboxing solution that identifies and prevents zero-day malware. It uses machine learning, dynamic analysis, and static analysis to detect unknown malware in real time. * Files and executables are analyzed in the cloud-based sandbox, and protections are shared globally within minutes. * Advanced WildFire specifically addresses zero-day threats by dynamically analyzing suspicious files and generating new signatures. * Why not "AI Access Security" (Option A)?AI Access Security is designed to secure SaaS applications by monitoring and enforcing data protection and compliance. While useful for SaaS security, it does not focus on detecting or preventing zero-day malware. * Why not "Advanced Threat Prevention" (Option B)?Advanced Threat Prevention (ATP) focuses on detecting zero-day exploits (e.g., SQL injection, buffer overflows) using inline deep learning but is not specifically designed to analyze and prevent zero-day malware. ATP complements Advanced WildFire, but WildFire is the primary solution for malware detection. * Why not "App-ID" (Option D)?App-ID identifies and controls applications on the network. While it improves visibility and security posture, it does not address zero-day malware detection or prevention. Reference: Palo Alto Networks Advanced WildFire documentation confirms its role in detecting and preventing zero-day malware through advanced analysis techniques.
Question 5
Which two statements clarify the functionality and purchase options for Palo Alto Networks AIOps for NGFW? (Choose two.)
Correct Answer: B,C
Palo Alto Networks AIOps for NGFW is a cloud-delivered service that leverages telemetry data and machine learning (ML) to provide proactive operational insights, best practice recommendations, and issue prevention. * Why "It is offered in two license tiers: a free version and a premium version" (Correct Answer B)?AIOps for NGFW is available in two tiers: * Free Tier: Provides basic operational insights and best practices at no additional cost. * Premium Tier: Offers advanced capabilities, such as AI-driven forecasts, proactive issue prevention, and enhanced ML-based recommendations. * Why "It uses telemetry data to forecast, preempt, or identify issues, and it uses machine learning (ML) to adjust and enhance the process" (Correct Answer C)?AIOps uses telemetry data from NGFWs to analyze operational trends, forecast potential problems, and recommend solutions before issues arise. ML continuously refines these insights by learning from real-world data, enhancing accuracy and effectiveness over time. * Why not "It is offered in two license tiers: a commercial edition and an enterprise edition" (Option A)?This is incorrect because the licensing model for AIOps is based on "free" and "premium" tiers, not "commercial" and "enterprise" editions. * Why not "It forwards log data to Advanced WildFire to anticipate, prevent, or identify issues, and it uses machine learning (ML) to refine and adapt to the process" (Option D)?AIOps does not rely on Advanced WildFire for its operation. Instead, it uses telemetry data directly from the NGFWs to perform operational and security analysis. Reference: Palo Alto Networks documentation for AIOps for NGFW confirms its functionality and licensing structure.