NO.1 Which authentication method can provide role-based administrative access to firewalls running
A. Kerberos
B. RADIUS with Vendor Specific Attributes
D. Certificate-based authentication
Answer: B

NO.2 Which two interface types provide support for network address translation (NAT)? Choose 2
A. Tap
B. Layer3
C. Virtual Wire
E. Layer2
Answer: B,C

NO.3 Two firewalls are configured in an Active/Passive High Availability (HA) pair with the following
election settings:
Firewall 5050-B is presently in the “Active” state and 5050-A is presently in the “Passive” state.
Firewall 5050-B reboots causing 5050-A to become Active.
Which firewall will be in the “Active” state after firewall 5050-B has completed its reboot and is back
A. Both firewalls are active (split brain)
B. Firewall 5050-A
C. Firewall 5050-B
D. It could be either firewall
Answer: C

NO.4 A company hosts a publicly-accessible web server behind their Palo Alto Networks firewall, with
this configuration information:
-Users outside the company are in the “Untrust-L3” zone.
-The web server physically resides in the “Trust-L3” zone.
-Web server public IP address:
-Web server private IP address:
Which NAT Policy rule will allow users outside the company to access the web server?
A. Option B
B. Option D
C. Option A
D. Option C
Answer: A

