1
Palo Alto Firewalls Questions with Answers (100%
Correct Answers)
Which protocol used to exchange heartbeat between HA?— Answer:
ICMP
The Management Network Port on a Firewall can be Configured as
which type of Interface?— Answer: Layer 3
Why Paloalto is being called a next-generation firewall?— Answer:
Next-generation firewalls include enterprise firewall capabilities, an
intrusion prevention system (IPS), and application control features.
Palo Alto NGFW is different from other vendors in terms of Platform,
Process, and architecture.
Palo Alto Networks delivers all the next-generation firewall features
using the single platform, parallel processing, and single management
systems, unlike other vendors who use different modules or multiple
management systems to offer NGFW features.
In a New Firewall, which Port provides WebUI access by default?—
Answer: Management port
© 2025 All rights reserved
, 2
What are various TCP & UDP port numbers used in HA?— Answer:
HA1: TCP/28769, TCP/28260 for clear text communication, TCP/28 for
encrypted communication.
HA2: Use Protocol number 99 or UDP/29281
A Network Design Change Requires An Existing Firewall To Start
Accessing Palo Alto Updates From a Data-Plane Interface Address
Instead Of The Management Interface. Which Configuration Setting
needs To Be Modified?— Answer: Service route
What are the various links used to establish HA?— Answer: Control
Link
Data Link
Backup Links
Packet-Forwarding Link
What is DMZ (Demilitarized Zone)?— Answer: Servers that are
accessed by the Internet are usually located in a DMZ (demilitarized
zone). The DMZ makes sure that these servers cannot connect to the
internal network. Make sure that the Rule Base contains rules for DMZ
traffic. For example, these are rules for a web server in the DMZ
© 2025 All rights reserved
Palo Alto Firewalls Questions with Answers (100%
Correct Answers)
Which protocol used to exchange heartbeat between HA?— Answer:
ICMP
The Management Network Port on a Firewall can be Configured as
which type of Interface?— Answer: Layer 3
Why Paloalto is being called a next-generation firewall?— Answer:
Next-generation firewalls include enterprise firewall capabilities, an
intrusion prevention system (IPS), and application control features.
Palo Alto NGFW is different from other vendors in terms of Platform,
Process, and architecture.
Palo Alto Networks delivers all the next-generation firewall features
using the single platform, parallel processing, and single management
systems, unlike other vendors who use different modules or multiple
management systems to offer NGFW features.
In a New Firewall, which Port provides WebUI access by default?—
Answer: Management port
© 2025 All rights reserved
, 2
What are various TCP & UDP port numbers used in HA?— Answer:
HA1: TCP/28769, TCP/28260 for clear text communication, TCP/28 for
encrypted communication.
HA2: Use Protocol number 99 or UDP/29281
A Network Design Change Requires An Existing Firewall To Start
Accessing Palo Alto Updates From a Data-Plane Interface Address
Instead Of The Management Interface. Which Configuration Setting
needs To Be Modified?— Answer: Service route
What are the various links used to establish HA?— Answer: Control
Link
Data Link
Backup Links
Packet-Forwarding Link
What is DMZ (Demilitarized Zone)?— Answer: Servers that are
accessed by the Internet are usually located in a DMZ (demilitarized
zone). The DMZ makes sure that these servers cannot connect to the
internal network. Make sure that the Rule Base contains rules for DMZ
traffic. For example, these are rules for a web server in the DMZ
© 2025 All rights reserved