Questions and CORRECT Answers
Which elements of Autonomous Digital Experience Management (ADEM) help
provide end-to-end visibility of everything in an organization's environment?
a. Alerts, artifacts, and MITRE tactics
b. Scanning of all traffic, ports, and protocols
c. Data collected from endpoint devices, synthetic monitoring tests, and real-time traffic
d. Integrated threat intelligence management, automated distribution to enforcement ports
at scale, full packet mirroring - CORRECT ANSWER - c. Data collected from endpoint
devices, synthetic monitoring tests, and real-time traffic
Which type of access allows unmanaged endpoints to access secured on-premises
applications?
a. Secure web gateway (SWG)
b. Manual external gateway
c. Prisma Access Clientless VPN
d. GlobalProtect VPN for remote access - CORRECT ANSWER - c. Prisma Access
Clientless VPN
Which two point products are consolidated into the Prisma secure access service
edge (SASE) platform? (Choose two)
a. Threat intelligence Platform (TIP)
b. Firewall as a service (FWaaS)
c. Security information and event management (SIEM)
d. Autonomous Digital Experience Management (ADEM) - CORRECT ANSWER - b.
Firewall as a service (FWaaS)
d. Autonomous Digital Experience Management (ADEM)
,What is an advantage of next-generation SD-WAN over legacy SD-WAN solutions?
a. It provides the ability to push common configurations, configuration updates, and
schedule upgrades to all or a subset of the managed appliances
b. It enables detection of the privileges and responsibilities of administrative users in a
network
c. It allows configuration to forward logs to external logging destinations, such as syslog
servers
d. It steers traffic and defines networking and security policies from an application-centric
perspective, rather than a packet-based approach - CORRECT ANSWER - d. It steers
traffic and defines networking and security policies from an application-centric
perspective, rather than a packet-based approach
Which product allows advanced Layer 7 inspection, access control, threat detection
and prevention?
a. Infrastructure as a Service (IaaS)
b. Firewall as a Service (FWaaS)
c. Network sandbox
d. Remote browser isolation - CORRECT ANSWER - b. Firewall as a Service (FWaaS)
How does the Palo Alto Networks secure access service edge (SASE) solution
enables Zero Trust in a customer environment?
a. It feeds threat intelligence into an automation engine for rapid and consistent protections
b. It stops attacks that use DNS for command and control or data theft
c. It classifies rules based on content, features, and safety
d. It continuously validates every stage of a digital interaction - CORRECT ANSWER - d.
It continuously validates every stage of a digital interaction
What allows enforcement of policies based on business intent, enables dynamic path
selection, and provides visibility into performance and availability for applications and
, networks?
a. Firewall as a Service (FWaaS)
b. Identity Access Management (IAM) methods
c. Cloud Access Security Broker (CASB)
d. Instant-On Network (ION) devices - CORRECT ANSWER - d. Instant-On Network
(ION) devices
What are two benefits provided to an organization using a secure web gateway
(SWG)? (Choose two)
a. Security policies for making internet access safer are enforced
b. Access to inappropriate websites or content is blocked based on acceptable use policies
c. VPNs remain connected reducing user risk exposure
d. An encrypted challenge-response mechanism obtains user credentials from the browser -
CORRECT ANSWER - a. Security policies for making internet access safer are enforced
b. Access to inappropriate websites or content is blocked based on acceptable use policies
.What is a benefit of deploying secure access service edge (SASE) with a secure web gateway
(SWG) over a SASE solution without a SWG?
a. It creates tunnels that allow users and systems to connect securely over a public network as if
they were connecting over a local area network (LAN)
b. Protection is offered in the cloud through a unified platform for complete visibility and precise
control over web access while enforcing security policies that protect users from hostile websites
c. A heartbeat connection between the firewall peers ensures seamless failover in the event that a
peer goes down
d. It prepares the keys and certificates required for decryption, creating decryption profiles and
policies, and configuring decryption port mirroring - CORRECT ANSWER - b. Protection
is offered in the cloud through a unified platform for complete visibility and precise control over
web access while enforcing security policies that protect users from hostile websites
Which App Response Time metric measures the amount of time it takes to transfer
incoming data from an external server to a local client?