1
Palo Alto Questions with Answers (100% Correct
Answers)
An Antivirus Security Profile specifies Actions and WildFire Actions.
Wildfire Actions enable you to configure the firewall to perform which
operation?
A. Delete packet data when a virus is suspected.
B. Download new antivirus signatures from WildFire.
C. Block traffic when a WildFire virus signature is detected.
D. Upload traffic to WildFire when a virus is suspected.— Answer: D.
Upload traffic to WildFire when a virus is suspected.
An Interface Management Profile can be attached to which two
interface types? (Choose two.)
A. Tap
B. Layer 2
© 2025 All rights reserved
,2
C. Loopback
D. Layer 3
E. Virtual Wire— Answer: C. Loopback
D. Layer 3
App-ID running on a firewall identifies applications using which three
methods? (Choose three.)
A. PAN-DB lookups
B. WildFire lookups
C. Application signatures
D. Program heuristics
E. Known protocol decoders— Answer: C. Application signatures
D. Program heuristics
E. Known protocol decoders
Application block pages can be enabled for which applications?
© 2025 All rights reserved
,3
A. any
B. web-based
C. MGT port-based
D. non-TCP/IP— Answer: B. web-based
Because a firewall examines every packet in a session, a firewall can
detect application ________?
A. shifts
B. errors
C. groups
D. filters— Answer: A. shifts
Finding URLs matched to the not-resolved URL category in the URL
Filtering log file might indicate that you should take which action?
© 2025 All rights reserved
, 4
A.Reboot the firewall.
B. Validate your Security policy rules.
C. Validate connectivity to the PAN-DB cloud.
D. Re-download the URL seed database.— Answer: C. Validate
connectivity to the PAN-DB cloud.
For which firewall feature should you create forward trust and
forward untrust certificates?
A. SSH decryption
B. SSL forward proxy decryption
C. SSL client-side certificate checking
D. SSL Inbound Inspection decryption— Answer: B. SSL forward
proxy decryption
If a DNS sinkhole is configured, any sinkhole actions indicating a
potentially infected host are recorded in which log type?
© 2025 All rights reserved
Palo Alto Questions with Answers (100% Correct
Answers)
An Antivirus Security Profile specifies Actions and WildFire Actions.
Wildfire Actions enable you to configure the firewall to perform which
operation?
A. Delete packet data when a virus is suspected.
B. Download new antivirus signatures from WildFire.
C. Block traffic when a WildFire virus signature is detected.
D. Upload traffic to WildFire when a virus is suspected.— Answer: D.
Upload traffic to WildFire when a virus is suspected.
An Interface Management Profile can be attached to which two
interface types? (Choose two.)
A. Tap
B. Layer 2
© 2025 All rights reserved
,2
C. Loopback
D. Layer 3
E. Virtual Wire— Answer: C. Loopback
D. Layer 3
App-ID running on a firewall identifies applications using which three
methods? (Choose three.)
A. PAN-DB lookups
B. WildFire lookups
C. Application signatures
D. Program heuristics
E. Known protocol decoders— Answer: C. Application signatures
D. Program heuristics
E. Known protocol decoders
Application block pages can be enabled for which applications?
© 2025 All rights reserved
,3
A. any
B. web-based
C. MGT port-based
D. non-TCP/IP— Answer: B. web-based
Because a firewall examines every packet in a session, a firewall can
detect application ________?
A. shifts
B. errors
C. groups
D. filters— Answer: A. shifts
Finding URLs matched to the not-resolved URL category in the URL
Filtering log file might indicate that you should take which action?
© 2025 All rights reserved
, 4
A.Reboot the firewall.
B. Validate your Security policy rules.
C. Validate connectivity to the PAN-DB cloud.
D. Re-download the URL seed database.— Answer: C. Validate
connectivity to the PAN-DB cloud.
For which firewall feature should you create forward trust and
forward untrust certificates?
A. SSH decryption
B. SSL forward proxy decryption
C. SSL client-side certificate checking
D. SSL Inbound Inspection decryption— Answer: B. SSL forward
proxy decryption
If a DNS sinkhole is configured, any sinkhole actions indicating a
potentially infected host are recorded in which log type?
© 2025 All rights reserved