SONICWALL SNSA LEARNING
COMPANION 2026 FIREWALL POLICIES
AND RULE BASE MANAGEMENT
FUNDAMENTALS
◉ What does a WAN Failover solution enable?(Select all that apply)
Answer: Maintaining a persistent connection for the WAN port
traffic by failing over to the secondary WAN port and Directing
redundant routes to one or more secondary service providers
◉ In the Event Logs, which of the following will generate a log
message for any dropped packets?
Answer: Manage > Logs & reporting> logs Settings > Base Setup >
Expand Network Category > ICMP Packets Dropped, select the box
under the GUI column to show in the Event Logs
◉ What type of certificate store be used to install the certificate?
Answer: Trusted Root Certification Authorities
◉ What is the SonicOS navigation path to begin configuring the VPN
on the firewall?
Answer: Manage >> under connectivity >> VPN
,◉ What type of object is created to configure a VPN host when
implementing a Site-to-site VPN?
Answer: An Address Object type Network
◉ What is the default encryption method for both of the IKE phases
when configuring a VPN on the firewall?
Answer: 3DES
◉ Which feature facilitates the setup and deployment of multiple
global VPN clients?
Answer: a VPN policy
◉ What does the LDAP server provide to allow or deny user
authorization?
Answer: Active Directory Membership
◉ Which group of Security Services uses the SonicWall Deep Packet
Inspection engine?
Answer: Gateway Anti-virus (GAV), Anti-Spyware and Instruction
Prevention Service (IPS)
◉ Which of the following are SonicWall's Advanced Threat
Protection features?(Select all thet apply)
, Answer: All the servces from Deep Packet inspection, Capture ATP,
Geo IP and Botnet Filter
◉ In order for SonicWall1's Deep Packet Inspection engine to
provide protection, where must GAV, IPS, and Gateway Anti-Spyware
be enable?(Select all that apply)
Answer: Security services and zones all found withinthe manage tab
>> connectivity and manage tab >> network
◉ Which packet status types are indicated by the Packet
Monitor?(Select all tha apply)
Answer: Generated, Forwarded, Consumed and dropped packet
status
◉ Which option enables the capture buffer data to be wrapped and
retained to save externally when full, instead of being overwritten?
Answer: Wrap Capture Buffer once Full
◉ Which diagnostic tool test for MySonicWall server connectivity?
Answer: Check Network Settings
◉ What options are used to preempt an administrator logged into
the firewall?(Select all tha apply)
Answer: Read only and Non-Config Mode
COMPANION 2026 FIREWALL POLICIES
AND RULE BASE MANAGEMENT
FUNDAMENTALS
◉ What does a WAN Failover solution enable?(Select all that apply)
Answer: Maintaining a persistent connection for the WAN port
traffic by failing over to the secondary WAN port and Directing
redundant routes to one or more secondary service providers
◉ In the Event Logs, which of the following will generate a log
message for any dropped packets?
Answer: Manage > Logs & reporting> logs Settings > Base Setup >
Expand Network Category > ICMP Packets Dropped, select the box
under the GUI column to show in the Event Logs
◉ What type of certificate store be used to install the certificate?
Answer: Trusted Root Certification Authorities
◉ What is the SonicOS navigation path to begin configuring the VPN
on the firewall?
Answer: Manage >> under connectivity >> VPN
,◉ What type of object is created to configure a VPN host when
implementing a Site-to-site VPN?
Answer: An Address Object type Network
◉ What is the default encryption method for both of the IKE phases
when configuring a VPN on the firewall?
Answer: 3DES
◉ Which feature facilitates the setup and deployment of multiple
global VPN clients?
Answer: a VPN policy
◉ What does the LDAP server provide to allow or deny user
authorization?
Answer: Active Directory Membership
◉ Which group of Security Services uses the SonicWall Deep Packet
Inspection engine?
Answer: Gateway Anti-virus (GAV), Anti-Spyware and Instruction
Prevention Service (IPS)
◉ Which of the following are SonicWall's Advanced Threat
Protection features?(Select all thet apply)
, Answer: All the servces from Deep Packet inspection, Capture ATP,
Geo IP and Botnet Filter
◉ In order for SonicWall1's Deep Packet Inspection engine to
provide protection, where must GAV, IPS, and Gateway Anti-Spyware
be enable?(Select all that apply)
Answer: Security services and zones all found withinthe manage tab
>> connectivity and manage tab >> network
◉ Which packet status types are indicated by the Packet
Monitor?(Select all tha apply)
Answer: Generated, Forwarded, Consumed and dropped packet
status
◉ Which option enables the capture buffer data to be wrapped and
retained to save externally when full, instead of being overwritten?
Answer: Wrap Capture Buffer once Full
◉ Which diagnostic tool test for MySonicWall server connectivity?
Answer: Check Network Settings
◉ What options are used to preempt an administrator logged into
the firewall?(Select all tha apply)
Answer: Read only and Non-Config Mode