nerdexam
Palo_Alto_Networks

ACE · Question #123

When configuring Security rules based on FQDN objects, which of the following statements are true?

The correct answer is C. In order to create FQDN-based objects, you need to manually define a list of associated IP. Up to 10 IP addresses can be configured for each FQDN entry. See the full explanation below for the reasoning.

Question

When configuring Security rules based on FQDN objects, which of the following statements are true?

Options

  • AThe firewall resolves the FQDN first when the policy is committed, and is refreshed each time Security rules are evaluated.
  • BThe firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration. There is no limit on the number of IP addresses stored for each resolved FQDN.
  • CIn order to create FQDN-based objects, you need to manually define a list of associated IP. Up to 10 IP addresses can be configured for each FQDN entry.
  • DThe firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration. The resolution of this FQDN stores up to 10 different IP addresses.

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    10% (2)
  • C
    70% (14)
  • D
    5% (1)

Community Discussion

No community discussion yet for this question.

Full ACE Practice