ACE Exam Questions
172 real ACE exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #102
Wildfire may be used for identifying which of the following types of traffic?
- Question #103
When Network Address Translation has been performed on traffic, Destination Zones in Security rules should be based on:
- Question #104
In Active/Active HA environments, redundancy for the HA3 interface can be achieved by
- Question #105
An Outbound SSL forward-proxy decryption rule cannot be created using which type of zone?
- Question #106
When a Palo Alto Networks firewall is forwarding traffic through interfaces configured for L2 mode, security policies can be set to match on multicast IP addresses.
- Question #107
In an Anti-Virus profile, changing the action to "Block" for IMAP or POP decoders will result in the following:
- Question #108
After configuring Captive Portal in Layer 3 mode, users in the Trust Zone are not receiving the Captive Portal authentication page when they launch their web browsers. How can this...
- Question #109
The "Disable Server Return Inspection" option on a security profile:
- Question #110
A user complains that they are no longer able to access a needed work application after you have implemented vulnerability and anti-spyware profiles. The user's application uses a...
- Question #111
You'd like to schedule a firewall policy to only allow a certain application during a particular time of day. Where can this policy be configured?
- Question #112
What is the size limitation of files manually uploaded to WildFire
- Question #113
Enabling "Highlight Unused Rules" in the Security policy window will:
- Question #114
Which statement accurately reflects the functionality of using regions as objects in Security Policies?
- Question #115
When employing the Brightcloud URL filtering database on the Palo Alto Networks firewalls, the order of checking within a profile is:
- Question #116
The following can be configured as a next hop in a Static Route:
- Question #117
In PAN-OS 5.0, how is Wildfire enabled?
- Question #118
Traffic going to a public IP address is being translated by your PANW firewall to your web server's private IP. Which IP should the Security Policy use as the "Destination IP" in o...
- Question #119
You have decided to implement a Virtual Wire Subinterface. Which options can be used to classify traffic?
- Question #120
When allowing an Application in a Security policy on a PAN-OS 5.0 device, would a dependency Application need to also be enabled if the application does not employ HTTP, SSL, MSRPC...
- Question #121
Users can be authenticated serially to multiple authentication servers by configuring:
- Question #122
When creating a Security Policy to allow Facebook in PAN-OS 5.0, how can you be sure that no other web-browsing traffic is permitted?
- Question #123
When configuring Security rules based on FQDN objects, which of the following statements are true?
- Question #124
When troubleshooting Phase 1 of an IPSec VPN tunnel, what location will have the most informative logs?
- Question #125
Configuring a pair of devices into an Active/Active HA pair provides support for:
- Question #126
Which of the dynamic Updates listed below are issued on a daily basis?
- Question #127
Select the implicit rules enforced on traffic failing to match any user defined Security Policies:
- Question #128
Palo Alto Networks firewalls support the use of both Dynamic (built-in user roles) and Role-Based (customized user roles)
- Question #129
In PAN-OS 6.0, rule numbers were introduced. Rule Numbers are:
- Question #130
Which of the following is NOT a valid option for built-in CLI access roles?
- Question #131
Which of the following objects cannot use User-ID as a match criteria?
- Question #132
Subsequent to the installation of new licenses, the firewall must be rebooted
- Question #133
When an interface is in Tap mode and a policy action is set to block, the interface will send a TCP reset.
- Question #134
The "Drive-By Download" protection feature, under File Blocking profiles in Content-ID, provides:
- Question #135
Which of the following would be a reason to use an XML API to communicate with a Palo Alto Networks firewall?
- Question #136
Which link is used by an Active-Passive cluster to synchronize session information?
- Question #137
Which of the following describes the sequence of the Global Protect agent connecting to a Gateway?
- Question #138
Taking into account an information in the screenshot above, answer the following question. In order for ping traffic to traverse this device from e1/2 to e1/1, what else needs to b...
- Question #139
What is the default DNS Sinkhole address used by Palo Alto Networks Firewall to cut off communication?
- Question #140
When configuring Admin Roles for Web UI access, what are the available access levels?
- Question #141
Which of the following interfaces types will have a MAC address?
- Question #142
Wildfire Analysis Reports are available for the following Operating Systems (select all that apply)
- Question #143
What option should be configured when using User-ID
- Question #144
What is the default setting for 'Action' in a Decryption Policy's rule?
- Question #145
With IKE, each device is identified to the other by a Peer ID. In most cases, this is just the public IP address of the device. In situations where the public ID is not static, thi...
- Question #146
When configuring a Decryption Policy, which of the following are available as matching criteria in a policy? (Choose 3)
- Question #147
Which of the following are methods HA clusters use to identify network outages?
- Question #148
As a Palo Alto Networks firewall administrator, you have made unwanted changes to the Candidate configuration. These changes may be undone by Device > Setup > Operations > Configur...
- Question #149
When employing the BrightCloud URL filtering database in a Palo Alto Networks firewall, the order of evaluation within a profile is:
- Question #150
When Destination Network Address Translation is being performed, the destination in the corresponding Security Policy Rule should use:
- Question #151
Taking into account only the information in the screenshot above, answer the following question. Which applications will be allowed on their standard ports? (Select all correct ans...