nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #116

An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's…

The correct answer is A. It provides selective DNS resolution, with specified domains resolved through the tunnel. A split DNS policy in GlobalProtect provides selective DNS resolution (A): only DNS queries for explicitly listed domains are routed through the VPN tunnel to be resolved by the corporate DNS servers assigned by the VPN, while all other DNS queries are resolved using the…

GlobalProtect Configuration

Question

An engineer is configuring a GlobalProtect portal and wants to enable split tunneling. The the DNS servers assigned by the VPN, while allowing all other DNS queries to be resolved by the client's locally configured DNS. What is the effect of configuring this split DNS policy?

Options

  • AIt provides selective DNS resolution, with specified domains resolved through the tunnel,
  • BIt blocks access to all domains that are not explicitly listed in the split tunnel configuration.
  • CIt forces all applications to use the corporate DNS servers, regardless of the split tunnel settings
  • DIt creates a DNS proxy on the client endpoint that forwards all queries to the firewall for inspection.

How the community answered

(31 responses)
  • A
    87% (27)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)

Explanation

A split DNS policy in GlobalProtect provides selective DNS resolution (A): only DNS queries for explicitly listed domains are routed through the VPN tunnel to be resolved by the corporate DNS servers assigned by the VPN, while all other DNS queries are resolved using the client's locally configured DNS servers outside the tunnel. This is the core purpose of split DNS - directing specific domain lookups to internal DNS while leaving general internet DNS queries to resolve locally, improving performance and reducing unnecessary VPN tunnel load. It does not block all unlisted domains (B); unlisted domains simply resolve via local DNS. It does not force all applications to use corporate DNS regardless of split tunnel settings (C). It does not create a DNS proxy on the endpoint that forwards all queries to the firewall for inspection (D); queries not matching the configured domains are handled locally.

Topics

#GlobalProtect#Split DNS#VPN#Split Tunneling

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice