Free ACE Exam Braindumps (page: 16)

Page 16 of 56

When configuring a Security Policy Rule based on FQDN Address Objects, which of the following statements is True?

  1. The firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again each time Security Profiles are evaluated.
  2. The firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again at DNS TTL expiration.
  3. In order to create FQDN-based objects, you need to manually define a list of associated IP addresses.

Answer(s): B



With PAN-OS 5.0, how can a common NTP value be pushed to a cluster of firewalls?

  1. Via a Panorama Template
  2. Via a shared object in Panorama
  3. Via a Panorama Device Group
  4. Via a Device Group object in Panorama

Answer(s): B



Color-coded tags can be used on all of the items listed below EXCEPT:

  1. Address Objects
  2. Zones
  3. Service Groups
  4. Vulnerability Profiles

Answer(s): D



What are two sources of information for determining whether the firewall has been successful in communicating with an external UserID Agent?

  1. System Logs and the indicator light under the UserID Agent settings in the firewall.
  2. Traffic Logs and Authentication Logs.
  3. System Logs and an indicator light on the chassis.
  4. System Logs and Authentication Logs.

Answer(s): A



Page 16 of 56



Post your Comments and Discuss Palo Alto Networks ACE exam with other Community members:

Anonimous commented on December 01, 2023
No experience yet
SPAIN
upvote

Paulie D commented on November 05, 2018
Access to the test materials was simple and fast! Thanks Braindumps.com!
UNITED STATES
upvote