Palo Alto Networks ACE Exam Questions
Accredited Configuration Engineer (ACE) (Page 7 )

Updated On: 16-Feb-2026

When SSL traffic passes through the firewall, which component is evaluated first?

  1. Decryption policy
  2. Decryption Profile
  3. Security policy
  4. Decryption exclusions list

Answer(s): C



SSL Inbound Inspection requires that the firewall be configured with which two components?(Choose two.)

  1. client's digital certificate
  2. client's public key
  3. server's digital certificate
  4. server's private key

Answer(s): A,B



An Interface Management Profile can be attached to which two interface types? (Choose two.)

  1. Loopback
  2. Virtual Wire
  3. Layer 2
  4. Layer 3
  5. Tap

Answer(s): A,B,D



Which two User-ID methods are used to verify known IP address-to-user mappings? (Choosetwo.)

  1. Client Probing
  2. Server Monitoring
  3. Session Monitoring
  4. Captive Portal

Answer(s): A,B



For which firewall feature should you create forward trust and forward untrust certificates?

  1. SSH decryption
  2. SSL client-side certificate checking
  3. SSL Inbound Inspection decryption
  4. SSL forward proxy decryption

Answer(s): D






Post your Comments and Discuss Palo Alto Networks ACE exam dumps with other Community members:

Join the ACE Discussion