Free ACE Exam Braindumps (page: 23)

Page 22 of 56

Which local interface cannot be assigned to the IKE gateway?

  1. Tunnel
  2. L3
  3. VLAN
  4. Loopback

Answer(s): A



Administrative Alarms can be enabled for which of the following except?

  1. Certificate Expirations
  2. Security Violation Thresholds
  3. Security Policy Tags
  4. Traffic Log capacity

Answer(s): A



When an interface is in Tap mode and a policy action is set to block, the interface will send a TCP reset.

  1. True
  2. False

Answer(s): B



What are the benefits gained when the "Enable Passive DNS Monitoring" checkbox is chosen on the firewall? (Select all correct answers.)

  1. Improved DNSbased C&C signatures.
  2. Improved PANDB malware detection.
  3. Improved BrightCloud malware detection.
  4. Improved malware detection in WildFire.

Answer(s): A,B,D






Post your Comments and Discuss Palo Alto Networks ACE exam with other Community members:

ACE Discussions & Posts