Palo Alto Networks ACE Exam Questions
Accredited Configuration Engineer (ACE) (Page 8 )

Updated On: 24-Feb-2026

If a DNS sinkhole is configured, any sinkhole actions indicating a potentially infected host are recorded in which log type?

  1. Traffic
  2. WildFire Submissions
  3. Data Filtering
  4. Threat

Answer(s): D



Which feature is a dynamic grouping of applications used in Security policy rules?

  1. implicit applications
  2. dependent applications
  3. application group
  4. application filter

Answer(s): C



Where does a GlobalProtect client connect to first when trying to connect to the network?

  1. AD agent
  2. User-ID agent
  3. GlobalProtect Gateway
  4. GlobalProtect Portal

Answer(s): D



What are three connection methods for the GlobalProtect agent? (Choose three.)

  1. Pre-Logon
  2. Captcha portal
  3. User-Logon
  4. On-demand

Answer(s): A,C,D



App-ID running on a firewall identifies applications using which three methods? (Choose three.)

  1. Application signatures
  2. Known protocol decoders
  3. WildFire lookups
  4. Program heuristics
  5. PAN-DB lookups

Answer(s): A,B,D






Post your Comments and Discuss Palo Alto Networks ACE exam dumps with other Community members:

Join the ACE Discussion