
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 2Objective 5
2.5 Configure Certificates NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 2)
Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
22questions here
5free pages
6concepts
40%of the exam
Questions 6–10
- 6
A company is deploying SSL decryption with a subordinate CA. They have two options: use the subordinate CA to issue forward trust certificates, or use the root CA directly. The security team is concerned about the risk of compromise. What is a key advantage of using a subordinate CA?
Select an answer first - 7
A firewall is configured to decrypt outbound SSL traffic. The security team wants to ensure that when a server certificate is untrusted, the client sees a warning. Which certificate should be configured as the forward untrust certificate?
Select an answer first - 8
Which setting is typically configured within an SSL/TLS profile to control the minimum allowed protocol version?
Select an answer first - 9
Which PAN-OS object is used to define allowed SSL/TLS protocol versions and cipher suites for decrypted traffic?
Select an answer first - 10
A security team is configuring SSL decryption. They want to ensure that clients are warned when a server certificate is expired. Which configuration should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.