Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Next-Generation Firewall Engineer

Domain 2Objective 5

2.5 Configure Certificates NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 2)

Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.

22questions here
5free pages
6concepts
40%of the exam

Questions 6–10

  1. 6expert · hard

    A company is deploying SSL decryption with a subordinate CA. They have two options: use the subordinate CA to issue forward trust certificates, or use the root CA directly. The security team is concerned about the risk of compromise. What is a key advantage of using a subordinate CA?

    Select an answer first
  2. 7application · medium

    A firewall is configured to decrypt outbound SSL traffic. The security team wants to ensure that when a server certificate is untrusted, the client sees a warning. Which certificate should be configured as the forward untrust certificate?

    Select an answer first
  3. 8foundation · easy

    Which setting is typically configured within an SSL/TLS profile to control the minimum allowed protocol version?

    Select an answer first
  4. 9foundation · easy

    Which PAN-OS object is used to define allowed SSL/TLS protocol versions and cipher suites for decrypted traffic?

    Select an answer first
  5. 10application · medium

    A security team is configuring SSL decryption. They want to ensure that clients are warned when a server certificate is expired. Which configuration should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.