Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Next-Generation Firewall Engineer

Domain 2Objective 5

2.5 Configure Certificates NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 3)

Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.

22questions here
5free pages
6concepts
40%of the exam

Questions 11–15

  1. 11foundation · easy

    Which validation method can be configured in a certificate profile to check the revocation status of certificates?

    Select an answer first
  2. 12expert · hard

    A security team is configuring SSL decryption and wants to balance security with compatibility. They need to support older clients that only support TLS 1.0, but they also want to enforce strong ciphers. What is the best approach?

    Select an answer first
  3. 13foundation · easy

    What is the primary role of a subordinate CA in PAN-OS SSL decryption?

    Select an answer first
  4. 14foundation · easy

    When a server presents an untrusted certificate, which certificate does the firewall use to continue decryption?

    Select an answer first
  5. 15application · medium

    An organization wants to use certificates from a public CA for user authentication to the firewall's management interface. They have already imported the CA certificate. What additional configuration is required to enable certificate authentication for administrators?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.