
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 2Objective 5
2.5 Configure Certificates NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 3)
Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
22questions here
5free pages
6concepts
40%of the exam
Questions 11–15
- 11
Which validation method can be configured in a certificate profile to check the revocation status of certificates?
Select an answer first - 12
A security team is configuring SSL decryption and wants to balance security with compatibility. They need to support older clients that only support TLS 1.0, but they also want to enforce strong ciphers. What is the best approach?
Select an answer first - 13
What is the primary role of a subordinate CA in PAN-OS SSL decryption?
Select an answer first - 14
When a server presents an untrusted certificate, which certificate does the firewall use to continue decryption?
Select an answer first - 15
An organization wants to use certificates from a public CA for user authentication to the firewall's management interface. They have already imported the CA certificate. What additional configuration is required to enable certificate authentication for administrators?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.