
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 2Objective 5
2.5 Configure Certificates NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 4)
Part of the PAN-OS Device Setting Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
22questions here
5free pages
6concepts
40%of the exam
Questions 16–20
- 16
A firewall is configured for SSL decryption. The security team wants to ensure that when a server certificate is untrusted, the client is blocked from proceeding. Which configuration should they use?
Select an answer first - 17
Which certificate is issued by the subordinate CA for servers that are considered trusted by the firewall?
Select an answer first - 18
Which PAN-OS feature is used to automatically enroll the firewall with a public or private PKI for certificate management?
Select an answer first - 19
Which PAN-OS object is used to define trusted CAs and validation criteria for certificates used in authentication and decryption?
Select an answer first - 20
When integrating PAN-OS with a private PKI, which component is required on the firewall to validate certificates issued by that PKI?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.