
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 1Objective 6
1.6 Configure Tunnels NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 4)
Part of the PAN-OS Networking Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
24questions here
5free pages
8concepts
40%of the exam
Questions 16–20
- 16
An IPSec tunnel between two Palo Alto firewalls is not coming up. The engineer checks the IKE gateway configuration and sees that the local and remote IKE versions match, and the pre-shared key is correct. The 'show vpn ipsec-sa' command shows no active SAs. What is the most likely next step to diagnose the issue?
Select an answer first - 17
A company is setting up a GRE tunnel between two sites. The tunnel is configured, but traffic is not being routed through it. The engineer verifies that the tunnel interface is up and the static route is correct. What should the engineer check next?
Select an answer first - 18
A company needs to connect two branch offices over the internet using a simple tunnel that can carry multicast traffic and routing protocols like OSPF. The traffic does not require encryption. Which tunnel type should be used?
Select an answer first - 19
A GRE tunnel between two Palo Alto firewalls is not passing traffic. The tunnel interface is up, and the static route is in place. What is the most likely cause of the problem?
Select an answer first - 20
When configuring an IPSec tunnel on a Palo Alto firewall, which three components must be defined and associated with each other?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.