
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 1Objective 6
1.6 Configure Tunnels NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 5)
Part of the PAN-OS Networking Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
24questions here
5free pages
8concepts
40%of the exam
Questions 21–24
- 21
A security auditor recommends that all IPSec tunnels use quantum-resistant cryptography to prepare for future threats. The engineer is configuring a new tunnel and wants to comply. What should the engineer do?
Select an answer first - 22
Which PAN-OS tool or command would you use first to verify whether an IPSec tunnel is up and to see the current security association (SA) status?
Select an answer first - 23
An engineer is configuring a GRE tunnel on a Palo Alto firewall. The tunnel interface has been created and assigned an IP address. What is the next step to route traffic through the tunnel?
Select an answer first - 24
Which of the following is a post-quantum cryptographic algorithm that PAN-OS supports for IPSec key exchange?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NEXT-GENERATION-FIREWALL-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.