
Palo Alto NetworksCertified Next-Generation Firewall Engineer
Domain 1Objective 2
1.2 Configure Zones NEXT-GENERATION-FIREWALL-ENGINEER Practice Questions (Page 3)
Part of the PAN-OS Networking Configuration domain, which accounts for 40% of the NEXT-GENERATION-FIREWALL-ENGINEER exam.
21questions here
5free pages
8concepts
40%of the exam
Questions 11–15
- 11
Why is it recommended to group interfaces with similar security requirements into the same zone?
Select an answer first - 12
A company is deploying a PAN-OS firewall in a network where the firewall must inspect traffic between two routers. The firewall will be placed inline, and the routers will handle all routing. The firewall should not have any IP addresses on its interfaces. Which zone type should the administrator configure for the interfaces connected to the routers?
Select an answer first - 13
A company is deploying a PAN-OS firewall in a network where the firewall must not route traffic but instead pass traffic between two network segments without modifying the IP addresses. The firewall will be placed inline between two switches, and the goal is to inspect traffic without acting as a router. Which zone type should the administrator configure for the interfaces connected to these segments?
Select an answer first - 14
Which of the following is a best practice for zone design in PAN-OS?
Select an answer first - 15
Which of the following is true about assigning multiple interfaces to the same zone?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NEXT-GENERATION-FIREWALL-ENGINEER” is a trademark of its owner, used for identification only.