PaloAlto - ACE认证考试题库及答案2016-1月 下载本文

Which of the following would be a reason to use the PAN-OS XML API to communicate with a Palo Alto Networks firewall? *

To permit syslogging of User Identification events.

To pull information from other network resources for User-ID.

To allow the firewall to push User-ID information to a Network Access Control (NAC) device.

Mark for follow up

Question 34 of 50.

Which link is used by an Active/Passive cluster to synchronize session information? *

The Uplink The Link

Management

The Data Link The Control Link

Mark for follow up

Question 35 of 50.

Taking into account only the information in the screenshot above, answer the following question. Which applications will be allowed on their standard ports? (Select all correct answers.)

Skype Gnutella SSH BitTorrent

Mark for follow up

Question 36 of 50.

Which of the following must be enabled in order for User-ID to function? *

Captive Portal Policies must be enabled.

Security Policies must have the User-ID option enabled.

User-ID must be enabled for the source zone of the traffic that is to be identified.

Captive Portal must be enabled.

Mark for follow up

Question 37 of 50.

A Config Lock may be removed by which of the following users? (Select all correct answers.)

Superusers

The administrator who set it Any administrator Device administrators

Mark for follow up

Question 38 of 50.

An enterprise PKI system is required to deploy SSL Forward Proxy decryption capabilities. True

Mark for follow up

Question 39 of 50.

What is the default setting for 'Action' in a Decryption Policy's rule? *

Decrypt

No-Decrypt

False

None Any

Mark for follow up

Question 40 of 50.

Without a WildFire subscription, which of the following files can be submitted by the Firewall to the hosted WildFire virtualized sandbox? *

PDF files only

PE files only

PE and Java Applet (jar and class) only

MS Office doc/docx, xls/xlsx, and ppt/pptx files only

Mark for follow up

Question 41 of 50.

Which pre-defined Admin Role has all rights except the rights to create administrative accounts and virtual systems? *

Superuser