Which three network events are highlighted through correlation objects as a potential security risks? (Choose three.)
A. Identified vulnerability exploits
B. Suspicious traffic patterns
C. Known command-and-control activity
D. Launch of an identified malware executable file
E. Endpoints access files from a removable drive
Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?
A. WildFire on the firewall, and AutoFocus on Panorama
B. URL Filtering on the firewall, and MindMeld on Panorama
C. Threat Prevention on the firewall, and Support on Panorama
D. GlobalProtect on the firewall, and Threat Prevention on Panorama
Which Palo Alto Networks security platform component should an administrator use to extend policies to remote users are not connecting to the internet from behind a firewall?
A. Threat Intelligence Cloud
B. Traps
C. GlobalProtect
D. Aperture
Which certificate can be used to ensure that traffic coming from a specific server remains encrypted?
A. Forward entrust
B. SSL exclude certificate
C. Forward trust
D. SSL inbound inspection
What is the recommended way to ensure that firewalls have the most current set of signatures for up-todate protection?
A. Store updates on an intermediary server and point all the firewalls to it
B. Monitor update announcements and manually push updates to firewalls
C. Utilize dynamic updates with an aggressive update schedule
D. Run a Perl script to regularly check for updates and alert when one in released
How often are regularly scheduled update for the Anti-virus Application, Threats, and Wildfire subscription databases made available by Palo Alto Networks in PAN-OS 8.0?
A. Anti-Virus (Daily) Application (Weekly), Threats (Daily), Wildfire (5 Minutes)
B. Anti-Virus (Weekly) Application (Daily), Threats (Daily), Wildfire (5 Minutes)
C. Anti-Virus (Daily) Application (Weekly), Threats (Weekly), Wildfire (5 Minutes)
D. Anti-Virus (Weekly) Application (Daily), Threats (Weekly), Wildfire (5 Minutes)
What are two core values of the Palo Alto Network Security Platform? (Choose two)
A. Sale enablement of all applications
B. Deployment of multiple point-based solutions to provide full security coverage
C. Prevention of cyberattacks
D. Threat remediation
E. Defense against threats with static security solution
A network covers three geographical areas: Americas, Europe (EMEA), and Asia (APAC). The APAC
segment of the network consists of nine HA pairs of PA-3060 firewalls, generating a combined log output K
logs per second.
Only 14 days of traffic log retention is required.

Which management and logging solution will be effective and cost-efficient for this segment of the network?
A. Two M-500s in HA management at the global level, with one M-100 with 4 TB of storage for APAC
B. Two M-500s in HA management at the global level, and one log collector-mode M-500 with 8 TB of storage for APAC
C. Two M-500s in HA management at the global level, and two log collector-mode M-500s in a log collector group with 16 TB of storage for APAC
D. Two Dual-mode M-500s in HA for both global management and storage. Each M-500 has 8 TB of storage
The botnet report displays a confidence score of 1 to 5 indicating the likelihood of a botnet infection.
Which three sources are used by the firewall as the basis of this score? (Choose three.)
A. Bad Certificate Reports
B. Traffic Type
C. Botnet Reports
D. Number of Events
E. Executable Downloads
F. Threat Landscape
Which two features are found in a next-generation firewall but are absent in a legacy firewall product? (Choose two)
A. Identification of application is possible on any port
B. Traffic is separated by zones
C. Traffic control is based on IP, port, and protocol
D. Policy match is a based on application
E. Onboard SSL decryption capability is used