77范文网 - 专业文章范例文档资料分享平台

PaloAlto ACE认证考试题库及答案(4)

来源:网络收集 时间:2020-06-07 下载这篇文档 手机版
说明:文章内容仅供预览,部分内容可能不全,需要完整文档或者需要复制内容,请下载word后使用。下载word有问题请添加微信号:或QQ: 处理(尽可能给您提供完整文档),感谢您的支持与谅解。点击这里给我发消息

Question 36 of 72.

What is required to configure multiple Phase 2 IPSec VPN tunnels to the same Phase 1 gateway?

答案:B

Multiple P2 tunnels with different Proxy ID's on different tunnel interfaces

Multiple P2 tunnels with different Proxy ID's on the same tunnel interface

Multiple tunnel interfaces

Multiple P2 tunnels with different Peer ID's on the same tunnel Interfaces

Mark for follow up

Question 37 of 72.

With SSH decryption enabled, the SCP application will be identified as:

答案:A

ssh

sftp

scp

ssh-tunnel

Mark for follow up

Question 38 of 72.

Which of the following licenses is necessary in order to provide more accurate Botnet reporting?

答案:D

GlobalProtect Gateway License

Threat Prevention License

Virtual System License

URL-Filtering License

All of the above

Mark for follow up

Question 39 of 72.

When a user logs in via Captive Portal, their user information is checked against:

答案:B

Active Directory

Radius

Local database

All of the above

Mark for follow up

Question 40 of 72.

What option should be configured when using User Identification?

答案: C

Enable User Identification per interface

Enable User Identification per Security Rule

Enable User Identification per Zone

None of the above

Mark for follow up

Question 41 of 72.

Which of the following are necessary components of a GlobalProtect solution?

答案:D

GlobalProtect NetConnect, GlobalProtect Agent, GlobalProtect Portal, GlobalProtect Server GlobalProtect Gateway, GlobalProtect NetConnect, GlobalProtect Agent, GlobalProtect Portal, GlobalProtect Server

GlobalProtect Gateway, GlobalProtect Agent, GlobalProtect Server

GlobalProtect Gateway, GlobalProtect Agent, GlobalProtect Portal

None of the above

Mark for follow up

Question 42 of 72.

How many bytes of the URL are captured in the URL Log?

答案: C

2047

255

511

1023

Mark for follow up

Question 43 of 72.

The following can be configured as a next hop in a Static Route:

答案: D

A Policy-Based Forwarding Rule

Virtual System

A Dynamic Routing Protocol

Virtual Router

None of the above

Mark for follow up

Question 44 of 72.

Which best describes the firewall rules to be applied to a session?

答案:B

last match applied

first match applied

most specific match applied

all matches applied

Mark for follow up

Question 45 of 72.

For a security policy to allow inbound NATed traffic to a web server with a private IP address in the trust zone, the entry in the Destination Address column of the security rule should be based on the private IP address of the web server.

答案:B

True

False

Mark for follow up

Question 46 of 72.

Which local interface cannot be assigned to IKE gateway?

答案:D

VLAN

Loopback

L3

Tunnel

Mark for follow up

Question 47 of 72.

A traffic log entry with an Application of \

答案: A

The TCP SYN-ACK response packet was not seen before the session timed out

Captive Portal has not been configured properly

An invalid SSL certificate is in use

The App-ID engine could not find a matching application

None of the above

Mark for follow up

百度搜索“77cn”或“免费范文网”即可找到本站免费阅读全部范文。收藏本站方便下次阅读,免费范文网,提供经典小说综合文库PaloAlto ACE认证考试题库及答案(4)在线全文阅读。

PaloAlto ACE认证考试题库及答案(4).doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印 下载失败或者文档不完整,请联系客服人员解决!
本文链接:https://www.77cn.com.cn/wenku/zonghe/1097187.html(转载请注明文章来源)
Copyright © 2008-2022 免费范文网 版权所有
声明 :本网站尊重并保护知识产权,根据《信息网络传播权保护条例》,如果我们转载的作品侵犯了您的权利,请在一个月内通知我们,我们会及时删除。
客服QQ: 邮箱:tiandhx2@hotmail.com
苏ICP备16052595号-18
× 注册会员免费下载(下载后可以自由复制和排版)
注册会员下载
全站内容免费自由复制
注册会员下载
全站内容免费自由复制
注:下载文档有可能“只有目录或者内容不全”等情况,请下载之前注意辨别,如果您已付费且无法下载或内容有问题,请联系我们协助你处理。
微信: QQ: