Regarding network segmentation, which two steps are involved in the configuration of a default route to an internet router? (Choose two.)
A. Select the Static Routes tab, then click Add.
B. Select Network > Interfaces.
C. Select the Config tab. then select New Route from the Security Zone Route drop-down menu.
D. Select Network > Virtual Router, then select the default link to open the Virtual Router dialog.
Which two valid components are used in installation of a VM-Series firewall in an OpenStack environment? (Choose two.)
A. OpenStack heat template in JSON format
B. OpenStack heat template in YAML Ain't Markup Language (YAML) format
C. VM-Series VHD image
D. VM-Series qcow2 image
Which two criteria are required to deploy VM-Series firewalls in high availability (HA)? (Choose two.)
A. Assignment of identical licenses and subscriptions
B. Deployment on a different host
C. Configuration of asymmetric routing
D. Deployment on same type of hypervisor
What are two requirements for automating service deployment of a VM-Series firewall from an NSX Manager? (Choose two.)
A. vCenter has been given Palo Alto Networks subscription licenses for VM-Series firewalls.
B. Panorama has been configured to recognize both the NSX Manager and vCenter.
C. The deployed VM-Series firewall can establish communications with Panorama.
D. Panorama can establish communications to the public Palo Alto Networks update servers.
A CN-Series firewall can secure traffic between which elements?
A. Host containers
B. Source applications
C. Containers
D. IPods
Which feature must be configured in an NSX environment to ensure proper operation of a VM-Series firewall in order to secure east-west traffic?
A. Deployment of the NSX DFW
B. VMware Information Sources
C. User-ID agent on a Windows domain server
D. Device groups within VMware Services Manager
Which two features of CN-Series firewalls protect east-west traffic between pods in different trust zones? (Choose two.)
A. Intrusion prevention system
B. Communication with Panorama
C. External load balancer
D. Layer 7 visibility
A customer in a VMware ESXi environment wants to add a VM-Series firewall and partition an existing group of virtual machines (VMs) in the same subnet into two groups. One group requires no additional security, but the second group requires substantially more security.
How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?
A. Edit the IP address of all of the affected VMs. www*
B. Create a new virtual switch and use the VM-Series firewall to separate virtual switches using virtual wire mode. Then move the guests that require more security into the new virtual switch.
C. Create a Layer 3 interface in the same subnet as the VMs and then configure proxy Address Resolution Protocol (ARP).
D. Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete it.
What are two environments supported by the CN-Series firewall? (Choose two.)
A. Positive K
B. OpenShift
C. OpenStack
D. Native K8
Which component allows the flexibility to add network resources but does not require making changes to existing policies and rules?
A. Content-ID
B. External dynamic list
C. App-ID
D. Dynamic address group