Cloud NGFW For AWS - Assessment

Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Completed: Apr 1 - 12:28 PM


Akash Peiris

36 %

Assessment Failed
Thank you for completing the assessment. Unfortunately, you did not
answer enough questions correctly to receive a passing grade.

Total Points: 5/14 Correct Answers: 5/14


View Response Details

Close

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 1/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Response Details
Print

Section Results
Section 1 Points: 5/14

Your Responses

Question 1 of 14 +1

Which of the following is an instantiation of the Cloud


NGFW service associated with your AWS account?
6636947

Cloud NGFW tenant

Cloud NGFW

Cloud NGFW endpoints

Rulestacks

Question 2 of 14 +0 / 1

In which deployment model is the Cloud NGFW located


behind a Transit Gateway (TGW) with a security VPC?
6636947

Distributed model

Centralized model

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 2/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Hierarchical model

Transit model

The correct answer was "Centralized model".

Question 3 of 14 +0 / 1

Which two of the following are characteristics of a


distributed architecture model? (Choose two.)
6636947

Lower TCO

Organizational cloud maturity

Limits the impact of an outage

Requires Transit Gateway

The correct answer was "Organizational cloud maturity, Limits the impact of
an outage".

Question 4 of 14 +1

In a distributed deployment, any traffic leaving the


availability zone is redirected to the NGFW endpoint and
sent to the Cloud NGFW for inspection and enforcement.
6636947

True

False

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 3/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Question 5 of 14 +0 / 1

Which of the following is a part of onboarding an AWS


account to the Cloud NGFW tenant?
6636947

Inviting users to help manage the account.

Creating Rulestacks and rules

Creating Cloud NGFW and endpoints

Specifying logging options

The correct answer was "Inviting users to help manage the account.".

Question 6 of 14 +1

Rulestacks are associated with which of the following?


6636947

VPCs

Availability Zones

Cloud NGFW endpoints

Cloud NGFW resource

Question 7 of 14 +1

Which three Amazon options are destinations for your


Cloud NGFW logs? (Choose three.)
6636947

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 4/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

S3

CloudWatch

ECS container

ELB log

Kinesis

Question 8 of 14 +0 / 1

Which rulestack defines rules for specific applications or


users?
6636947

Local rulestack

Global pre-rules

Global post-rules

Universal rules

The correct answer was "Local rulestack".

Question 9 of 14 +0 / 1

Which security rule object is an ongoing data stream


related to an organization's potential or current security
threats?
6636947

Prefix and FQDN lists

Custom URL Category

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 5/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Intelligent feed

External dynamic list

The correct answer was "Intelligent feed".

Question 10 of 14 +0 / 1

What helps define an “allow but scan” rule that inspects


for threats like viruses, malware, spyware, and DDoS
attacks?
6636947

Security policy

Security profile

App-ID

Content-ID

The correct answer was "Security profile".

Question 11 of 14 +0 / 1

Which two types of administrators can create and modify


global and local Rulestacks? (Choose two.)
6636947

Local

Global

Firewall

Tenant

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 6/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

The correct answer was "Global, Tenant".

Question 12 of 14 +1

What enables you to see the applications on your network


and learn how they work their behavioral characteristics,
and their relative risk? 6636947

App-ID

Content-ID

Security policies

Security profiles

Question 13 of 14 +0 / 1

What is the term for a single object or collective unit that


groups discrete identities such as IP addresses, fully
qualified domain names (FQDNs), intelligent feeds, or
certificates?
6636947

Rulestack

Object stack

Security policy object

Security rule object

The correct answer was "Security rule object".

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 7/8
4/1/24, 12:29 PM Cloud NGFW for AWS - Assessment

Question 14 of 14 +0 / 1

Which decryption types are available for Cloud NGFW for


AWS? (Choose two.)
6636947

Inbound TLS

Inbound SSH

Outbound TLS

East-West TLS

The correct answer was "Inbound TLS , Outbound TLS".

https://beacon.paloaltonetworks.com/assessment_responses/report/21828424#assessment-response-details 8/8

You might also like