When offloading traffic from the NGFW using Arista MSS, a 5 tuple is used and what
actions are available? (Select all that apply)
A. Permit
B. Deny
C. Block
D. Allow
E. Reset - Answers -A, B
How does Arista MSS decide what traffic should be sent to the NGFW for inspection?
A. Defined in CloudVision console
B. Interesting rules pulled from Panorama
C. Traffic is inline using vWire between leaf switches - Answers -B
Using which two metrics gathered by Celiometer, OpenStack deploys or shuts down
additional instances of the VM-Series firewall to meet the current needs of your network.
A. Memory Utilization
B. CPU Utilization
C. Incoming bytes per second
D. Outgoing bytes per second - Answers -B, C
What is responsible for Orchestration on Open Stack?
A. KVM/Ubuntu 14.04
B. Contrail 3.0.2
C. Mirantis 8.0 (Liberty)
D. OpenStack Heat Templates (version 2015-10-15 or higher)
E. Celiometer (service scaling only) - Answers -D
What is responsible for Networking on Open Stack?
A. KVM/Ubuntu 14.04
B. Contrail 3.0.2
C. Mirantis 8.0 (Liberty)
D. OpenStack Heat Templates (version 2015-10-15 or higher)
E. Celiometer (service scaling only) - Answers -B
What is responsible for Telemetry on Open Stack?
A. KVM/Ubuntu 14.04
B. Contrail 3.0.2
C. Mirantis 8.0 (Liberty)
D. OpenStack Heat Templates (version 2015-10-15 or higher)
E. Celiometer (service scaling only) - Answers -E
In regards to Open Stack the compute node that houses the VM-Series must meet the
following criteria (Select 4)
A. Instance type OS::Nova::Server
,B. Allow configuration of at least 3 interfaces
C. Accept the VM-Series qcow2 image
D. Accept the compute flavor parameter
E. Accept Palo Alto Networks as trusted application installer - Answers -A, B, C, D
Which of the following vCenter/ESXi versions are supported for NSX?
A. 5.5
B. 6.0
C. 6.5
D. 6.7 - Answers -A, B, C
What version(s) of NSX-V are supported by VM-Series?
A. 6.0
B. 6.1
C. 6.2
D. 6.3 - Answers -B, C, D
What is the purpose of the NSX Service Composer?
A. allows you to group virtual machines and create policy to redirect traffic to the VM-
Series firewall
B. automatically detect when to autoscale
C. malware detection and prevention
D. configure in place of Panorama - Answers -A
What is the service called for the VM-Series on NSX-V Manager?
A. PANW NGFW
B. Palo Alto Networks VM-Series
C. Palo Alto Networks
D. Palo Alto Networks NGFW - Answers -D
How can you automate a VM-Series deployment on NSX-V?
A. Service Composer
B. PAN XML API
C. NetX API
D. Virtual machine template - Answers -C
What type of interface is supported in NSX-V (Choose 1)?
A. Tap
B. vWire
C. Layer 2
D. Layer 3 - Answers -B
What port is used for a VM-Series firewall management interface to communicate with
Panorama?
A. 80
B. 443
,C. 3978
D. 6514 - Answers -C
What do Panorama and NSX-V Manager use for registering the Palo Alto Networks
NGFW service?
A. NetX management plane API
B. They do not communicate. The service must be manually installed
C. NetX data plane API
D. PAN OS XML API - Answers -A
After NSX-V auto deploys a firewall what connects the hypervisor to the firewall so it
can retrieve traffic?
A. NetX management plane API
B. They do not communicate. The service must be manually installed
C. NetX data plane API
D. PAN OS XML API - Answers -C
How does NSX-V Manager update Panorama when a guest is added or modified in the
ESXi cluster or a security group is updated or created
A. NetX management plane API
B. SOAP XML API
C. NetX data plane API
D. PAN OS XML API - Answers -D
To ensure that traffic from the guests is steered to the VM-Series firewall, you must
have what installed on each guest
A. GlobalProtect
B. VMWare tools
C. Cortex XDR
D. PAN-OS Terminal Agent - Answers -B
Where are steering rules DEFINED for NSX?
A. Panorama
B. vCenter
C. vSwitch
D. NSX Manager - Answers -A
Where are steering rules APPLIED for NSX?
A. Panorama
B. vCenter
C. vSwitch
D. NSX Manager - Answers -D
A company moving as much of its business as possible into Amazon AWS is trying to
minimize which parameter(s)?
A. Capital expenses
, B. Operating expenses
C. both opex and capex
D. Security exposure - Answers -A
An online retailer uses a hybrid cloud to handle burst capacity. Which part of the
application is most likely to be sent to the public cloud during a demand peak?
A. B2C payment module, which includes credit cards, names, etc.
B. warehouse module, which identifies how much of each item the various warehouses
have and where they are located
C. shipping module, which contains people's shipping addresses and the exact items
they ordered
D. B2B payment module, which includes invoice information - Answers -B
On which two cloud environments can you install micro-segmentation? (Choose two.)
A. public cloud, used as IaaS (infrastructure as a service)
B. hybrid cloud
C. public cloud, used as PaaS (platform as a service)
D. private cloud
E. public cloud, used as SaaS - Answers -B, D
What are the two major risks of using SaaS? (Choose two.)
A. loss of connectivity
B. poor performance
C. unexpected costs
D. loss of data integrity
E. confidential data leaks - Answers -D, E
Which type of cloud service can be protected by a firewall controlled by the organization
rather than by the cloud provider?
A. SaaS
B. FaaS
C. PaaS
D. IaaS - Answers -D
Which model is not supported for ESXi use?
A. VM-50
B. VM-70
C. VM-100
D. VM-1000 - Answers -B
If all the virtual machines on an ESXi host belong in the same zone, should you
installVM-Series? If so, why?
A. No, it is a waste of processing power
B. Yes, because VMs move randomly and you might have VMs with different zones in
the future
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller GEEKA. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $13.49. You're not tied to anything after your purchase.