
実践サンプルと問題集と指導には2026年最新のNGFW-Engineer有効なテスト問題集
最新 [2026年09月03日] 100%合格率保証付きの素晴らしいNGFW-Engineer試験問題PDF
質問 # 75
Palo Alto Networks NGFWs use SSL/TLS profiles to secure which two types of connections? (Choose two.)
- A. GlobalProtect Gateways
- B. User Authentication
- C. NAT tables
- D. GlobalProtect Portal
正解:A、D
解説:
Basic Concept: SSL/TLS service profiles bind a certificate and protocol settings to firewall services that present HTTPS/TLS endpoints. GlobalProtect portal and gateway are classic examples.
Why C and D are Correct: GlobalProtect Gateways and GlobalProtect Portals use SSL/TLS service profiles to define the server certificate and TLS parameters presented to connecting endpoints.
Why A is Wrong: NAT tables is associated with authentication, PKI, or TLS configuration, but it is not the object or step that enforces the certificate validation or service identity requirement being tested.
Why B is Wrong: User Authentication is associated with authentication, PKI, or TLS configuration, but it is not the object or step that enforces the certificate validation or service identity requirement being tested.
質問 # 76
An NGFW engineer is establishing bidirectional connectivity between the accounting virtual system (VSYS) and the marketing VSYS. The traffic needs to transition between zones without leaving the firewall (no external physical connections). The interfaces for each VSYS are assigned to separate virtual routers (VRs), and inter-VR static routes have been configured. An external zone has been created correctly for each VSYS.
Security policies have been added to permit the desired traffic between each zone and its respective external zone. However, the desired traffic is still unable to successfully pass from one VSYS to the other in either direction.
Which additional configuration task is required to resolve this issue?
- A. Enable the "allow inter-VSYS traffic" option in both external zone configurations.
- B. Create a transit VSYS and route all inter-VSYS traffic through it.
- C. Create Security policies to allow the traffic between the two external zones.
- D. Add each VSYS to the list of visible virtual systems of the other VSYS.
正解:D
解説:
Basic Concept: Inter-VSYS communication that stays inside the firewall requires external zones, routes, policies, and visibility between virtual systems. Missing visibility prevents the handoff even when policies exist.
Why B is Correct: Adding each VSYS to the other's visible virtual systems list is required so the external-zone
/next-vr relationship can resolve the peer VSYS.
Why A is Wrong: Create a transit VSYS and route all inter-VSYS traffic through it. mentions a VSYS, zone, or routing concept, but it does not satisfy the specific external-zone, visibility, or resource-control requirement for this virtual system design.
Why C is Wrong: Enable the "allow inter-VSYS traffic" option in both external zone configurations.
mentions a VSYS, zone, or routing concept, but it does not satisfy the specific external-zone, visibility, or resource-control requirement for this virtual system design.
Why D is Wrong: Create Security policies to allow the traffic between the two external zones. mentions a VSYS, zone, or routing concept, but it does not satisfy the specific external-zone, visibility, or resource- control requirement for this virtual system design.
質問 # 77
In a Collector Group with multiple Log Collectors, enabling redundancy ensures that:
- A. Logs are stored in a compressed format to save space.
- B. Each log is stored only on the primary Log Collector.
- C. Logs are distributed based on a round-robin mechanism.
- D. Each log has two copies, each residing on a different Log Collector.
正解:D
質問 # 78
Without performing a context switch, which set of operations can be performed that will affect the operation of a connected firewall on the Panorama GUI?
- A. Modification of post NAT rules, creation of new views on the local firewall ACC tab, creation of local custom reports
- B. Restarting the local firewall, running a packet capture, accessing the firewall CLI
- C. Modification of pre-security rules, modification of a virtual router, modification of an IKE Gateway Network Profile
- D. Modification of local security rules, modification of a Layer 3 interface, modification of the firewall device hostname
正解:C
解説:
From the Panorama GUI context, pre-rules (pre-security rules), virtual routers, and IKE Gateway Network Profiles are managed centrally through Device Groups and Templates, so modifications apply directly to firewalls after commit/push without needing to switch to the firewall's local context.
質問 # 79
How do Zone Protection Profiles enhance network security?
- A. By encrypting all traffic entering and leaving the zone
- B. By providing protection against flood attacks, reconnaissance scans, and packet-based threats
- C. By replacing security policies with predefined rule sets
- D. By dynamically assigning users to security groups
正解:B
質問 # 80
A network administrator is hardening a new Palo Alto Networks firewall and wants to ensure that all firewall- generated management traffic, such as calls to Strata Logging Service, uses a dedicated in-band data port instead of the out-of-band management port.
Which configuration setting should the administrator modify to reroute this type of traffic?
- A. Static route
- B. Service route
- C. Interface Management profile
- D. Virtual router
正解:B
解説:
Basic Concept: Service route configuration controls egress for firewall-generated management traffic. It can force cloud service or update traffic through a data-plane interface.
Why A is Correct: Service route is the setting that reroutes firewall-originated traffic away from the management port.
Why B is Wrong: Interface Management profile is related to management or logging, but it does not provide the required Panorama operation, rule hierarchy behavior, or dual-log forwarding outcome.
Why C is Wrong: Virtual router is related to management or logging, but it does not provide the required Panorama operation, rule hierarchy behavior, or dual-log forwarding outcome.
Why D is Wrong: Static route is related to management or logging, but it does not provide the required Panorama operation, rule hierarchy behavior, or dual-log forwarding outcome.
質問 # 81
Which two actions in the IKE Gateways will allow implementation of post-quantum cryptography when building VPNs between multiple Palo Alto Networks NGFWs? (Choose two.)
- A. Select IKE v2, enable the Advanced Options - PQ PPK, then set a 64+ character string for the post-quantum pre shared key.
- B. Select IKE v2 Preferred, enable the Advanced Options - PQ KEM, then add one or more
"Rounds." - C. Select IKE v2, enable the Advanced Options - PQ KEM, then create an IKE Crypto Profile with Advanced Options adding one or more "Rounds."
- D. Ensure Authentication is set to "certificate," then import a post-quantum derived certificate.
正解:B、C
解説:
To implement post-quantum cryptography (PQC) in VPNs between Palo Alto Networks NGFWs, you would enable the PQ KEM (Post-Quantum Key Encapsulation Mechanism) in the IKE gateway configuration. This enables the firewall to use quantum-resistant encryption for key exchange, which is an essential part of securing communications against the potential future threats posed by quantum computing.
By selecting IKE v2 Preferred and enabling the PQ KEM option under Advanced Options, you can add specific Rounds for the post-quantum cryptography process, which will help in implementing quantum-resistant key exchange methods.
This option similarly selects IKE v2 and enables PQ KEM while also creating a dedicated IKE Crypto Profile with the necessary Rounds configured for post-quantum cryptography.
質問 # 82
An engineer configures a PA-440 firewall to act as a switch by creating several Layer 2 interfaces and assigning them all to VLAN 20. A file server is connected to interface ethernet1/1, and client workstations are connected to interfaces ethernet1/2 and ethemet1/3. All devices are in VLAN 20. The clients are unable to access the file server.
Which configuration step to allow this communication by default is missing?
- A. Create a Layer 3 subinterface for VLAN 20 to enable routing.
- B. Create an Aggregate Ethernet (AE) group that includes all three interfaces.
- C. Place ethernet1/1, ethernet1/2, and ethernet1/3 into the same Layer 2 zone.
- D. Create an "allow" Security policy with the source and destination VLAN set to "VLAN 20".
正解:C
解説:
Basic Concept: Layer 2 interfaces in the same VLAN still depend on zone assignment and intrazone/interzone policy. Same-zone traffic is allowed by intrazone-default unless changed.
Why B is Correct: Placing all three Layer 2 interfaces in the same Layer 2 zone allows same-VLAN communication by default.
Why A is Wrong: Create an Aggregate Ethernet (AE) group that includes all three interfaces. is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why C is Wrong: Create an "allow" Security policy with the source and destination VLAN set to "VLAN 20".
is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why D is Wrong: Create a Layer 3 subinterface for VLAN 20 to enable routing. is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
質問 # 83
What is a valid configurable limit for setting resource quotas when defining a new VSYS on a Palo Alto Networks firewall?
- A. Disk space allocation for logs
- B. Maximum number of virtual routers
- C. Percentage of total CPU utilization
- D. Maximum number of SSL decryption rules
正解:D
解説:
When defining a new VSYS, PAN-OS allows administrators to set explicit resource quotas on policy-related objects, including limits on rule capacities, which can include SSL decryption rules as part of security policy resources, enabling controlled allocation of configuration and processing capacity per VSYS.
質問 # 84
Which configuration step is required when implementing a new self-signed root certificate authority (CA) certificate for SSL decryption on a Palo Alto Networks firewall?
- A. Configure the subordinate CA to issue certificates with indefinite validity periods.
- B. Disable all existing SSL decryption rules until the new certificate is fully propagated.
- C. Import the new subordinate CA certificate into the trust stores of all client devices.
- D. Set the subordinate CA certificate as the default routing certificate for all network traffic.
正解:C
解説:
When implementing a new self-signed root certificate authority (CA) for SSL decryption on a Palo Alto Networks firewall, the subordinate CA certificate (which is generated by the firewall) must be imported into the trust stores of all client devices. This ensures that client devices trust the firewall as a valid certificate authority, enabling the firewall to decrypt and re-encrypt SSL traffic.
Importing the subordinate CA certificate into the client devices' trust stores is necessary for those devices to trust the new self-signed root CA and properly handle SSL decryption traffic.
質問 # 85
Which statement applies to Log Collector Groups?
- A. In any single Collector Group, all the Log Collectors must run on the same Panorama model.
- B. Log redundancy is available only if each Log Collector has the same amount of total disk storage.
- C. Enabling redundancy increases the log processing traffic in a Collector Group by 50%.
- D. The maximum number of Log Collectors in a Log Collector Group is 18 plus two hot spares.
正解:D
解説:
The maximum number of Log Collectors that can be added to a Log Collector Group is 18 plus 2 hot spares, ensuring redundancy and availability in case of failure. This allows for a total of up to
20 Log Collectors in a group, providing sufficient scalability and reliability for log collection.
質問 # 86
When deploying Palo Alto Networks NGFWs in a cloud service provider (CSP) environment, which method ensures high availability (HA) across multiple availability zones?
- A. Implementing Terraform templates for redundancy within one availability zone
- B. Using load balancer and health probes
- C. Deploying Ansible scripts for zone-specific scaling
- D. Configuring active/active HA
正解:B
解説:
To ensure high availability (HA) across multiple availability zones (AZs) in a cloud service provider (CSP) environment, using a load balancer with health probes is a recommended method. This setup ensures that traffic can be directed to the healthy NGFW instances across multiple availability zones. If one NGFW instance or availability zone goes down, the load balancer can redirect traffic to the available instance(s) in other zones, providing redundancy and maintaining service availability.
質問 # 87
A network engineer observes that after a primary link recovers, the firewall immediately switches traffic back from the backup static route to the primary static route. The engineer checks the path monitoring configuration for the primary route.
Which value is configured for the preemptive hold time to cause this behavior?
- A. 0
- B. Lowest possible value greater than 0
- C. Feature disabled
- D. Default value
正解:A
解説:
A preemptive hold time of 0 causes the firewall to immediately switch traffic back to the primary static route as soon as the monitored path is restored, resulting in instant failback without any delay.
質問 # 88
Which two zone types are valid when configuring a new security zone? (Choose two.)
- A. Internal
- B. Virtual Wire
- C. Intrazone
- D. Tunnel
正解:B、D
解説:
When configuring a new security zone on a Palo Alto Networks firewall, the two valid zone types are:
Tunnel: A Tunnel zone is used for traffic that is associated with a VPN tunnel, such as IPSec tunnels. Traffic passing through a tunnel interface is classified into this zone.
Virtual Wire: A Virtual Wire zone is used when a firewall operates in transparent mode (also known as Layer
2 mode). In this configuration, the firewall can inspect traffic without modifying the IP address structure of the network.
質問 # 89
In regard to the Advanced Routing Engine (ARE), what must be enabled first when configuring a logical router on a PAN-OS firewall?
- A. Content update
- B. Plugin
- C. License
- D. General setting
正解:D
解説:
Basic Concept: Before logical routers can be configured, PAN-OS must be switched from the legacy virtual router model to the Advanced Routing Engine through the firewall's general routing setting.
Why D is Correct: The General setting is correct because enabling advanced routing is the prerequisite that exposes logical router configuration; it is not activated by a license, plugin, or content package.
Why A is Wrong: Advanced Routing Engine is not enabled by adding a license alone. Licensing may affect platform features, but logical routers require the routing engine setting.
Why B is Wrong: Plugins extend integrations such as SD-WAN, but they do not enable the base Advanced Routing Engine.
Why C is Wrong: Content updates deliver application, threat, and signature data. They do not activate logical router support.
質問 # 90
What is the function of a Certificate Revocation List (CRL) in a PKI?
- A. Lists certificates that have been revoked before their expiration date
- B. Lists certificates pending renewal
- C. Lists expired certificates
- D. Lists all issued certificates
正解:A
質問 # 91
Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?
- A. Set "Enable in HA Passive State."
- B. Set passive link state to "Auto."
- C. Set LACP mode to "Active."
- D. Set Transmission Rate to "fast."
正解:A
解説:
In a High Availability (HA) active/passive pair configuration, when setting up an Aggregate Ethernet (AE) interface, enabling the "Enable in HA Passive State" option allows the interface to participate in LACP (Link Aggregation Control Protocol) even when the system is in the passive state. This ensures that the pre-negotiation of the LACP link occurs, allowing the link aggregation to be ready as soon as the firewall becomes active.
質問 # 92
How does a Palo Alto Networks firewall choose the best route when it receives routes for the same destination from different routing protocols?
- A. The route that was received first will be entered into the forwarding table, and all subsequent routes will be rejected.
- B. It compares the administrative distance and chooses the one with the highest value.
- C. It will attempt to load balance the traffic across all routes.
- D. It compares the administrative distance and chooses the one with the lowest value.
正解:D
解説:
When a Palo Alto Networks firewall receives routes for the same destination from different routing protocols, it uses the administrative distance (AD) to determine the best route. The administrative distance is a measure of the trustworthiness of a route, with a lower value indicating higher preference. The firewall will choose the route with the lowest administrative distance to populate its forwarding table.
質問 # 93
Which PAN-OS method of mapping users to IP addresses is the most reliable?
- A. Port mapping
- B. Server monitoring
- C. GlobalProtect
- D. Syslog
正解:C
解説:
Basic Concept: User-ID depends on accurate user-to-IP mappings. Mappings are most reliable when users authenticate directly through a firewall-controlled mechanism rather than being inferred from logs.
Why B is Correct: GlobalProtect is the most reliable listed method because it authenticates the user/device and creates a direct, current mapping that follows the endpoint across network changes.
Why A is Wrong: Port mapping is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why C is Wrong: Syslog is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
Why D is Wrong: Server monitoring is a valid Palo Alto Networks or networking concept in another context, but it does not implement the exact configuration outcome required by this question.
質問 # 94
A security engineer creates a policy allowing only members of the Finance?Active Directory group to access a cloud-based accounting application.
Which NGFW capability makes this policy possible?
- A. NAT policy
- B. High availability clustering
- C. Dynamic routing protocols
- D. User-ID / identity integration
正解:D
解説:
User-ID integration maps IP addresses to authenticated users or groups, allowing identity-based security policies.
質問 # 95
Why is SSL/TLS decryption considered critical for effective NGFW security inspection in modern networks?
- A. It simplifies firewall rule design
- B. It reduces network latency
- C. It eliminates the need for IPS
- D. It enables inspection of encrypted application traffic
正解:D
解説:
Most modern traffic is encrypted.
SSL/TLS decryption allows NGFWs to inspect traffic content and detect threats hidden within encrypted sessions.
質問 # 96
......
Palo Alto Networks NGFW-Engineer 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
NGFW-Engineer時間限定!無料アクセス:https://jp.fast2test.com/NGFW-Engineer-premium-file.html
NGFW-Engineer認定有効な試験問題集と解答学習ガイド:https://drive.google.com/open?id=11P4wdlPJpMYcsC42ghWz4D2pl1IbF_GR