An engineer is troubleshooting traffic routing through the virtual router. The firewall uses multiple routing protocols, and the engineer is trying to determine routing priority Match the default Administrative Distances for each routing protocol.

2. An engineer must configure the Decryption Broker feature. To which router must the engineer assign the decryption forwarding interfaces that are used in Decryption Broker security chain?

3. Which time determines how long the passive firewall will wait before taking over as the active firewall alter losing communications with the HA peer?

4. What can you use with Global Protect to assign user-specific client certificates to each GlobalProtect user?

5. A user at an internal system queries the DNS server for their web server with a private IP of 10 250 241 131 in the. The DNS server returns an address of the web server's public address,

In order to reach the web server, which security rule and U-Turn NAT rule must be configured on the firewall?





6. Refer to the exhibit.

Review the screenshots and consider the following information:

• FW-1 is assigned to the FW-1_DG device group, and FW-2 is assigned to OFFICE_FW_DG.

• There are no objects configured in REGIONAL_DG and OFFICE_FW_DG device groups.

Which IP address will be pushed to the firewalls inside Address Object Server-1?

7. Which CLI command is used to determine how much disk space is allocated to logs?

8. Which log type will help the engineer verify whether packet buffer protection was activated?

9. Which profile generates a packet threat type found in threat logs?

10. What happens, by default, when the GlobalProtect app fails to establish an IPSec tunnel to the GlobalProtect gateway?



