All certifications / NGFW Engineer / Cheat sheet
NGFW Engineer NGFW-Engineer cheat sheet
Domain 1: PAN-OS networking configuration (38%)
Exam tips
- If a question says the firewall must be added 'with no network changes' or 'without IP addresses', the answer is virtual wire. If it must only observe and never block, it is tap. Routing, NAT and VPN termination require Layer 3.
- Remember the defaults: intrazone allowed, interzone denied, neither logged. When a question asks why denied traffic does not appear in the Traffic log, the answer is that interzone-default must be overridden to enable logging.
- Zone protection attaches to the ingress zone, not the destination. If a question asks why an interface will not answer ping or show a block page, look for a missing interface management profile or a missing Response Pages option.
- Memorize the PAN-OS AD defaults, especially OSPF internal 30 and iBGP 200, and remember that longest prefix match beats AD. Logical router always implies the Advanced Routing Engine.
- PBF is evaluated before routing, but app-based PBF only applies after the app is in the application cache, so the first session uses the routing table. Service routes are for firewall-originated traffic, not user traffic.
- Security rules use pre-NAT addresses and the post-NAT zone. NAT rules use pre-NAT addresses and the zone found by routing the pre-NAT destination. Almost every NAT exam question turns on this.
- Lower priority number wins, and preemption must be on for both peers. Active/active supports only Layer 3 and virtual wire. HA3 appears only in active/active questions.
- Phase 1 up but phase 2 down with a policy-based peer almost always means proxy IDs. Remember the tunnel interface needs a zone and router, and traffic still needs security rules and a route.
- PPKs mean IKEv2 only and must match on both peers. GRE is not encryption; if a question needs confidentiality over the Internet, GRE alone is the wrong answer.
- Portal configures, gateway enforces. Pre-logon uses machine certificates before user login. IPsec is preferred, SSL is the fallback. HIP objects are criteria; HIP profiles are what security rules reference.
Key terms
- Virtual wire
- A pair of interfaces bound together so the firewall inspects traffic transparently with no IP addresses, routing or switching.
- Tap interface
- An interface fed by a switch SPAN or mirror port that gives visibility and logging but cannot enforce or block.
- Aggregate Ethernet (AE)
- A logical interface bundling several same-speed physical ports, optionally negotiated with LACP, for bandwidth and redundancy.
- LACP
- Link Aggregation Control Protocol, which negotiates an aggregate bundle with the peer and removes failed or misconnected members.
- Subinterface
- A logical interface on a parent port that handles one 802.1Q VLAN tag, with its own zone and addressing.
- Tunnel interface
- A logical Layer 3 interface used as the endpoint of a route-based IPsec, GRE or GlobalProtect tunnel.
- Loopback interface
- An always-up logical Layer 3 interface used for services such as management, DNS proxy or a GlobalProtect portal.
- VLAN interface
- A Layer 3 interface attached to a Layer 2 VLAN so its hosts can be routed to other networks.
- Security zone
- A logical group of interfaces with the same trust level that security and NAT policy reference.
- intrazone-default
- The predefined rule that allows traffic whose source and destination zone are the same; not logged by default.
- interzone-default
- The predefined rule that denies traffic between different zones; not logged by default.
- External zone
- A zone type used on multi-vsys firewalls to represent another virtual system for inter-vsys traffic.
- Tunnel zone
- A zone type used with tunnel content inspection so policy can apply to traffic inside a cleartext tunnel.
- Enable User Identification
- A per-zone setting that tells the firewall to map IP addresses in that zone to usernames.
- Rule override
- Changing the settings, such as logging or profiles, of a predefined default rule, which cannot be deleted.
- Zone protection profile
- A profile applied to an ingress zone that defends against floods, reconnaissance and malformed packets before policy lookup.
- SYN cookies
- A SYN flood defense where the firewall completes the handshake on the server's behalf and forwards only validated connections.
- Random Early Drop (RED)
- A flood defense that drops a growing share of packets once the Activate threshold is exceeded.
- Reconnaissance protection
- Zone protection settings that detect port scans and host sweeps and can alert, block or block the source IP.
- DoS protection policy
- Rules with DoS profiles that protect specific hosts using classified or aggregate thresholds.
- Interface management profile
- A profile that controls which management and response services (ping, SSH, HTTPS, response pages and more) a data interface accepts.
- Virtual router
- The legacy PAN-OS routing instance holding interfaces, static routes and dynamic protocols with its own routing table.
- Logical router
- The routing instance used when the Advanced Routing Engine is enabled, configured with reusable routing profiles and route maps.
- Administrative distance
- A preference value for route sources; lower wins when prefixes are equal length. PAN-OS defaults include static 10 and OSPF internal 30.
- Floating static route
- A static route given a higher administrative distance so it is used only when the preferred dynamic route disappears.
- ECMP
- Equal-cost multipath: installing multiple equal routes to a destination and balancing sessions across them.
- RIB and FIB
- The routing information base holds all learned routes; the forwarding information base holds the best routes actually used to forward.
- Policy-based forwarding (PBF)
- Rules that forward matching traffic by criteria like source, user or application instead of the routing table.
- Application cache
- The record of App-ID results by destination that lets later sessions of an application match app-based PBF rules.
- Symmetric return
- A PBF option that sends replies back out the same interface and next hop on which the original traffic arrived.
- Service route
- A setting that makes a management-plane service such as DNS, updates or syslog source its traffic from a data interface instead of MGT.
- DHCP relay
- A firewall interface role that forwards client DHCP broadcasts to a DHCP server on another network.
- DNS proxy
- A firewall feature that answers client DNS queries, forwards them to chosen servers per domain and caches the results.
- DIPP
- Dynamic IP and Port source NAT: many hosts share one or a few addresses with source port translation.
- Dynamic IP NAT
- Source NAT that maps each host one-to-one to a free pool address without port translation; the pool can be exhausted.
- Static IP NAT
- A fixed one-to-one address translation that can be made bi-directional to allow inbound connections.
- Destination NAT
- Translation of the destination address, and optionally port, usually to publish an internal server.
- U-turn NAT
- NAT that lets internal clients reach an internal server via its public IP by translating destination and source so traffic returns through the firewall.
- Post-NAT zone
- The zone where the translated destination actually lives, used as the destination zone in security rules.
- HA1
- The HA control link carrying hellos, heartbeats, state and configuration synchronization.
- HA2
- The HA data link that synchronizes sessions, forwarding tables, IPsec SAs and ARP tables.
- HA3
- The active/active-only link that forwards packets between peers for session setup and asymmetric flows.
- Preemption
- The option that lets the higher-priority (lower number) peer reclaim the active role; must be enabled on both peers.
- Split brain
- A failure where both peers believe they should be active, usually because the only HA1 link failed.
- Link group
- A set of monitored interfaces whose failure condition (any or all) triggers failover.
- Floating IP
- An active/active address bound to one peer that moves to the other peer on failure.
- IKE gateway
- The object defining the VPN peer, local interface, IKE version, authentication and IKE crypto profile for phase 1.
- IKE crypto profile
- Phase 1 settings: Diffie-Hellman group, encryption, authentication and key lifetime.
- IPsec crypto profile
- Phase 2 settings: ESP or AH, encryption, authentication, PFS DH group and lifetime.
- Proxy ID
- A local/remote subnet pair that defines a phase 2 SA, required when the peer uses a policy-based VPN.
- Tunnel monitoring
- Pings through the tunnel to a remote IP that detect a broken data path and trigger wait-recover or fail-over.
- Perfect forward secrecy (PFS)
- A fresh Diffie-Hellman exchange for phase 2 keys so one compromised key does not expose other sessions.
- Post-quantum preshared key (PPK)
- An extra shared secret mixed into IKEv2 key derivation (RFC 8784) so session keys resist future quantum attacks on Diffie-Hellman.
- Harvest now, decrypt later
- The threat of recording encrypted traffic today to decrypt it once quantum computers can break the key exchange.
- Hybrid key exchange
- Combining a classical and a post-quantum key exchange so the result is at least as strong as the stronger one.
- Key encapsulation mechanism (KEM)
- A public key method for establishing a shared secret, the form most post-quantum key exchange algorithms take.
- GRE
- Generic Routing Encapsulation, an unencrypted tunneling protocol (IP protocol 47) that encapsulates packets in a new IP header.
- GRE keepalive
- A periodic check that marks a GRE tunnel down when the peer stops responding so routing can react.
- Portal
- The GlobalProtect component that authenticates the app and delivers its configuration and gateway list.
- External gateway
- A gateway that terminates tunnels from remote users over the Internet and enforces policy on their traffic.
- Internal gateway
- A gateway inside the network used for User-ID and HIP enforcement, often without a tunnel.
- Internal host detection
- A reverse DNS check of a known internal IP that tells the app whether it is on the corporate network.
- Pre-logon
- A connect method that establishes the tunnel with a machine certificate before the user signs in.
- Split tunneling
- Sending only chosen routes, domains or applications through the tunnel while other traffic goes directly to the Internet.
- HIP profile
- A combination of HIP objects evaluated as a match condition in security policy.
Domain 2: PAN-OS device setting configuration (38%)
Exam tips
- Dynamic roles update automatically, custom admin role profiles do not. If a question mentions granular control, API-only access, or disabling CLI, the answer is an admin role profile.
- Server profile = where; authentication profile = how and who; sequence = try several in order. SAML is configured by importing IdP metadata. RADIUS and SAML IdPs commonly provide MFA.
- Redirect mode needs a Layer 3 interface with Response Pages in its management profile; transparent mode suits vwire and Layer 2. HTTPS triggers require decryption. Authentication policy identifies; security policy still decides allow or deny.
- Inter-vsys traffic needs an external zone and a security rule in each vsys. Shared gateways do NAT and routing but no security policy. An interface and a zone always belong to exactly one vsys.
- Traffic, Threat, URL, WildFire and Data logs are forwarded with a log forwarding profile on security rules; System and Configuration logs use Device > Log Settings. Traffic logs default to session end only.
- Base image first, content before software, Panorama before firewalls, passive peer before active. Thresholds delay content installation to reduce risk from a bad release.
- Forward Trust must be trusted by clients; Forward Untrust must not be. Inbound inspection uses the server's real key, forward proxy uses impersonation. Service profiles protect the firewall's own services; certificate profiles validate others' certificates.
- Pinned apps and mutual TLS need technical exclusions; privacy categories use No Decrypt rules. Attach a decryption profile to No Decrypt rules so certificate checks still happen.
- Server monitoring reads DC security logs; syslog listeners parse third-party messages; GlobalProtect is best for remote users; XML API is for scripts. Group mapping needs LDAP or the Cloud Identity Engine.
- Loading or reverting a snapshot changes only the candidate; you still need to commit. Permitted IPs on the MGT interface are the main control over who can reach management.
- Explicit means clients are configured (PAC file or settings) and can be challenged for authentication; transparent means no client changes. The feature depends on platform and release, and HTTPS content inspection still needs decryption.
Key terms
- Dynamic role
- A built-in admin role such as Superuser or Device Administrator that is updated automatically with new features.
- Admin role profile
- A custom role defining per-area web UI, XML API, REST API and CLI permissions; must be maintained manually after upgrades.
- Device Administrator
- A dynamic role with full firewall access except creating administrator accounts and virtual systems.
- superreader
- A CLI role level that allows read-only access to the full CLI.
- Vsys administrator
- A role restricted to managing specific virtual systems on a multi-vsys firewall.
- Vendor-specific attribute (VSA)
- A value returned by RADIUS, TACACS+ or SAML that assigns an admin role or access domain without a local account.
- Config log
- The log that records configuration changes, including which administrator made them.
- Server profile
- Connection settings for an external service such as LDAP, RADIUS, TACACS+, SAML IdP or Kerberos KDC.
- Authentication profile
- A profile that selects the authentication method and server, username format, allow list, lockout and MFA factors.
- Authentication sequence
- An ordered list of authentication profiles tried one after another until one succeeds.
- TACACS+
- A device administration AAA protocol that runs over TCP and encrypts the entire payload.
- SAML IdP metadata
- The identity provider's details, including signing certificate and SSO URL, imported to build a SAML server profile.
- Allow list
- The users or groups in an authentication profile that are permitted to authenticate with it.
- Multi-factor authentication (MFA)
- Requiring more than one type of proof, such as a password plus a push approval or token code.
- Authentication policy
- A rulebase that decides which traffic must authenticate, how, and for how long before security policy applies to it.
- Authentication enforcement object
- The rule action choosing browser-challenge, web-form or no-captive-portal and an authentication profile.
- Browser-challenge
- An enforcement method using Kerberos SPNEGO so domain browsers authenticate without a prompt.
- Redirect mode
- Authentication Portal mode that redirects users to a firewall Layer 3 interface, supporting session cookies and Kerberos SSO.
- Transparent mode
- Authentication Portal mode where the firewall impersonates the destination site to present the challenge.
- Authentication timeout
- How long a user stays authenticated for an authentication rule before being challenged again.
- Virtual system (vsys)
- A logical firewall inside one physical firewall with its own interfaces, zones, policies and admins.
- Shared gateway
- A virtual system that lets multiple vsys share external interfaces; it supports NAT and PBF but has no security policy.
- External zone
- A zone type pointing at another vsys, used to pass traffic between virtual systems.
- Multi Virtual System Capability
- The device setting that enables creating additional vsys, subject to platform support and licensing.
- Shared location
- The configuration scope whose objects and policies are available to every vsys.
- Target vsys
- The CLI setting that scopes commands to a particular virtual system.
- Traffic log
- A per-session record written by default at session end for sessions matching rules with logging enabled.
- Log forwarding profile
- An object attached to security rules that sends matching policy logs to Panorama, cloud logging, syslog, SNMP, email or HTTP.
- Device > Log Settings
- Where System, Configuration, User-ID, HIP Match and other non-policy logs are forwarded.
- Syslog server profile
- Settings for syslog destinations, including transport, port, format, facility and custom message formats.
- HTTP server profile
- A server profile that sends logs to web services with customizable URI, headers and payload.
- Strata Logging Service
- Palo Alto's cloud log storage service (formerly Cortex Data Lake) used by cloud management and analytics apps.
- Feature release
- A PAN-OS version that introduces new capabilities, such as 11.1, identified by its first two numbers.
- Base image
- The .0 image of a feature release, which must be downloaded before installing a maintenance release of that feature release.
- Maintenance release
- A bug-fix release within a PAN-OS feature release, such as a later 11.1.x build.
- Applications and Threats
- The content package containing App-ID definitions and vulnerability and spyware signatures.
- Threshold
- A dynamic update setting that waits a set number of hours after release before installing new content.
- Device state
- An export of the firewall's configuration and related files used to restore or replace a device.
- Certificate authority (CA)
- An entity that signs certificates; endpoints trust certificates signed by CAs in their trust store.
- Forward Trust certificate
- The CA certificate the firewall uses to sign impersonated server certificates when the real server certificate is trusted.
- Forward Untrust certificate
- An untrusted CA certificate used to sign impersonated certificates for sites with invalid certificates, so users see a warning.
- SSL Inbound Inspection
- Decryption of traffic to your own servers using their imported certificate and private key.
- SSL/TLS service profile
- Settings for the certificate and TLS versions used by services the firewall hosts, such as the web interface and portal.
- Certificate profile
- Settings for validating client or peer certificates: trusted CAs, username field and OCSP/CRL checks.
- OCSP
- Online Certificate Status Protocol, a real-time query to a responder about a certificate's revocation status.
- Certificate pinning
- An app accepting only a specific certificate or CA for its server, which breaks when a firewall substitutes its own certificate.
- Mutual TLS
- TLS where the client also presents a certificate; a forward proxy cannot present the client's certificate, so it cannot decrypt the session.
- SSL Decryption Exclusion list
- The predefined and custom list of hostnames the firewall never decrypts, found under Certificate Management.
- No Decrypt rule
- A decryption policy rule that leaves matching traffic encrypted, often for sensitive URL categories.
- Decryption profile
- Settings that validate certificates and protocols for decrypted and non-decrypted sessions.
- Decryption log
- The log that records decryption sessions and failures, with reasons, used to find apps needing exclusions.
- Server monitoring
- User-ID collection of logon events from domain controllers, Exchange or eDirectory by the integrated or Windows User-ID agent.
- Syslog parse profile
- Regex or field rules that extract username and IP address from third-party syslog messages.
- Terminal server agent
- A User-ID component that maps users on shared multi-user hosts by source port range.
- Group mapping
- Retrieving directory group membership, usually via LDAP, so policy can reference groups.
- Group include list
- The set of directory groups the firewall retrieves for use in policy.
- Cloud Identity Engine
- A Palo Alto cloud service that syncs users and groups from directories and IdPs and provides cloud authentication.
- Management plane
- The part of the firewall that runs the web interface, CLI, logging and configuration, separate from traffic processing.
- Permitted IP Addresses
- A list on the MGT interface or an interface management profile limiting which hosts can reach management services.
- Candidate configuration
- The editable copy of the configuration that takes effect only after a commit.
- Running configuration
- The configuration the firewall is currently enforcing.
- Partial commit
- A commit of only selected changes, such as those made by specific administrators.
- Config lock
- A lock preventing other administrators from changing the candidate configuration.
- Named snapshot
- A saved, named copy of the configuration that can later be loaded into the candidate.
- Explicit proxy
- A proxy that clients are configured to use, directly or via a PAC file, sending requests to its IP and port.
- Transparent proxy
- A proxy that intercepts web traffic in the path without any client configuration.
- PAC file
- A proxy auto-config script that tells browsers which proxy to use for which destinations.
- HTTP CONNECT
- The method an explicit proxy client uses to ask the proxy to open a tunnel to an HTTPS destination.
- Proxy authentication
- Challenging a client that talks to an explicit proxy to prove its identity, commonly with Kerberos or SAML.
- DNS proxy object
- The firewall DNS proxy configuration that the web proxy uses to resolve destination names.
Domain 3: Integration and automation (24%)
Exam tips
- Device groups = policy and objects; templates = Network and Device tabs. Pre-rules come before local rules and cannot be overridden locally. In a stack, the higher template wins.
- Commit to Panorama is not enough; you must also push. Panorama must be on the same or newer release than its firewalls, so it is always upgraded first. Log Collector mode has no management web UI.
- Know the XML request types: keygen, config (with actions like get, show, set, edit, delete), op and commit. REST uses versioned URLs and JSON; commit is an XML API function. API-only accounts come from admin role profiles, not dynamic roles.
- Terraform is declarative and state-based, Ansible runs ordered idempotent tasks, pan-os-python is the Python SDK the Ansible collection builds on. All of them change the candidate configuration, so a commit is still required.
- IP lists go in rules, domain lists go in anti-spyware DNS policies, URL lists go in URL filtering or rule URL categories. EDL and DAG changes take effect without a commit.
- The chain is: log forwarding profile filter, then tagging action, then DAG matching the tag, then a security rule using the DAG. HTTP server profiles send logs to webhooks for tickets and chat.
- Know the five folders: config, license, software, content, plugins. init-cfg.txt handles bootstrap basics and Panorama registration; bootstrap.xml is optional full config. Bootstrapping only runs from factory default.
- Managed service with no instances to operate means Cloud NGFW. Kubernetes east-west inspection means CN-Series. Full control of a virtual firewall on any hypervisor or cloud means VM-Series.
- Map concepts: Panorama device groups and templates correspond to SCM folders and snippets. SCM is cloud-hosted and uses Strata Logging Service; Panorama is customer-hosted and suits on-premises or isolated environments.
Key terms
- Device group
- A Panorama container of firewalls sharing policies and objects, arranged in a hierarchy under Shared.
- Shared location
- The top of the device group hierarchy, whose objects and rules are inherited by every device group.
- Pre-rules / post-rules
- Panorama rules evaluated before, or after, a firewall's local rules.
- Template
- Panorama configuration for the firewall's Network and Device tab settings, such as interfaces, zones and server profiles.
- Template stack
- An ordered combination of templates assigned to firewalls; higher templates win when settings conflict.
- Template variable
- A placeholder such as $dns-primary in a template whose value is set per firewall.
- Override
- A local firewall value that replaces a template-pushed value until the override is reverted.
- Commit to Panorama
- Makes changes part of Panorama's running configuration without sending them to firewalls.
- Push to Devices
- Sends device group, template or collector group configuration from Panorama to managed devices.
- Commit and Push
- A single action that commits to Panorama and then pushes to the selected devices.
- Panorama mode
- The mode in which Panorama both manages devices and stores logs with its local Log Collector.
- Management Only mode
- Panorama mode that manages devices but stores no firewall logs locally.
- Log Collector mode
- Mode that makes an appliance a dedicated log collector managed by another Panorama.
- Collector group
- A set of Log Collectors that share log storage for redundancy and scale.
- keygen
- The XML API request type that returns an API key for a username and password.
- XPath
- The path syntax the XML API uses to address a node in the configuration tree.
- set vs edit
- XML API config actions: set adds or merges at the xpath, edit replaces the node at the xpath.
- type=op
- The XML API request type for running operational (non-configuration) commands expressed as XML.
- REST API
- The JSON-based PAN-OS API using versioned resource URLs and standard HTTP methods.
- API-only role
- An admin role profile with web UI and CLI disabled and only needed API permissions enabled.
- API key lifetime
- A device setting that makes API keys expire after a set period.
- Infrastructure as code (IaC)
- Managing configuration through version-controlled text files applied by tools rather than manual changes.
- Declarative
- Describing the desired end state and letting the tool compute the changes, as Terraform does.
- Terraform state
- The file where Terraform records the resources it manages and their current values.
- Idempotent
- Producing the same result no matter how many times an operation runs, a design goal of Ansible modules.
- paloaltonetworks.panos
- The Ansible collection of modules for managing PAN-OS firewalls and Panorama.
- pan-os-python
- Palo Alto's Python SDK that models firewall and Panorama configuration as an object tree.
- External dynamic list (EDL)
- A web-hosted list of IPs, domains or URLs that the firewall retrieves periodically and uses in policy without a commit.
- Check interval
- How often the firewall retrieves an EDL: every five minutes, hourly, daily, weekly or monthly.
- Dynamic address group (DAG)
- An address group whose members are IP addresses registered with tags that match its filter.
- Tag registration
- Associating a tag with an IP address or user at runtime, via the API, VM monitoring, auto-tagging or agents.
- DNS sinkhole
- An anti-spyware action that answers malicious domain queries with a controlled address so infected hosts can be found.
- Dynamic user group
- A group whose membership is users with matching tags, used for user-based quarantine.
- Auto-tagging
- A log forwarding built-in action that adds or removes tags on IPs or users when a matching log is generated.
- Built-in action
- An action inside a log forwarding profile entry, such as tagging, performed when a log matches.
- Tag timeout
- The time after which an auto-applied tag is removed, letting a host leave quarantine automatically.
- Webhook
- An HTTP request sent to another system when an event occurs, used here via an HTTP server profile.
- Payload format
- The per-log-type URI, headers and body template an HTTP server profile uses to build its requests.
- IP-Tag log
- The log that records tags registered to and removed from IP addresses.
- Bootstrap package
- The config, license, software, content and plugins folders a VM-Series firewall reads on first boot.
- init-cfg.txt
- Bootstrap file with basic management, DNS, hostname and Panorama registration settings as key-value pairs.
- bootstrap.xml
- An optional full configuration file loaded during bootstrapping.
- authcodes
- The file in the license folder containing license authorization codes applied at first boot.
- VM auth key
- A key generated on Panorama that lets a bootstrapping VM-Series firewall register with it.
- Zero Touch Provisioning (ZTP)
- A process where supported hardware firewalls automatically connect to their assigned Panorama or cloud manager on first power-up.
- PA-Series
- Palo Alto's physical hardware firewalls with separate management and data plane resources.
- Single-pass architecture
- Processing each packet once for classification and inspection instead of passing it through separate engines.
- VM-Series
- The virtual machine form of PAN-OS for private hypervisors and public clouds, operated by the customer.
- CN-Series
- Containerized firewalls for Kubernetes, with CN-MGMT and CN-NGFW components managed by Panorama.
- Cloud NGFW
- A managed firewall service for AWS and Azure that Palo Alto operates and customers consume as a native cloud resource.
- Rulestack
- The collection of rules and objects used to configure a Cloud NGFW resource.
- Strata Cloud Manager (SCM)
- Palo Alto's cloud-delivered console for managing and monitoring NGFWs and Prisma Access.
- Folder
- An SCM hierarchy container whose configuration is inherited by the folders and devices beneath it.
- Snippet
- A reusable, named set of configuration in SCM that can be applied to folders or devices.
- Strata Logging Service
- The cloud log service that SCM-managed firewalls forward logs to for visibility and reporting.
- Best practice assessment
- An evaluation of configuration against Palo Alto recommendations with scores and remediation advice.
- AIOps
- AI-driven operations features that predict health and capacity problems and flag risky configuration.
Study NGFW Engineer for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the NGFW Engineer study planLessons, quizzes, exam simulations and hands-on labs.