[2024] Pass Palo Alto Networks PCNSE Exam Updated 125 Questions [Q67-Q87]

Share

[2024] Pass Palo Alto Networks PCNSE Exam Updated 125 Questions

Get 2024 Updated Free Palo Alto Networks PCNSE Exam Questions and Answer

NEW QUESTION # 67
At which stage of the cyber-attack lifecycle would the attacker attach an infected PDF file to an email?

  • A. reconnaissance
  • B. IP command and control
  • C. exploitation
  • D. delivery

Answer: A


NEW QUESTION # 68
Which Panorama administrator types require the configuration of at least one access domain?
(Choose two)

  • A. Dynamic
  • B. Role Based
  • C. Device Group
  • D. Custom Panorama Admin
  • E. Template Admin

Answer: C,E


NEW QUESTION # 69
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs.
The administrator assigns priority 100 to the active firewall.
Which priority is correct for the passive firewall?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
Reference:
https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/framemaker/71/pan-os/pan-os/section_5.p (page 9)
https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/pan-os/10-0/pan-os-admin/pan-os-admin.pd page 315


NEW QUESTION # 70
What can an engineer use with GlobalProtect to distribute user-specific client certificates to each GlobalProtect user?

  • A. SSL/TLS Service profile
  • B. Certificate profile
  • C. SCEP
  • D. OCSP Responder

Answer: C


NEW QUESTION # 71
An administrator logs in to the Palo Alto Networks NGFW and reports that the WebUI is missing the Policies tab. Which profile is the cause of the missing Policies tab?

  • A. Authentication
  • B. Authorization
  • C. Admin Role
  • D. WebUI

Answer: C


NEW QUESTION # 72
Refer to the exhibit.

An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)

  • A. Untrust (Any) to Untrust (10.1.1.100), web-browsing -Allow
  • B. Untrust (Any) to DMZ (10.1.1.100), ssh -Allow
  • C. Untrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow
  • D. Untrust (Any) to DMZ (10.1.1.100), web-browsing -Allow
  • E. Untrust (Any) to Untrust (10.1.1.101), ssh -Allow

Answer: B,D


NEW QUESTION # 73
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also
creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are
three entries. The first entry shows traffic dropped as application Unknown. The next two entries show
traffic allowed as application SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as
SSL?

  • A. Disable the exclude cache option for the firewall.
  • B. Create a decryption rule matching the encrypted BitTorrent traffic with action "No-Decrypt," and place
    the rule at the top of the Decryption policy.
  • C. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the
    decryption rule.
  • D. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the
    top of the Security policy.

Answer: D


NEW QUESTION # 74
A variable name must start with which symbol?

  • A. $
  • B. &
  • C. #
  • D. !

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/manage-templates-and-temp


NEW QUESTION # 75
Which log file can be used to identify SSL decryption failures?

  • A. Traffic
  • B. ACC
  • C. Threats
  • D. Configuration

Answer: A

Explanation:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClboCAC


NEW QUESTION # 76
A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server.
Which solution in PAN-OSĀ® software would help in this case?

  • A. application override
  • B. content inspection
  • C. redistribution of user mappings
  • D. Virtual Wire mode

Answer: C

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/deploy-user-id-in-a-large-scale-network


NEW QUESTION # 77
An administrator has users accessing network resources through Citrix XenApp 7 x. Which User-ID mapping solution will map multiple users who are using Citrix to connect to the network and access resources?

  • A. Terminal Services agent
  • B. Client Probing
  • C. GlobalProtect
  • D. Syslog Monitoring

Answer: C


NEW QUESTION # 78
What is the purpose of the firewall decryption broker?

  • A. Inspection traffic within IPsec tunnel
  • B. Decrypt SSL traffic a then send it as cleartext to a security chain of inspection tools
  • C. Reduce SSL traffic to a weaker cipher before sending it to a security chain of inspection tools
  • D. Force decryption of previously unknown cipher suites

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/decryption-features/decryption-broker


NEW QUESTION # 79
Which Panorama objects restrict administrative access to specific device-groups?

  • A. access domains
  • B. templates
  • C. admin roles
  • D. authentication profiles

Answer: A

Explanation:
Access domains control administrative access to specific Device Groups and templates, and also control the ability to switch context to the web interface of managed firewalls. https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/role-based-access-control/access-domains.html


NEW QUESTION # 80
After configuring HA in Active/Passive mode on a pair of firewalls the administrator gets a failed commit with the following details.

What are two explanations for this type of issue? (Choose two)

  • A. The peer IP is not included in the permit list on Management Interface Settings
  • B. One of the firewalls has gone into the suspended state
  • C. Either management or a data-plane interface is used as HA1-backup
  • D. The Backup Peer HA1 IP Address was not configured when the commit was issued

Answer: C,D

Explanation:
Cause The issue is seen when the HA1-backup is configured with either management (MGT) or an in-band interface. The "Backup Peer HA1 IP Address" is not configured : https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UmPCAU&lang=en_US%E2%80%A9


NEW QUESTION # 81
An engineer is creating a template and wants to use variables to standardize the configuration across a large number of devices Which Mo variable types can be defined? (Choose two.)

  • A. Zone
  • B. IP netmask
  • C. FQDN
  • D. Path group

Answer: B,C


NEW QUESTION # 82
A network security engineer has applied a File Blocking profile to a rule with the action of Block.
The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system.
Where is the best place to validate if the firewall is blocking the user's TAR file?

  • A. WildFire Submissions log
  • B. Data Filtering log
  • C. Threat log
  • D. URL Filtering log

Answer: B

Explanation:
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZ1CAK


NEW QUESTION # 83
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the System logs and look for the error messages about BGP.
  • B. Perform a traffic pcap on the NGFW to see any BGP problems.
  • C. View the ACC tab to isolate routing issues.
  • D. View the Runtime Stats and look for problems with BGP configuration.

Answer: C,D


NEW QUESTION # 84
Which command can be used to validate a Captive Portal policy?

  • A. debug cp-policy <criteria>
  • B. request cp-policy-eval <criteria>
  • C. test authentication-policy-match <criteria>
  • D. eval captive-portal policy <criteria>

Answer: C

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-cli-quick-start/use-the-cli/test-the- configuration/test-policy-matches


NEW QUESTION # 85
Review the images. A firewall policy that permits web traffic includes the What is the result of traffic that matches the "Alert - Threats" Profile Match List?

  • A. The source address of traffic that matches a threat is automatically tagged as BadGuys for 180 minutes.
  • B. The source address of SMTP traffic that matches a threat is automatically blocked as BadGuys for 180 minutes.
  • C. The source address of traffic that matches a threat is automatically blocked as BadGuys for 180 minutes.
  • D. The source address of SMTP traffic that matches a threat is automatically tagged as BadGuys for 180 minutes.

Answer: D


NEW QUESTION # 86
A firewall should be advertising the static route 10 2 0 0/24 into OSPF The configuration on the neighbor is correct but the route is not in the neighbor's routing table Which two configurations should you check on the firewall'? (Choose two )

  • A. In the OSFP configuration ensure that the correct redistribution profile is selected in the OSPF Export Rules section
  • B. Ensure that the OSPF neighbor state is "2-Way"
  • C. Within the redistribution profile ensure that Redist is selected
  • D. In the redistribution profile check that the source type is set to "ospf"

Answer: A,C

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/network/network-virtual-routers/ospf/ospf-export-rules-tab
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGTCA0


NEW QUESTION # 87
......

Verified PCNSE exam dumps Q&As with Correct 125 Questions and Answers: https://www.2pass4sure.com/PCNSE-PAN-OS/PCNSE-actual-exam-braindumps.html

PCNSE Dumps PDF and Test Engine Exam Questions: https://drive.google.com/open?id=11Z4QfX5dvx3eYwRZ2fx-gCUCCu8dlrUr