[Feb 03, 2024] Get to the Top with PCNSE Practice Exam Questions [Q47-Q72]

Share

[Feb 03, 2024] Get to the Top with PCNSE Practice Exam Questions

Use Real PCNSE Dumps Free Sample Questions and Practice Test Engine

NEW QUESTION # 47
Which three options does the WF-500 appliance support for local analysis? (Choose three)

  • A. jar files
  • B. APK files
  • C. PNG files
  • D. Portable Executable (PE) files
  • E. E-mail links

Answer: A,D,E

Explanation:


NEW QUESTION # 48
What type of address object would be useful for internal devices where the addressing structure assigns meaning to certain bits in the address, as illustrated in the diagram?

  • A. IP Wildcard Mask
  • B. IP Range
  • C. IP Netmask
  • D. IP Address

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-address-object-to-represent-ip-addresse


NEW QUESTION # 49
The certificate information displayed in the following image is for which type of certificate?
Exhibit:

  • A. Self-Signed Root CA certificate
  • B. Public CA signed certificate
  • C. Web Server certificate
  • D. Forward Trust certificate

Answer: A


NEW QUESTION # 50
What are the differences between using a service versus using an application for Security Policy match?

  • A. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take action after enough packets allow for App-ID identification regardless of the ports being used
  • B. There are no differences between "service" or "application". Use of an "application" simplifies configuration by allowing use of a friendly application name instead of port numbers
  • C. Use of a "service" enables the firewall to take action after enough packets allow for App-ID identification
  • D. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take immediate action if the port being used is a member of the application standard port list.

Answer: A


NEW QUESTION # 51
Which statement regarding HA timer settings is true?

  • A. Use the Critical profile for faster failover timer settings.
  • B. Use the Aggressive profile for slower failover timer settings.
  • C. Use the Moderate profile for typical failover timer settings
  • D. Use the Recommended profile for typical failover timer settings

Answer: D

Explanation:
The Recommended profile is the default profile that provides typical failover timer settings for most deployments. The other profiles are designed for specific scenarios where faster or slower failover is desired. Reference: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-timers


NEW QUESTION # 52
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs.
The administrator assigns priority 100 to the active firewall.
Which priority is correct for the passive firewall?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/framemaker/71/pan-os/ pan-os/section_5.pdf (page 9)


NEW QUESTION # 53
A network administrator troubleshoots a VPN issue and suspects an IKE Crypto mismatch between peers. Where can the administrator find the corresponding logs after running a test command to initiate the VPN?

  • A. Configuration logs
  • B. Traffic logs
  • C. Tunnel Inspection logs
  • D. System logs

Answer: D


NEW QUESTION # 54
Which rule type controls end user SSL traffic to external websites?

  • A. SSH Proxy
  • B. SSL Forward Proxy
  • C. SSL Outbound Proxyless Inspection
  • D. SSL Inbound Inspection

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts/ssl- forward-proxy.html


NEW QUESTION # 55
What are three valid actions in a File Blocking Profile? (Choose three)

  • A. Alret
  • B. Continue
  • C. Forward
  • D. Block
  • E. Upload
  • F. Reset-both

Answer: A,B,D

Explanation:
You can configure a file blocking profile with the following actions:
* Forward - When the specified file type is detected, the file is sent to WildFire for analysis. A log is also generated in the data filtering log.
* Block - When the specified file type is detected, the file is blocked and a customizable block page is presented to the user. A log is also generated in the data filtering log.
* Alert - When the specified file type is detected, a log is generated in the data filtering log.
* Continue - When the specified file type is detected, a customizable response page is presented to the user. The user can click through the page to download the file. A log is also generated in the data filtering log. Because this type of forwarding action requires user interaction, it is only applicable for web traffic.
* Continue-and-forward - When the specified file type is detected, a customizable continuation page is presented to the user. The user can click through the page to download the file. If the user clicks through the continue page to download the file, the file is sent to WildFire for analysis.
A log is also generated in the data filtering log.
https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/file-blocking- profiles.html


NEW QUESTION # 56
Which feature must you configure to prevent users from accidentally submitting their corporate credentials to a phishing website?

  • A. Anti-Spyware profile
  • B. URL Filtering profile
  • C. Zone Protection profile
  • D. Vulnerability Protection profile

Answer: B

Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/prevent- credential-phishing


NEW QUESTION # 57
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.
Which VPN configuration would adapt to changes when deployed to the future site?

  • A. Preconfigured IPsec tunnels
  • B. Preconfigured PPTP Tunnels
  • C. Preconfigured GlobalProtect client
  • D. Preconfigured GlobalProtect satellite

Answer: D


NEW QUESTION # 58
Which three authentication services can administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)

  • A. SAML
  • B. TACACS+
  • C. RADIUS
  • D. PAP
  • E. LDAP
  • F. Kerberos

Answer: A,E,F

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication The administrative accounts are defined on an external SAML, TACACS+, or RADIUS server. The server performs both authentication and authorization. For authorization, you define Vendor-Specific Attributes (VSAs) on the TACACS+ or RADIUS server, or SAML attributes on the SAML server. PAN-OS maps the attributes to administrator roles, access domains, user groups, and virtual systems that you define on the firewall. For details, see:
Configure SAML Authentication Configure TACACS+ Authentication Configure RADIUS Authentication


NEW QUESTION # 59
An administrator is required to create an application-based Security policy rule to allow Evernote. The Evernote application implicitly uses SSL and web browsing. What is the minimum the administrator needs to configure in the Security rule to allow only Evernote?

  • A. Add the Evernote application to the Security policy rule, then add a second Security policy rule containing both HTTP and SSL.
  • B. Create an Application Override using TCP ports 443 and 80.
  • C. Add the HTTP, SSL, and Evernote applications to the same Security policy
  • D. Add only the Evernote application to the Security policy rule.

Answer: D

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/applications-with-implicit-support


NEW QUESTION # 60
An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object should they select?

  • A. default-browser-challenge
  • B. default-no-captive-portal
  • C. default-web-format
  • D. default-authentication-bypass

Answer: B

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/objects/objects-authentication.html


NEW QUESTION # 61
An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object should they select?

  • A. default-browser-challenge
  • B. default-web-form
  • C. default-no-captive-portal
  • D. default-authentication-bypass

Answer: C

Explanation:
Explanation/Reference: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects- authentication


NEW QUESTION # 62
An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing and preemption is disabled.
What must be verified to upgrade the firewalls to the most recent version of PAN-OS software?

  • A. Wildfire update package
  • B. Application and Threats update package
  • C. Anti virus update package
  • D. User-ID agent

Answer: B

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-PAN-OS-Upgrade/ta-p/111045


NEW QUESTION # 63
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet.
Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10.1.1.22

Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?
A)

B)

C)

D)

  • A. Option B
  • B. Option A
  • C. Option D
  • D. Option C

Answer: D


NEW QUESTION # 64
While troubleshooting an SSL Forward Proxy decryption issue which PAN-OS CLI command would you use to check the details of the end-entity certificate that is signed by the Forward Trust Certificate or Forward Untrust Certificate?

  • A. show systen setting ssl-decrypt certificate
  • B. show systea setting ssl-decrypt certificate-cache
  • C. debug dataplane show ssl-decrypt ssl-stats
  • D. show system setting ssl-decrypt certs

Answer: A


NEW QUESTION # 65
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN-OS software. The firewall has internet connectivity through an Ethernet interface, but no internet connectivity from the management interface. The Security policy has the default security rules and a rule that allows all web-browsing traffic from any to any zone. What must the administrator configure so that the PAN-OS software can be upgraded?

  • A. Service route
  • B. Security policy rule
  • C. CRL
  • D. Scheduler

Answer: A


NEW QUESTION # 66
What is considered the best practice with regards to zone protection?

  • A. Review DoS threat activity (ACC > Block Activity) and look for patterns of abuse
  • B. If the levels of zone and DoS protection consume too many firewall resources, disable zone protection
  • C. Set the Alarm Rate threshold for event-log messages to high severity or critical severity
  • D. Use separate log-forwarding profiles to forward DoS and zone threshold event logs separately from other threat logs

Answer: A

Explanation:
Explanation
The best practice with regards to zone protection is to review DoS threat activity (ACC > Block Activity) and look for patterns of abuse. This way, you can identify the sources and types of DoS attacks that target your network zones and adjust your zone protection profiles and policies accordingly1. You can also use the DoS Protection dashboard widget to monitor the number of sessions that match DoS protection policies2. You do not need to use separate log-forwarding profiles to forward DoS and zone threshold event logs separately from other threat logs, as you can use a single log-forwarding profile to forward different types of logs to different destinations3. You should not disable zone protection if the levels of zone and DoS protection consume too many firewall resources, as this would expose your network zones to potential DoS attacks. Instead, you should optimize your zone protection profiles and policies to reduce the resource consumption4. You should not set the Alarm Rate threshold for event-log messages to high severity or critical severity, as this would limit the visibility into DoS attacks that have lower severity levels. Instead, you should set the Alarm Rate threshold to a value that is appropriate for your network environment and traffic patterns. References: 1:
https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices/dos-and-zone-protection
2:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-acc-to-monitor-network-activit
3:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/configure-log-forwarding/log-forwardi
4:
https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices/dos-and-zone-protection
:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/networking/network-profiles/zone-protection-profi


NEW QUESTION # 67
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OSĀ® software, the administrator enables log forwarding from the firewalls to Panoram A.
Pre-existing logs from the firewalls are not appearing in PanoramA.
Which action would enable the firewalls to send their pre-existing logs to Panorama?

  • A. The log database will need to exported form the firewalls and manually imported into Panorama.
  • B. A CLI command will forward the pre-existing logs to Panorama.
  • C. Use the import option to pull logs into Panorama.
  • D. Use the ACC to consolidate pre-existing logs.

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/management-features/pa-7000-series-firewall-log-forwarding-to-panorama


NEW QUESTION # 68
When an in-band data port is set up to provide access to required services, what is required for an interface that is assigned to service routes?

  • A. You must set the interface to Layer 2 Layer 3. or virtual wire
  • B. You must enable DoS and zone protection
  • C. You must use a static IP address
  • D. The interface must be used for traffic to the required services

Answer: C

Explanation:
Explanation
According to the Palo Alto Networks documentation, "To configure a service route, you must specify a source interface and a source address. The source interface can be any data port (Ethernet interface) or a loopback interface. The source address must be a static IP address that is configured on the source interface." References:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/service-routes/service-routes-overview


NEW QUESTION # 69
Which menu item enables a firewall administrator to see details about traffic that is currently active through the NGFW?

  • A. App Scope
  • B. ACC
  • C. Session Browser
  • D. System Logs

Answer: C

Explanation:
Explanation
Session browser. However ACC will show metadata on traffic through the firewall, and you can create some helpful on-the-fly reports, but these will not provide deep detail. Alternatively for more detail you can go to Monitor > Traffic and filter for relevant sessions.


NEW QUESTION # 70
Which three rule types are available when defining policies in Panorama? (Choose three.)

  • A. Pre Rules
  • B. Stealth Rules
  • C. Post Rules
  • D. Clean Up Rules
  • E. Default Rules

Answer: A,C,E

Explanation:
Explanation: https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface- help/panorama-web-interface/defining-policies-on-panorama


NEW QUESTION # 71
A network-security engineer attempted to configure a bootstrap package on Microsoft Azure, but the virtual machine provisioning process failed. In reviewing the bootstrap package, the engineer only had the following directories: /config, /license and /software
Why did the bootstrap process fail for the VM-Series firewall in Azure?

  • A. The /config or /software folders were missing mandatory files to successfully bootstrap
  • B. The VM-Series firewall was not pre-registered in Panorama and prevented the bootstrap process from successfully completing
  • C. All public cloud deployments require the /plugins folder to support proper firewall native integrations
  • D. The /content folder is missing from the bootstrap package

Answer: A


NEW QUESTION # 72
......

Pass Palo Alto Networks PCNSE exam - questions - convert Tets Engine to PDF: https://www.2pass4sure.com/PCNSE-PAN-OS/PCNSE-actual-exam-braindumps.html

2024 Realistic Verified Free Palo Alto Networks PCNSE Exam Questions: https://drive.google.com/open?id=1Z3r2rL9iSlvT5AJLs67hxAIZJD4fA83p