Enhance Your Career With Available Preparation Guide for PCNSE Exam
Get Special Discount Offer of PCNSE Certification Exam Sample Questions and Answers
NEW QUESTION 83
An administrator needs to evaluate a recent policy change that was committed and pushed to a firewall device group.
How should the administrator identify the configuration changes?
- A. context-switch to the affected firewall and use the configuration audit tool
- B. click Preview Changes under Push Scope
- C. use Test Policy Match to review the policies in Panorama
- D. review the configuration logs on the Monitor tab
Answer: D
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/panorama-web-interface/panorama-com
NEW QUESTION 84
Which three options are supported in HA Lite? (Choose three.)
- A. Active/passive deployment
- B. Configuration synchronization
- C. Session synchronization
- D. Virtual link
- E. Synchronization of IPsec security associations
Answer: A,B,E
Explanation:
"The PA-200 firewall supports HA Lite only. HA Lite is an active/passive deployment that provides configuration synchronization and some runtime data synchronization such as IPSec security associations. It does not support any session synchronization (HA2), and therefore does not offer stateful failover."
NEW QUESTION 85
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
- A. Verify AutoFocus status using CLI "test" command.
- B. Check the license
- C. Check the WebUI Dashboard AutoFocus widget.
- D. Verify AutoFocus is enabled below Device Management tab.
- E. Check for WildFire forwarding logs.
Answer: B,D
Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/getting-started/enable- autofocus-threat-intelligence
NEW QUESTION 86
Starting with PAN-OS version 9.1, application dependency information is now reported in which new locations? (Choose two.)
- A. On the Policy Optimizer's Rule Usage page
- B. On the Objects > Applications browsers pages
- C. On the Application tab in the Security Policy Rule creation window
- D. On the App Dependency tab in the Commit Status window
Answer: C,D
NEW QUESTION 87
A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas) i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system ) ii. Enterprise-Untrusted-CA, which is verified as Forward Untrust Certificate iii. Enterprise-lntermediate-CA iv. Enterprise-Root-CA which is verified only as Trusted Root CA An end-user visits https //www example-website com/ with a server certificate Common Name (CN) www example-website com The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall The end-user's browser will show that the certificate for www.example-website.com was issued by which of the following?
- A. Enterprise-Root-CA which is a self-signed CA
- B. Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
- C. Enterprise-Trusted-CA which is a self-signed CA
- D. Enterprise-Untrusted-CA which is a self-signed CA
Answer: D
NEW QUESTION 88
Based on PANW Best Practices for Planning DoS and Zone Protection, match each type of DoS attack to an example of that type of attack.
Answer:
Explanation:
NEW QUESTION 89
If the firewall has the link monitoring configuration, what will cause a failover?
- A. ethernet1/6 going down
- B. ethernet1/3 and ethernet1/6 going down
- C. ethernet1/3 going down
- D. ethernet1/3 or Ethernet1/6 going down
Answer: B
NEW QUESTION 90
An administrator has been asked to create 100 virtual firewalls in a local, on-premise lab environment (not in
"the cloud"). Bootstrapping is the most expedient way to perform this task.
Which option describes deployment of a bootstrap package in an on-premise virtual environment?
- A. Create and attach a virtual hard disk (VHD).
- B. Use config-drive on a USB stick.
- C. Use an S3 bucket with an ISO.
- D. Use a virtual CD-ROM with an ISO.
Answer: D
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/management-features/bootstrapp firewalls-for-rapid-deployment.html
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/bootstrap-the-vm-series-firewall/bootstra
NEW QUESTION 91
Which protocol is supported by GlobalProtect Clientless VPN?
- A. FTP
- B. RDP
- C. SSH
- D. HTTPS
Answer: B
NEW QUESTION 92
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image. Which configuration change should the administrator make?
A)
B)
C)
D)
E)
- A. Option D
- B. Option B
- C. Option E
- D. Option C
- E. Option A
Answer: A
NEW QUESTION 93
In High Availability, which information is transferred via the HA data link?
- A. heartbeats
- B. User-ID information
- C. HA state information
- D. session information
Answer: D
NEW QUESTION 94
A customer has an application that is being identified as unknown-top for one of their custom PostgreSQL database connections. Which two configuration options can be used to correctly categorize their custom database application? (Choose two.)
- A. Security policy to identify the custom application.
- B. Application Override policy.
- C. Custom application.
- D. Custom Service object.
Answer: B,C
Explanation:
Explanation
Unlike the App-ID engine, which inspects application packet contents for unique signature elements, the Application Override policy's matching conditions are limited to header-based data only. Traffic matched by an Application Override policy is identified by the App-ID entered in the Application entry box.Choices are limited to applications currently in the A Because this traffic bypasses all Layer 7 inspection, the resulting security is that of a Layer-4 firewall. Thus, this traffic should be trusted without the need for Content-ID inspection. The resulting application assignment can be used in other firewall functions such as Security policy and QoS.Use CasesThree primary uses cases for Application Override Policy are:
To identify "Unknown" App-IDs with a different or custom application signature To re-identify an existing application signature To bypass the Signature Match Engine (within the SP3 architecture) to improve processing timesA discussion of typical uses of application override and specific implementation examples is here:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application- O
NEW QUESTION 95
What are three valid actions in a File Blocking Profile? (Choose three)
- A. Upload
- B. Continue
- C. Block
- D. Reset-both
- E. Alret
- F. Forward
Answer: B,C,E
Explanation:
You can configure a file blocking profile with the following actions:
* Forward - When the specified file type is detected, the file is sent to WildFire for analysis. A log is also generated in the data filtering log.
* Block - When the specified file type is detected, the file is blocked and a customizable block page is presented to the user. A log is also generated in the data filtering log.
* Alert - When the specified file type is detected, a log is generated in the data filtering log.
* Continue - When the specified file type is detected, a customizable response page is presented to the user. The user can click through the page to download the file. A log is also generated in the data filtering log. Because this type of forwarding action requires user interaction, it is only applicable for web traffic.
* Continue-and-forward - When the specified file type is detected, a customizable continuation page is presented to the user. The user can click through the page to download the file. If the user clicks through the continue page to download the file, the file is sent to WildFire for analysis.
A log is also generated in the data filtering log.
https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/file-blocking- profiles.html
NEW QUESTION 96
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)
- A. View the System logs and look for the error messages about BGP.
- B. Perform a traffic pcap on the NGFW to see any BGP problems.
- C. View the ACC tab to isolate routing issues.
- D. View the Runtime Stats and look for problems with BGP configuration.
Answer: C,D
NEW QUESTION 97
- A. Use the ACC to consolidate pre-existing logs.
- B. The log database will need to exported form the firewalls and manually imported into Panorama.
- C. A CLI command will forward the pre-existing logs to Panorama.
- D. Use the import option to pull logs into Panorama.
- E. Pre-existing logs from the firewalls are not appearing in PanoramA.
Which action would enable the firewalls to send their pre-existing logs to Panorama?
Answer: C
Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/management-features/pa-7000-series-firewall-log-forwarding-to-panorama
NEW QUESTION 98
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)
- A. The firewall's DP CPU is higher than 50%.
- B. The firewall is in multi-vsys mode.
- C. The traffic does not match the packet capture filter.
- D. The traffic is offloaded.
Answer: C,D
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/monitoring/take-packet-captures/disable-hardware- offload
NEW QUESTION 99
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs. The administrator assigns priority 100 to the active firewall.
Which priority is correct for the passive firewall?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Reference:
https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/framemaker/71/pan- os/pan-os/section_5.pdf (page 9)
NEW QUESTION 100
......
Updated PCNSE Dumps Questions Are Available For Passing Palo Alto Networks Exam: https://2cram.actualtestsit.com/Palo-Alto-Networks/PCNSE-exam-prep-dumps.html