100% Real & Accurate PCNSE Questions and Answers with Free and Fast Updates
Get Unlimited Access to PCNSE Certification Exam Cert Guide
NEW QUESTION # 20
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software.
Furthermore, SSL is used to tunnel malicious traffic to command-and-control servers on the internet and SSL Forward Proxy Decryption is not enabled.
Which component once enabled on a perirneter firewall will allow the identification of existing infected hosts in an environment?
- A. Vulnerability Protection profiles applied to outbound security policies with action set to block
- B. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole
- C. File Blocking profiles applied to outbound security policies with action set to alert
- D. Antivirus profiles applied to outbound security policies with action set to alert
Answer: B
NEW QUESTION # 21
Using multiple templates in a stack to manage many firewalls provides which two advantages? (Choose two.)
- A. define a common standard template configuration for firewalls
- B. standardize log-forwarding profiles for security polices across all stacks
- C. inherit address-objects from templates
- D. standardize server profiles and authentication configuration across all stacks
Answer: A,D
Explanation:
Explanation
Using multiple templates in a stack to manage many firewalls provides the advantages of defining a common standard template configuration for firewalls and standardizing server profiles and authentication configuration across all stacks. A template stack is a container for multiple templates that you can assign to firewalls and firewall groups. The templates in a stack are prioritized so that the settings in a higher-priority template override the same settings in a lower-priority template. This allows you to create a hierarchy of templates that define common settings for all firewalls and specific settings for different groups of firewalls. References:
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-templates-and-temp
NEW QUESTION # 22
Based on the following image, what is the correct path of root, intermediate, and end-user certificate?
- A. Symantec > VeriSign > Palo Alto Networks
- B. VeriSign > Palo Alto Networks > Symantec
- C. VeriSign > Symantec > Palo Alto Networks
- D. Palo Alto Networks > Symantec > VeriSign
Answer: A
NEW QUESTION # 23
Which Security policy rule will allow an admin to block facebook chat but allow Facebook in general?
- A. Allow application facebook before denying application facebook-chat
- B. Deny application facebook on top
- C. Allow application facebook on top
- D. Deny application facebook-chat before allowing application facebook
Answer: D
NEW QUESTION # 24
In an existing deployment, an administrator with numerous firewalls and Panorama does not see any WildFire logs in Panorama. Each firewall has an active WildFire subscription On each firewall. WildFire togs are available.
This issue is occurring because forwarding of which type of logs from the firewalls to Panorama is missing?
- A. WildFire logs
- B. Threat logs
- C. Traffic togs
- D. System logs
Answer: A
Explanation:
Explanation
When an administrator has numerous firewalls and Panorama, WildFire logs need to be forwarded from the firewalls to Panorama in order for them to be visible in Panorama. WildFire logs contain information about malicious files that have been detected by WildFire and provide detailed information such as the file's hash value, severity, and other attributes. This information can then be used to help identify threats and take appropriate security measures. Proper configuration of forwarding WildFire logs is essential for monitoring malicious activity and ensuring the security of the network.
NEW QUESTION # 25
Which operation will impact the performance of the management plane?
- A. Decrypting SSL sessions
- B. Generating a SaaS Application report
- C. Enabling packet buffer protection
- D. Enabling DoS protection
Answer: B
Explanation:
Explanation
TIPS & TRICKS: REDUCING MANAGEMENT PLANE LOAD:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSvCAK TIPS & TRICKS: REDUCING MANAGEMENT PLANE LOAD-PART 2:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU4CAK
NEW QUESTION # 26
A network administrator troubleshoots a VPN issue and suspects an IKE Crypto mismatch between peers. Where can the administrator find the corresponding logs after running a test command to initiate the VPN?
- A. Tunnel Inspection logs
- B. System logs
- C. Traffic logs
- D. Configuration logs
Answer: B
Explanation:
According to the Palo Alto Networks documentation, "To view IKE and IPSec Crypto profiles in the logs, filter the System log for eventid equal to vpn (Monitor > Logs > System)." Reference: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/vpn/set-up-site-to-site-vpn/set-up-ike-crypto-profiles.html
NEW QUESTION # 27
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)
- A. Task Manager
- B. Traffic Logs
- C. Configuration Logs
- D. System Logs
Answer: A,D
Explanation:
1. System Logs: The system logs contain information about various events that occur on the firewall, including the commit process. The administrator can review the system logs to verify whether the commit completed successfully or whether there were any errors or warnings during the commit process.
2. Task Manager: The task manager displays a list of all active tasks on the firewall, including the commit task. The administrator can use the task manager to check the status of the commit task, including whether it is in progress, completed successfully, or failed.
NEW QUESTION # 28
Use the image below If the firewall has the displayed link monitoring configuration what will cause a failover?
- A. ethernet1/3 or ethernet1/6 going down
- B. ethernet1/6 going down
- C. etheme!1/3 going down
- D. ethernet1/3 and ethernet1/6 going down
Answer: D
NEW QUESTION # 29
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also
creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are
three entries. The first entry shows traffic dropped as application Unknown. The next two entries show
traffic allowed as application SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as
SSL?
- A. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the
top of the Security policy. - B. Create a decryption rule matching the encrypted BitTorrent traffic with action "No-Decrypt," and place
the rule at the top of the Decryption policy. - C. Disable the exclude cache option for the firewall.
- D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the
decryption rule.
Answer: A
NEW QUESTION # 30
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.
Which VPN configuration would adapt to changes when deployed to the future site?
- A. Preconfigured IPsec tunnels
- B. Preconfigured PPTP Tunnels
- C. Preconfigured GlobalProtect client
- D. Preconfigured GlobalProtect satellite
Answer: D
Explanation:
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/large-scale-vpn-lsvpn/configure-the-globalprotect-portal-for-lsvpn/define-the-satellite-configurations.html
NEW QUESTION # 31
Which protection feature is available only in a Zone Protection Profile?
- A. UDP Flood Protections
- B. Port Scan Protection
- C. SYN Flood Protection using SYN Flood Cookies
- D. ICMP Flood Protection
Answer: B
Explanation:
Configure one of the following Reconnaissance Protection actions for the firewall to take in response to the corresponding reconnaissance attempt: Allow-The firewall allows the port scan or host sweep reconnaissance to continue.
SYN Flood Cookies is also available on DoS Protection Profile, the answer refers to ONLY. DoS Protection profiles protect specific devices (classified profiles) and groups of devices (aggregate profiles) against SYN, UDP, ICMP, ICMPv6, and Other IP flood attacks.
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/network/network-network-profiles/network-network-profiles-zone-protection/reconnaissance-protection.html#ida0512c75-ed54-4b31-8d2c-9f459466d4d2 Port scan protection = Reconnaissance Protection That can only be done in a Zone Protection Profile. That's meant to be configured on an external-facing interface to protect the entire attack surface.
DOS Protection profiles are meant to be configured on internal-facing interfaces to protect a specific server or group of servers from flood attacks, including SYN Flood.
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/configure-zone-protection-to-increase-network-security/configure-reconnaissance-protection
NEW QUESTION # 32
An administrator wants to grant read-only access to all firewall settings, except administrator accounts, to a new-hire colleague in the IT department.
Which dynamic role does the administrator assign to the new-hire colleague?
- A. Superuser (read-only)
- B. System administrator (read-only)
- C. Device administrator (read-only)
- D. Firewall administrator (read-only)
Answer: C
Explanation:
Explanation
Read-only access to all firewall settings except password profiles (no access) and administrator accounts (only the logged in account is visible).https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage-firewall-ad
NEW QUESTION # 33
Which three authentication factors does PAN-OSĀ® software support for MFA (Choose three.)
- A. Push
- B. Okta Adaptive
- C. Pull
- D. SMS
- E. Voice
Answer: A,D,E
Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/authentication/configure- multi-factor-authentication
NEW QUESTION # 34
Which feature of Panorama allows an administrator to create a single network configuration that can be reused repeatedly for large-scale deployments even if values of configured objects, such as routes and interface addresses, change?
- A. A device group
- B. Template variables
- C. The Shared device group
- D. Template stacks
Answer: B
Explanation:
Explanation
Template variables are placeholders that you can use in a template or a template stack to represent values that differ across firewalls, such as IP addresses, hostnames, or interface names. Template variables allow you to create a single network configuration that can be reused repeatedly for large-scale deployments even if values of configured objects change1. Option A is incorrect because template stacks are used to group multiple templates together and apply them to firewalls or device groups. Template stacks do not allow you to use variables for different values2. Option C is incorrect because the Shared device group is used to push policies and objects that are common across all firewalls managed by Panorama. The Shared device group does not allow you to use variables for different values3. Option D is incorrect because a device group is used to group firewalls that require similar policies and objects. A device group does not allow you to use variables for different values3.
NEW QUESTION # 35
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
- A. SSH keys must be manually generated.
- B. No prerequisites are required.
- C. Both SSH keys and SSL certificates must be generated.
- D. SSL certificates must be generated.
Answer: B
Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/configure-ssh- proxy
NEW QUESTION # 36
......
Reliable Study Materials for PCNSE Exam Success For Sure: https://torrentvce.certkingdompdf.com/PCNSE-latest-certkingdom-dumps.html