Ultimate Guide to Prepare Free Palo Alto Networks PCNSE Exam Questions & Answer [Q31-Q54]

Share

Ultimate Guide to Prepare Free Palo Alto Networks PCNSE Exam Questions and Answer

Pass Palo Alto Networks PCNSE Tests Engine pdf - All Free Dumps

NEW QUESTION # 31
View the GlobalProtect configuration screen capture.

What is the purpose of this configuration?

  • A. It configures the tunnel address of all internal clients to an IP address range starting at 192.168.10.1.
  • B. It forces an internal client to connect to an internal gateway at IP address 192.168.10.1.
  • C. It enables a client to perform a reverse DNS lookup on 192.168.10.1 to detect that it is an internal client.
  • D. It forces the firewall to perform a dynamic DNS update, which adds the internal gateway's hostname and IP address to the DNS server.

Answer: C

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-por the-globalprotect-client-authentication-configurations/define-the-globalprotect-agent-configurations
"Select this option to allow the GlobalProtect agent to determine if it is inside the enterprise network. This option applies only to endpoints that are configured to communicate with internal gateways.When the user attempts to log in, the agent does a reverse DNS lookup of an internal host using the specified Hostname to the specified IP Address. The host serves as a reference point that is reachable if the endpoint is inside the enterprise network. If the agent finds the host, the endpoint is inside the network and the agent connects to an internal gateway; if the agent fails to find the internal host, the endpoint is outside the network and the agent establishes a tunnel to one of the external gateways"


NEW QUESTION # 32
Which CLI command can be used to export the tcpdump capture?

  • A. download mgmt.-pcap
  • B. scp extract mgmt-pcap from mgmt.pcap to <username@host:path>
  • C. scp export tcpdump from mgmt.pcap to <username@host:path>
  • D. scp export mgmt-pcap from mgmt.pcap to <username@host:path>

Answer: D

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-Interface/ta- p/55415


NEW QUESTION # 33
Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?

  • A. sim
  • B. find
  • C. check
  • D. test

Answer: D

Explanation:
Reference:
http://www.shanekillen.com/2014/02/palo-alto-useful-cli-commands.html


NEW QUESTION # 34
A customer has an application that is being identified as unknown-top for one of their custom PostgreSQL database connections. Which two configuration options can be used to correctly categorize their custom database application? (Choose two.)

  • A. Custom Service object.
  • B. Application Override policy.
  • C. Custom application.
  • D. Security policy to identify the custom application.

Answer: B,C

Explanation:
Explanation
Unlike the App-ID engine, which inspects application packet contents for unique signature elements, the Application Override policy's matching conditions are limited to header-based data only. Traffic matched by an Application Override policy is identified by the App-ID entered in the Application entry box.Choices are limited to applications currently in the App-ID database.Because this traffic bypasses all Layer 7 inspection, the resulting security is that of a Layer-4 firewall. Thus, this traffic should be trusted without the need for Content-ID inspection. The resulting application assignment can be used in other firewall functions such as Security policy and QoS.Use CasesThree primary uses cases for Application Override Policy are:
To identify "Unknown" App-IDs with a different or custom application signature To re-identify an existing application signature To bypass the Signature Match Engine (within the SP3 architecture) to improve processing timesA discussion of typical uses of application override and specific implementation examples is here:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application- O


NEW QUESTION # 35
An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls.
The firewalls will provide access to mobile users and act as edge locations to on-premises infrastructure The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration Which two solutions can the administrator use to scale this configuration? (Choose two.)

  • A. variables
  • B. collector groups
  • C. template stacks
  • D. virtual systems

Answer: A,C

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/centralized-firewall-con
https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/manage-templates-and-tem


NEW QUESTION # 36
An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)

  • A. source users
  • B. GlobalProtect HIP
  • C. App-ID
  • D. source and destination IP addresses
  • E. URL categories

Answer: A,D,E


NEW QUESTION # 37
In the following image from Panorama, why are some values shown in red?

  • A. sg2 has misconfigured session thresholds.
  • B. sg2 session count is the lowest compared to the other managed devices.
  • C. uk3 has a logging rate that deviates from the seven-day calculated baseline.
  • D. us3 has a logging rate that deviates from the administrator-configured thresholds.

Answer: B


NEW QUESTION # 38
View the GlobalProtect configuration screen capture.
What is the purpose of this configuration?

  • A. It configures the tunnel address of all internal clients to an IP address range starting at 192.168.10.1.
  • B. It forces an internal client to connect to an internal gateway at IP address 192.168.10.1.
  • C. It enables a client to perform a reverse DNS lookup on 192.168.10.1 to detect that it is an internal client.
  • D. It forces the firewall to perform a dynamic DNS update, which adds the internal gateway's hostname and IP address to the DNS server.

Answer: C

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/ globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect- agent-configurations


NEW QUESTION # 39
What must be configured to apply tags automatically based on User-ID logs?

  • A. Log Forwarding profile
  • B. Group mapping
  • C. Device ID
  • D. Log settings

Answer: D

Explanation:
Explanation
Depending on the type of log you want to use for tagging, create a log forwarding profile or configure the log settings to define how you want the firewall or Panorama to handle logs. For Authentication, Data, Threat, Traffic, Tunnel Inspection, URL, and WildFire logs, create a log forwarding profile. For User-ID, GlobalProtect, and IP-Tag logs, configure the log settings.https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-auto-tagging-to-automate-secur


NEW QUESTION # 40
An engineer is configuring Packet Buffer Protection on ingress zones to protect from single-session DoS attacks Which sessions does Packet Buffer Protection apply to?

  • A. It applies to new sessions and is global
  • B. It applies to existing sessions and is global
  • C. It applies to existing sessions and is not global
  • D. It applies to new sessions and is not global

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection


NEW QUESTION # 41
What are three reasons why an installed session can be identified with the "application incomplete" tag? (Choose three.)

  • A. There is not enough application data after the TCP connection was established.
  • B. The TCP connection did not fully establish.
  • C. The TCP connection was terminated without identifying any application data.
  • D. The client sent a TCP segment with the PUSH flag set.
  • E. There was no application data after the TCP connection was established.

Answer: A,B,E

Explanation:
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC


NEW QUESTION # 42
What are the differences between using a service versus using an application for Security Policy match?

  • A. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take immediate action if the port being used is a member of the application standard port list.
  • B. Use of a "service" enables the firewall to take action after enough packets allow for App-ID identification
  • C. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take action after enough packets allow for App-ID identification regardless of the ports being used
  • D. There are no differences between "service" or "application". Use of an "application" simplifies configuration by allowing use of a friendly application name instead of port numbers

Answer: C


NEW QUESTION # 43
Which method will dynamically register tags on the Palo Alto Networks NGFW?

  • A. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)
  • B. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
  • C. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
  • D. Restful API or the VMware API on the firewall or on the User-ID agent

Answer: C

Explanation:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/register- ip-addresses-and-tags-dynamically


NEW QUESTION # 44
Which data flow describes redistribution of user mappings?

  • A. firewall to firewall
  • B. Domain Controller to User-ID agent
  • C. User-ID agent to firewall
  • D. User-ID agent to Panorama

Answer: A

Explanation:
Explanation
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-firewalls-to-redistribute-u


NEW QUESTION # 45
What is the best definition of the Heartbeat Interval?

  • A. The frequency at which the HA peers exchange ping
  • B. The frequency at which the HA peers check link or path availability
  • C. The interval during which the firewall will remain active following a link monitor failure
  • D. The interval in milliseconds between hello packets

Answer: D

Explanation:
Explanation
According to the Palo Alto Networks Knowledge Base , the best definition of the Heartbeat Interval is A.
The interval in milliseconds between hello packets.
The Heartbeat Interval is a CLI command that configures how often an HA peer sends an ICMP ping to its partner through the HA control link. The ping verifies network connectivity and ensures that the peer kernel is responsive. The default value is 1000ms for all Palo Alto Networks platforms.


NEW QUESTION # 46
When setting up a security profile, which three items can you use? (Choose three.)

  • A. antivirus
  • B. Wildfire analysis
  • C. anti-ransomware
  • D. decryption profile
  • E. URL filtering

Answer: A,B,E

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles.html


NEW QUESTION # 47
An administrator has created an SSL Decryption policy rule that decrypts SSL sessions on any port.
Which log entry can the administrator use to verify that sessions are being decrypted?

  • A. Decryption log
  • B. In the details of the Threat log entries
  • C. In the details of the Traffic log entries
  • D. Data Filtering log

Answer: C

Explanation:
Explanation/Reference: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-and-Test-SSL- Decryption/ta-p/59719


NEW QUESTION # 48
Which two features does PAN-OS software use to identify applications? (Choose two.)

  • A. transaction characteristics
  • B. session number
  • C. pot number
  • D. application layer payload

Answer: A,C

Explanation:
Signatures are then applied to allowed traffic to identify the application based on unique application properties and related [transaction characteristics]. The signature also determines if the application is being used on its [default port or it is using a non-standard port.] If the traffic is allowed by policy, the traffic is then scanned for threats and further analyzed for identifying the application more granularly.
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/app-id-overview.html


NEW QUESTION # 49
The firewall identifies a popular application as an unknown-tcp.
Which two options are available to identify the application? (Choose two.)

  • A. Create a Security policy to identify the custom application.
  • B. Create a custom application.
  • C. Create a custom object for the custom application server to identify the custom application.
  • D. Submit an App-ID request to Palo Alto Networks.

Answer: A,B

Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/app-id/use-application-objects- in-policy/create-a-custom-application


NEW QUESTION # 50
Place the steps in the WildFire process workflow in their correct order.

Answer:

Explanation:


NEW QUESTION # 51
SD-WAN is designed to support which two network topology types? (Choose two.)

  • A. ring
  • B. point-to-point
  • C. full-mesh
  • D. hub-and-spoke

Answer: C,D


NEW QUESTION # 52
Ethernet1/1 has been configured with the following subinterfaces:

The following security policy rule is applied:

The Interface Management Profile permits the following:

A customer is trying to ping 10.10.10.1 from VLAN 799 IP 10.10.10.2/24.
What will be the result of this ping?

  • A. The ping will not be successful because the virtual router is different from the other subinterfaces.
  • B. The ping will not successful because the security policy permits this traffic.
  • C. The ping will not successful because the management profile applied to ethernet1/1 allows ping.
  • D. The ping will not be successful because the security policy does not apply to VLAN 799.
  • E. The ping will not be successful because there is no management profile attached to ethernet1/1.799.

Answer: E


NEW QUESTION # 53
When using the predefined default profile, the policy will inspect for viruses on the decoders. Match each decoder with its default action.
Answer options may be used more than once or not at all.

Answer:

Explanation:

Explanation
IMAP , POP3 , SMTP - > Alert
HTTP,FTP,SMB -> Reset-both


NEW QUESTION # 54
......

Online Exam Practice Tests with detailed explanations!: https://actual4test.practicetorrent.com/PCNSE-practice-exam-torrent.html