Exit demo PCNSC Palo Alto Networks Certified Network Security Consultant (PCNSC) PDF format · free preview

Palo Alto Networks PCNSC - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pcnsc.html

Question 1
Single choice

An administrator sees several inbound sessions identified as unknown tcp in the Traffic logs. The administrator determines that these sessions are from external users accessing the company's propriety accounting application. The administrator wants to reliability identity this as their accounting application and to scan this traffic for threats.

Which option would achieve this result?

A.

Create an Application Override policy and a custom threat signature for the application.

B.

Create a custom App-ID and use the "ordered condition cheek box.

C.

Create an Application Override policy

D.

Create a custom App-ID and enable scanning on the advanced tab.

Question 2
Single choice

Which PAN-OS policy must you configure to force a user to provide additional credential before he is allowed to access an internal application that contains highly sensitive business data?

A.

Authentication policy

B.

Decryption policy

C.

Security policy

D.

Application Override policy

Question 3
Single choice

A web server is hosted in the DMZ and the server re configured to listen for income connections on TCP port 443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server host its contents over Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule.

Which combination of service and application, and order of Security policy rules needs to be configured to allow cleaned web-browsing traffic to the server on tcp/443?

A.

Rule# 1 application: ssl; service application-default: action allow Role # 2 application web browsing,
service application default, action allow

B.

Rule #1application web-browsing, service service imp action allow Rule #2 application ssl. service
application -default, action allow

C.

Rule#1 application web-brows.no service application-default, action allow Rule #2 application ssl.
Service application-default, action allow

D.

Rule#1application: web-biows.no; service service-https action allow Rule#2 application ssl. Service
application-default, action allow

Question 4
Single choice

In High Availability, which information is transferred via the HA data link?

A.

heartbeats

B.

HA state information

C.

session information

D.

User-ID information

Question 5
Single choice

An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between panorama and the managed firewall and Log Collectors.

How would the administrator establish the chain of trust?

A.

Configure strong password

B.

Set up multiple-factor authentication.

C.

Use custom certificates.

D.

Enable LDAP or RADIUS integration.

Question 6
Single choice

Refer to the exhibit.

A web server in the DMZ is being mapped to a public address through DNAT.

Which Security policy rule will allow traffic to flow to the web server?

A.

Untrust (any) to Untrust (10. 1.1. 100), web browsing -Allow

B.

1.
1. 100), web browsing -Allow

C.

1.
1. 100), web browsing -Allow

D.

1.
1. 100), web browsing -Allow

Question 7
Single choice

An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW. THE update contains application that matches the same traffic signatures as the customer application.

Which application should be used to identify traffic traversing the NGFW?

A.

custom application

B.

Custom and downloaded application signature files are merged and are used.

C.

System longs show an application errors and signature is used.

D.

downloaded application

Question 8
Single choice

Which feature prevents the submission of login information into website froms?

A.

credential phishing prevention

B.

file blocking

C.

User-ID

D.

data filtering

Question 9
Multiple choice

The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.

Which two options would help the administrator Troubleshoot this issue? (Choose two.)

A.

Perform a traffic pcap on the NGFW lo see any BGP problems

B.

View the System logs and look for error messages about BGP

C.

View the Runtime Stats and look for problems with BGP configuration

D.

View the ACC lab to isolate routing issues.

Question 10
Multiple choice

Which three user authentication services can be modified in to provide the Palo Alto Networks NGFW with both username and role names? (Choose three.)

A.

PAP

B.

SAML

C.

LDAP

D.

TACACS+

E.

RADIUS

F.

Kerberos

Showing 10 of 141 questions · Unlock the full set