Exit demo PCNSE Palo Alto Networks Certified Network Security Engineer - PAN-OS 11.x (PCNSE) PDF format · free preview

Palo Alto Networks PCNSE - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pcnse.html

Question 1
Single choice

What is considered the best practice with regards to zone protection?

A.

Review DoS threat activity (ACC > Block Activity) and look for patterns of abuse

B.

Use separate log-forwarding profiles to forward DoS and zone threshold event logs separately from other threat logs

C.

If the levels of zone and DoS protection consume too many firewall resources, disable zone protection

D.

Set the Alarm Rate threshold for event-log messages to high severity or critical severity

Question 2
Multiple choice

A traffic log might list an application as "not-applicable" for which two reasons'? (Choose two )

A.

The firewall did not install the session

B.

The TCP connection terminated without identifying any application data

C.

The firewall dropped a TCP SYN packet

D.

There was not enough application data after the TCP connection was established

Question 3
Multiple choice

A remote administrator needs access to the firewall on an untrust interlace.

Which three options would you configure on an interface Management profile lo secure management access? (Choose three)

A.

HTTP

B.

User-ID

C.

SSH

D.

HTTPS

E.

Permitted IP Addresses

Question 4
Single choice

Which statement accurately describes service routes and virtual systems?

A.

Virtual systems can only use one interface for all global service and service routes of the firewall

B.

The interface must be used for traffic to the required external services

C.

Virtual systems that do not have specific service routes configured inherit the global service and service route settings for the firewall

D.

Virtual systems cannot have dedicated service routes configured: and virtual systems always use the global service and service route settings for the firewall

Question 5
Single choice

An administrator analyzes the following portion of a VPN system log and notices the following issue

"Received local id 10 10 1 4/24 type IPv4 address protocol 0 port 0, received remote id 10.1.10.4/24 type
IPv4 address protocol 0 port 0."

What is the cause of the issue?

A.

IPSec crypto profile mismatch

B.

IPSec protocol mismatch

C.

mismatched Proxy-IDs

D.

bad local and peer identification IP addresses in the IKE gateway

Question 6
Single choice

A network security engineer must implement Quality of Service policies to ensure specific levels of delivery guarantees for various applications in the environment.
They want to ensure that they know as much as they can about QoS before deploying.

Which statement about the QoS feature is correct?

A.

QoS is only supported on firewalls that have a single virtual system configured

B.

QoS can be used in conjunction with SSL decryption

C.

QoS is only supported on hardware firewalls

D.

QoS can be used on firewalls with multiple virtual systems configured

Question 7
Single choice

What happens when an A P firewall cluster synchronies IPsec tunnel security associations (SAs)?

A.

Phase 2 SAs are synchronized over HA2 finks

B.

Phase 1 and Phase 2 SAs are synchronized over HA2 links

C.

Phase 1 SAs are synchronized over HA1 links

D.

Phase 1 and Phase 2 SAs are synchronized over HA3 links

Question 8
Single choice

Refer to the exhibit.

An administrator cannot see any Traffic logs from the Palo Alto Networks NGFW in Panorama reports. The configuration problem seems to be on the firewall.

Which settings, if configured incorrectly, most likely would stop only Traffic logs from being sent from the firewall to Panorama?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 9
Single choice

In an HA failover scenario what occurs when sessions match an SSL Forward Proxy Decryption policy?

A.

HA Sync does not occur the existing session is transferred to the active firewall.

B.

HA Sync does not occur the firewall drops the session.

C.

HA Sync occurs the session is sent to testpath

D.

HA Sync occurs the firewall allows the session Put does not decrypt the session.

Question 10
Multiple choice

What are three reasons for excluding a site from SSL decryption? (Choose three.)

A.

the website is not present in English

B.

unsupported ciphers

C.

certificate pinning

D.

unsupported browser version

E.

mutual authentication

Showing 10 of 860 questions · Unlock the full set