[May-2023] Practice Palo Alto Networks PCNSC exam. Online Exam Practice Tests with detailed explanations! Pass PCNSC with confidence! [Q42-Q67]

Share

Practice Paloalto Certifications and Accreditations PCNSC exam. Online Exam Practice Tests with detailed explanations! Pass PCNSC with confidence!

PCNSC - Palo Alto Networks Certified Network Security Consultant Practice Tests 2023 | Pass4cram

NEW QUESTION # 42
Which User-ID method should b configured to map addresses to usernames for users connected through a terminal server?

  • A. server monitoring
  • B. XFF header
  • C. port mapping
  • D. Client probing

Answer: C


NEW QUESTION # 43
A session in the Traffic log is reporting the application as "incomplete" What does "incomplete" mean?

  • A. Data was received but wan instantly discarded because of a Deny policy was applied before App ID could be applied.
  • B. The three-way TCP handshake did not complete.
  • C. The traffic is coming across UDP, and the application could not be identified.
  • D. The three-way TCP handshake was observed, but the application could not be identified.

Answer: B


NEW QUESTION # 44
Which three file types can be forward to WildMFire for analysis a part of the basic WildMFire service?

  • A. .dil
  • B. .apk
  • C. .jar
  • D. .pdf
  • E. .exe
  • F. .fon

Answer: B,C,D


NEW QUESTION # 45
Which administrative authentication method supports authorization by an external service?

  • A. Certification
  • B. RADIUS
  • C. SSH keys
  • D. LDAP

Answer: C


NEW QUESTION # 46
A user's traffic traversing a Palo Alto Networks NGFW sometime can reach http//www company com At the session times out.
The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http //www company com.
How con the firewall be configured to automatically disable the PBF rule if the next hop goes down?

  • A. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.
  • B. Configure path monitoring for tine next hop gateway on the default route in tin- virtual router.
  • C. Enable and configure a Link Monitoring Profile for the external interface of the firewall.
  • D. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question.

Answer: A


NEW QUESTION # 47
A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny".
Which action will this configuration cause on the matched traffic?

  • A. The configuration is invalid. The Profile Settings section will be- grayed out when the action is set to "Deny"
  • B. The configuration is invalid it will cause the firewall to Skip this Security policy rule A warning will be displayed during a command.
  • C. The configuration is valid It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to "Deny" The configuration will allow the matched session unless a vulnerability signature is detected. The "Deny" action will supersede the per. defined, severity defined actions defined in the associated Vulnerability Protection Profile.

Answer: A


NEW QUESTION # 48
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using Link aggregation.
Which two formats are correct for naming aggregate interlaces? (Choose two.)

  • A. aggregate.8
  • B. aggregate.1
  • C. ae.1
  • D. ae.8

Answer: C,D


NEW QUESTION # 49
An organization has Palo Alto Networks MGfWs that send logs to remote monitoring and security management platforms. The network team has report has excessive traffic on the corporate WAN. How could the Palo Alto Networks NOFW administrator reduce WAN traffic while maintaining support for all the existing monitoring/security platforms?

  • A. Forward logs from external sources to Panorama for correlation, arid from Panorama send to the NGFW
  • B. forward logs from firewalls only to Panorama, and have Panorama forward log* lo other external service.
  • C. Any configuration on an M-500 would address the insufficient bandwidth concerns.
  • D. Configure log compression and optimization features on all remote firewalls.

Answer: B


NEW QUESTION # 50
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS software, the administrator enables logs forwarding from the firewalls to panorama Pre-existing logs from the firewall are not appearing in Panorama.
Which action would enables the firewalls to send their preexisting logs to Panorama?

  • A. The- log database will need to be exported from the firewall and manually imported into Panorama.
  • B. Use the ACC to consolidate pre-existing logs.
  • C. A CLI command will forward the pre-existing logs to Panorama.
  • D. Use the import option to pull logs panorama.

Answer: C


NEW QUESTION # 51
What are two benefits of nested device groups in panorama? (Choose two )

  • A. all device groups inherit setting from the Shared group
  • B. reuse of the existing Security policy rules and objects
  • C. overwrites local firewall configuration
  • D. requires configuration both function and location for every device

Answer: A,D


NEW QUESTION # 52
Which two methods can be used to verify firewall connectivity to Autofocus? (Choose two. )

  • A. Check the WebUl Dashboard Autofocus widget
  • B. Verify AutoFocus is enabled below Device Management tab
  • C. Check for WildFire forwarding logs.
  • D. Verify AutoFocus status using the CLI "test"command.
  • E. Check the license

Answer: A,E


NEW QUESTION # 53
A Company needs to preconfigured firewalls to be sent to remote sites with the least amount of preconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.
Which VPN configuration would adapt to changes when deployed to Hie future site?

  • A. preconfigured GlobalProtcet client
  • B. preconfigured iPsec tunnels
  • C. preconfigured PPTP Tunnels
  • D. preconfigured GlobalProtcet satellite

Answer: D


NEW QUESTION # 54
An administrator pushes a new configuration from panorama to a pair of firewalls that are configured as active/passive HA pair.
Which NGFW receives the configuration from panorama?

  • A. the passive firewall, which then synchronizes to the active firewall
  • B. both the active and passive firewalls, which then synchronizes with each other
  • C. the active firewall, which then synchronizes to the passive firewall
  • D. both the active and passive firewalls independently, with no synchronization afterward

Answer: B


NEW QUESTION # 55
Which two options prevents the firewall from capturing traffic passing through it? (Choose two.)

  • A. The firewall is in milti-vsys mode.
  • B. The firewall's DP CPU is higher than 50%
  • C. The traffic is offloaded.
  • D. The traffic does not match the packet capture filter

Answer: C,D


NEW QUESTION # 56
A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks.
How can the Palo Alto Networks NGFW be configured to specifically protect tins server against resource exhaustion originating from multiple IP address (DDoS attack)?

  • A. Add a Vulnerability Protection Profile to block the attack.
  • B. Add a DoS Protection Profile with defined session count.
  • C. Add QoS Profiles to throttle incoming requests.
  • D. Define a custom App-ID to ensure that only legitimate application traffic reaches the server

Answer: B


NEW QUESTION # 57
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?

  • A. The IP Address of sinkhole.paloaltonetworks.com
  • B. The IP Address of the command-and-control server
  • C. The IP Address specified in the sinkhole configuration
  • D. The IP Address of one of the external DNS servers identified in the anti-spyware database

Answer: C

Explanation:
Explanation
https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Verify-DNS-Sinkhole-Function-is-Working/t


NEW QUESTION # 58
An administrator sees several inbound sessions identified as unknown tcp in the Traffic logs. The administrator determines that these sessions are from external users accessing the company's propriety accounting application. The administrator wants to reliability identity this as their accounting application and to scan this traffic for threats.
Which option would achieve this result?

  • A. Create a custom App-ID and enable scanning on the advanced tab.
  • B. Create a custom App-ID and use the "ordered condition cheek box.
  • C. Create an Application Override policy
  • D. Create an Application Override policy and a custom threat signature for the application.

Answer: D


NEW QUESTION # 59
Winch three steps will reduce the CPU utilization on the management plane? (Choose three. ) Disable logging at session start in Security policies.

  • A. Reduce the traffic being decrypted by the firewall.
  • B. Disable predefined reports.
  • C. Disable SNMP on the management interface.
  • D. Application override of SSL application.

Answer: A,B,C


NEW QUESTION # 60
How would an administrator monitor/capture traffic on the management interface of the Palo Alto Networks NGFW?

  • A. Enable all four stage of traffic capture (TX, RX, DROP, Firewall)
  • B. Use the debug dataplane packet-diag set capture stage management file command
  • C. Use the tcpdump command
  • D. USe the debug dataplane packet-dia set capture stage firewall file command

Answer: C


NEW QUESTION # 61
An administrator wants multiple web servers in the DMZ to receive connections from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10 1.22 Based on the information shown in the age, which NAT rule will forward web-browsing traffic correctly?

A)

B)

C)

D)

  • A. Option C
  • B. Option B
  • C. Option A
  • D. Option D

Answer: C


NEW QUESTION # 62
Which Captive Portal mode must be contoured to support MFA authentication?

  • A. Single Sign-On
  • B. NTLM
  • C. Redirect
  • D. Transparent

Answer: C


NEW QUESTION # 63
Which feature prevents the submission of login information into website froms?

  • A. file blocking
  • B. data filtering
  • C. User-ID
  • D. credential phishing prevention

Answer: D


NEW QUESTION # 64
Which event will happen administrator uses an Application Override Policy?

  • A. The application name assigned to the traffic by the security rule is written to the traffic log.
  • B. The Palo Alto Networks NGFW Steps App-ID processing at Layer 4.
  • C. Threat-ID processing time is decreased.
  • D. App-ID processing time is increased.

Answer: B


NEW QUESTION # 65
An administrator has left a firewall to used default port for all management services.
Which three function performed by the dataplane? (Choose three.)

  • A. antivirus
  • B. NAT
  • C. NTP
  • D. file blocking
  • E. WildFire updates

Answer: B,C,E


NEW QUESTION # 66
Which version of Global Protect supports split tunneling based on destination domain, client process, and HTTP/HTTPs video streaming application?

  • A. Glovbalprotect version 4.1 with PAn-OS 8.0
  • B. Glovbalprotect version 4.0 with PAn-OS 8.0
  • C. Glovbalprotect version 4.1 with PAn-OS 8.1
  • D. Glovbalprotect version 4.0 with PAn-OS 8.1

Answer: D


NEW QUESTION # 67
......

Get instant access to PCNSC practice exam questions: https://drive.google.com/open?id=1jff3EhcNkgHwJoyEVD5tEeBZepQbvQUh

The best PCNSC exam study material and preparation tool is here: https://www.pass4cram.com/PCNSC_free-download.html