PCNSE Braindumps Real Exam Updated on Dec 30, 2021 with 363 Questions [Q203-Q228]

Share

PCNSE Braindumps Real Exam Updated on Dec 30, 2021 with 363 Questions

Latest PCNSE PDF Dumps & Real Tests Free Updated Today


Sample Questions

Which configuration must be made on the firewall before it can read User-ID-to-IP-address mapping tables from external sources?

  • B. Server Monitoring
  • D. User-ID Agents
  • C. Captive Portal
  • A. Group Mapping Settings

For an external device to consume a local User-ID-to-IP-address mapping table, which data is used for authentication between the devices?

  • D. certificates added to the User-ID agent configuration
  • B. User-ID agent’s Server Monitor Account information
  • C. administrators account information on the source device with the User-ID role set
  • A. the source device’s Data Redistribution Collector Name and Pre-Shared Key

User-ID-to IP-address mapping tables can be read by which product or service?

  • B. Panorama Log Collector
  • A. Cortex XDR
  • D. Prisma Cloud
  • C. AutoFocus

PCNSE: Requirements

Please note that this certification exam is of the Advanced level, which means that you need to have some prior knowledge. Although it is not stated officially as a strict requirement, you can have 3 to 5 years of experience of working in the networking or security industries. Besides that, a potential candidate can have the equivalent of 6-12 months of experience in deploying Palo Alto Networks NGFW within the Palo Alto Networks product portfolio and configuring it.


It is also recommended that the students explore other prep resources available at the Palo Alto Networks education website. The recommended tools include:

  • Cybersecurity Skills Practice Lab
  • Administrator’s guide
  • Palo Alto PCNSE Study Guide & Practice Exam
  • Preparation videos & tutorials

 

NEW QUESTION 203
A network security engineer for a large company has just installed a PA-5060 Firewall to isolate the company's PCI environment from its production network. The company's engineers made configuration changes to the switches on both network segments, and connected them to the new firewall.
Soon after the cutover, however, users began to complain about latency and some servicers stopped communicating. There are no security policies that deny traffic between the two networks segments. You suspect that there is an interface misconfiguration on Ethernet 1/1.
Which two commands should be used to troubleshoot the issue? (Choose two)

  • A. show interface logical
  • B. show interface hardware
  • C. show interface ethernet1/1
  • D. show interface management

Answer: A,C

 

NEW QUESTION 204
Click the Exhibit button

An administrator has noticed a large increase in bittorrent activity. The administrator wants to determine where the traffic is going on the company.
What would be the administrator's next step?

  • A. Create local filter for bittorrent traffic and then view Traffic logs.
  • B. Right-Click on the bittorrent link and select Value from the context menu
  • C. Click on the bittorrent application link to view network activity
  • D. Create a global filter for bittorrent traffic and then view Traffic logs.

Answer: C

 

NEW QUESTION 205
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet.
Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10.1.1.22

Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?
A)

B)

C)

D)

  • A. Option D
  • B. Option A
  • C. Option C
  • D. Option B

Answer: C

 

NEW QUESTION 206
After pushing a security policy from Panorama to a PA-3020 firwall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs. What could be the problem?

  • A. The firewall is not licensed for logging to this Panorama device.
  • B. Panorama is not licensed to receive logs from this particular firewall.
  • C. None of the firwwall's policies have been assigned a Log Forwarding profile
  • D. A Server Profile has not been configured for logging to this Panorama device.

Answer: C

 

NEW QUESTION 207
A logging infrastructure may need to handle more than 10,000 logs per second.
Which two options support a dedicated log collector function? (Choose two)

  • A. Panorama virtual appliance on ESX(i) only
  • B. M-500
  • C. M-100 with Panorama installed
  • D. M-100

Answer: B,D

 

NEW QUESTION 208
Refer to the exhibit.

An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)

  • A. Untrust (Any) to DMZ (10.1.1.1), web-browsing -Allow
  • B. Untrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
  • C. Untrust (Any) to DMZ (10.1.1.1), ssh -Allow
  • D. Untrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow
  • E. Untrust (Any) to Untrust (10.1.1.1), ssh -Allow

Answer: A,C

 

NEW QUESTION 209
In which two types of deployment is active/active HA configuration supported? (Choose two.)

  • A. Layer 2 mode
  • B. TAP mode
  • C. Virtual Wire mode
  • D. Layer 3 mode

Answer: C,D

 

NEW QUESTION 210
Refer to the exhibit.

An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) received HTTP traffic and host B(10.1.1.101) receives SSH traffic.
Which two security policy rules will accomplish this configuration? (Choose two)

  • A. Untrust (Any) to DMZ (1.1.1.100) Web-browsing -Allow
  • B. Untrust (Any) to Untrust (10.1.1.1) Web-browsing -Allow
  • C. Untrust (Any) to Untrust (10.1.1.1) Ssh-Allow
  • D. Untrust (Any) to DMZ (1.1.1.100) Ssh-Allow

Answer: A,B

 

NEW QUESTION 211
A network Administrator needs to view the default action for a specific spyware signature. The administrator follows the tabs and menus through Objects> Security Profiles> Anti-Spyware and select default profile.
What should be done next?

  • A. View the default actions displayed in the Action column.
  • B. Click the Exceptions tab and then click
  • C. Click the simple-critical rule and then click the
  • D. Click the Rules tab and then look for rules with "default" in the Action column.

Answer: B

 

NEW QUESTION 212
Which DoS protection mechanism detects and prevents session exhaustion attacks?

  • A. Packet Based Attack Protection
  • B. TCP Port Scan Protection
  • C. Resource Protection
  • D. Flood Protection

Answer: C

Explanation:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/dos- protection-profiles

 

NEW QUESTION 213
Which PAN-OS® policy must you configure to force a user to provide additional credentials before he is
allowed to access an internal application that contains highly-sensitive business data?

  • A. Decryption policy
  • B. Security policy
  • C. Authentication policy
  • D. Application Override policy

Answer: C

 

NEW QUESTION 214
An engineer must configure the Decryption Broker feature
Which Decryption Broker security chain supports bi-directional traffic flow?

  • A. Layer 2 security chain
  • B. Transparent Bridge security chain
  • C. Layer 3 security chain
  • D. Transparent Proxy security chain

Answer: C

Explanation:
Together, the primary and secondary interfaces form a pair of decryption forwarding interfaces. Only interfaces that you have enabled to be Decrypt Forward interfaces are displayed here. Your security chain type (Layer 3 or Transparent Bridge) and the traffic flow direction (unidirectional or bidirectional) determine which of the two interfaces forwards allowed, clear text traffic to the security chain, and which interface receives the traffic back from the security chain after it has undergone additional enforcement.

 

NEW QUESTION 215
Several offices are connected with VPNs using static IPV4 routes.
An administrator has been tasked with implementing OSPF to replace static routing.
Which step is required to accoumplish this goal?

  • A. Create new VPN zones at each site to terminate each VPN connection
  • B. Assign an IP address on each tunnel interface at each site
  • C. Enable OSPFv3 on each tunnel interface and use Area ID 0.0.0.0
  • D. Assign OSPF Area ID 0.0.0.0 to all Ethernet and tunnel interfaces

Answer: D

 

NEW QUESTION 216
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port which it connects. How would an administrator configure the interface to 1Gbps?

  • A. set deviceconfig system speed-duplex 1Gbps-full-duplex
  • B. set deviceconfig system speed-duplex 1Gbps-duplex
  • C. set deviceconfig interface speed-duplex 1Gbps-full-duplex
  • D. set deviceconfig Interface speed-duplex 1Gbps-half-duplex

Answer: B

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Speed-and-Duplex-of-the-Mana Port/ta-p/59034 user@PA# set deviceconfig system speed-duplex100Mbps-full-duplex 100Mbps-full-duplex
100Mbps-half-duplex 100Mbps-half-duplex10Mbps-full-duplex 10Mbps-full-duplex10Mbps-half-duplex
10Mbps-half-duplex1Gbps-full-duplex 1Gbps-full-duplex1Gbps-half-duplex 1Gbps-half-duplex auto-negotiate auto-negotiate

 

NEW QUESTION 217
Which User-ID method maps IP addresses to usernames for users connecting through an 802.1x-enabled wireless network device that has no native integration with PAN-OS® software?

  • A. Port Mapping
  • B. Client Probing
  • C. Server Monitoring
  • D. XML API

Answer: D

Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts

 

NEW QUESTION 218
Which two features can be used to tag a username so that it is included in a dynamic user group? (Choose two)

  • A. User-ID Windows-based agent
  • B. log forwarding auto-tagging
  • C. GlobafProtect agent
  • D. XML API

Answer: A,C

 

NEW QUESTION 219
An administrator needs to optimize traffic to prefer business-critical applications over non- critical applications.
QoS natively integrates with which feature to provide service quality?

  • A. Port Inspection
  • B. App-ID
  • C. Certificate revocation
  • D. Content-ID

Answer: B

 

NEW QUESTION 220
Refer to the exhibit.

An administrator cannot see any of the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?
A)

B)

C)

D)

  • A. Option A
  • B. Option D
  • C. Option C
  • D. Option B

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-log-collection/configure-log-forward

 

NEW QUESTION 221
An administrator is configuring an IPSec VPN to a Cisco ASA at the administrator's home and experiencing issues completing the connection. the following is the output from the command:

What could be the cause of this problem?

  • A. The shared secrets do not match between the Palo Alto Networks Firewall and the ASA.
  • B. The Proxy IDs on the Palo Alto Networks Firewall do not match the setting on the ASA.
  • C. The dead peer detection settings do not match between the Palo Alto Networks Firewall and the ASA.
  • D. The public IP addresses do not match for both the Palo Alto Networks Firewall and the ASA.

Answer: D

 

NEW QUESTION 222
Several offices are connected with VPNs using static IPv4 routes. An administrator has been tasked with implementing OSPF to replace static routing.
Which step is required to accomplish this goal?

  • A. Assign OSPF Area 0.0.0.0 to all Ethernet and tunnel interfaces.
  • B. Assign an IP address on each tunnel interface at each site.
  • C. Create new VPN zones at each site to terminate each VPN connection.
  • D. Enable OSPFv3 on each tunnel interface and use Area ID 0.0.0.0

Answer: A

Explanation:
OSPF Area Types include the Backbone Area, Area 0, is the core of an OSPF network. The backbone has the reserved area ID of 0.0.0.0. All other areas are connected to it and all traffic between areas must traverse it. All routing between areas is distributed through the backbone area. While all other OSPF areas must connect to the backbone area, this connection doesn't need to be direct and can be made through a virtual link.
https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/networking/configure-ospf

 

NEW QUESTION 223
A variable name must start with which symbol?

  • A. &
  • B. #
  • C. !
  • D. $

Answer: D

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/manage-templates-and-temp

 

NEW QUESTION 224
A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone which options differentiates multiple VLAN into separate zones?

  • A. Create V-Wire objects with two V-Wire interfaces and define a range of "0-4096" in the "Tag Allowed" field of the V-Wire object.
  • B. Create Layer 3 subinterfaces that are each assigned tA. single VLAN ID and a common virtual router. The physical Layer 3 interface would handle untagged traffic. Assign each interface/subinterface tA. unique zone. Do not assign any interface an IP address.
  • C. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the Tag Allowed" field of the V-Wire object. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each iinterface/sub interface to a unique zone.
  • D. Create VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/sub interface to a unique zone.

Answer: C

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/vlan-tagged-traffic Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet.

 

NEW QUESTION 225
A session in the Traffic log is reporting the application as "incomplete." What does "incomplete" mean?

  • A. The three-way TCP handshake was observed, but the application could not be identified.
  • B. Data was received but was instantly discarded because of a Deny policy was applied before App-ID could be applied.
  • C. The traffic is coming across UDP, and the application could not be identified.
  • D. The three-way TCP handshake did not complete.

Answer: A

 

NEW QUESTION 226
An Administrator is configuring an IPSec VPN toa Cisco ASA at the administrator's home and experiencing issues completing the connection. The following is th output from the command:
less mp-log ikemgr.log:

What could be the cause of this problem?

  • A. The public IP addresse do not match for both the Palo Alto Networks Firewall and the ASA.
  • B. The shared secerts do not match between the Palo Alto firewall and the ASA
  • C. The deed peer detection settings do not match between the Palo Alto Networks Firewall and the ASA
  • D. The Proxy IDs on the Palo Alto Networks Firewall do not match the settings on the ASA.

Answer: D

 

NEW QUESTION 227
Support for which authentication method was added in PAN-OS 8.0?

  • A. LDAP
  • B. RADIUS
  • C. Diameter
  • D. TACACS+

Answer: D

 

NEW QUESTION 228
......

PCNSE Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund: https://www.pass4cram.com/PCNSE_free-download.html

Pass Palo Alto Networks PCNSE Exam With  Practice Test Questions Dumps Bundle: https://drive.google.com/open?id=1yLMHukgZ6pxDCoqamxKLCvKwlt2-VOdw