Free Sales Ending Soon - 100% Valid PCNSE Exam Dumps with 363 Questions [Q125-Q148]

Share

Free Sales Ending Soon - 100% Valid PCNSE Exam Dumps with 363 Questions

Verified PCNSE dumps Q&As on your PCNSE Exam Questions Certain Success!

NEW QUESTION 125
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?

  • A. Root certificate imported into the firewall with "Trust" enabled
  • B. Importation of a certificate from an HSM
  • C. Firewall connectivity to a CRL
  • D. Security policy rule allowing SSL to the target server

Answer: D

Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl- inbound-inspection

 

NEW QUESTION 126
Which interface configuration will accept specific VLAN IDs?

  • A. Subinterface
  • B. Access Interface
  • C. Trunk Interface
  • D. Tab Mode

Answer: A

Explanation:
You can only assign a single VLAN to a subinterface, and not to the physical interface. Each subinterface must have a VLAN ID before it can pass traffic.
http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/intrface.htm l

 

NEW QUESTION 127
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)

  • A. The firewall is in multi-vsys mode.
  • B. The firewall's DP CPU is higher than 50%.
  • C. The traffic is offloaded.
  • D. The traffic does not match the packet capture filter.

Answer: C,D

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/monitoring/take-packet-
captures/disable-hardware-offload

 

NEW QUESTION 128
Place the steps in the WildFire process workflow in their correct order.

Answer:

Explanation:

Explanation
Timeline Description automatically generated

https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/about-wildfire.html

 

NEW QUESTION 129
Which three authentication factors does PAN-OS software support for MFA (Choose three.)

  • A. Okta Adaptive
  • B. Pull
  • C. SMS
  • D. Push
  • E. Voice

Answer: C,D,E

 

NEW QUESTION 130
Based on the following image,

what is the correct path of root, intermediate, and end-user certificate?

  • A. Symantec > VeriSign > Palo Alto Networks
  • B. VeriSign > Palo Alto Networks > Symantec
  • C. Palo Alto Networks > Symantec > VeriSign
  • D. VeriSign > Symantec > Palo Alto Networks

Answer: A

 

NEW QUESTION 131
Which feature must you configure to prevent users form accidentally submitting their corporate credentials to a phishing website?

  • A. Zone Protection profile
  • B. Anti-Spyware profile
  • C. Vulnerability Protection profile
  • D. URL Filtering profile

Answer: D

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/prevent-credential-phishin

 

NEW QUESTION 132
An administrator is defining protection settings on the Palo Alto Networks NGFW to guard against resource exhaustion. When platform utilization is considered, which steps must the administrator take to configure and apply packet buffer protection?

  • A. Enable and configure the Packet Buffer Protection thresholds.
    Enable Packet Buffer Protection per ingress zone.
  • B. Enable and then configure Packet Buffer thresholds.
    Enable Interface Buffer protection.
  • C. Enable per-vsys Session Threshold alerts and triggers for Packet Buffer Limits.
    Enable Zone Buffer Protection per zone.
  • D. Create and Apply Zone Protection Profiles in all ingress zones.
    Enable Packet Buffer Protection per ingress zone.
  • E. Configure and apply Zone Protection Profiles for all egress zones.
    Enable Packet Buffer Protection per egress zone.

Answer: A

Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/zone-protection-and-dos- protection/configure-zone-protection-to-increase-network-security/configure-packet-buffer-protection

 

NEW QUESTION 133
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)

  • A.
  • B.
  • C.
  • D.

Answer: A,B

 

NEW QUESTION 134
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image.
Which configuration change should the administrator make?
A:

B:

C:

D:

E:

  • A. Option B
  • B. Option A
  • C. Option C
  • D. Option E
  • E. Option D

Answer: A

 

NEW QUESTION 135
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN-OS software. The firewall has internet connectivity through an Ethernet interface, but no internet connectivity from the management interface. The Security policy has the default security rules and a rule that allows all web-browsing traffic from any to any zone.
What must the administrator configure so that the PAN-OS software can be upgraded?

  • A. Service route
  • B. Security policy rule
  • C. CRL
  • D. Scheduler

Answer: A

Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clp3CAC

 

NEW QUESTION 136
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach http://www.company.com. At other times the session times out. The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http://www.company.com.
How can the firewall be configured automatically disable the PBF rule if the next hop goes down?

  • A. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.
  • B. Enable and configure a Link Monitoring Profile for the external interface of the firewall.
  • C. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question:.
  • D. Configure path monitoring for the next hop gateway on the default route in the virtual router.

Answer: A

Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFiCAK

 

NEW QUESTION 137
Exhibit:

What will be the egress interface if the traffic's ingress interface is ethernet1/6 sourcing from 192.168.111.3 and to the destination 10.46.41.113 during the time shown in the image?

  • A. ethernet1/3
  • B. ethernet1/6
  • C. ethernet1/7
  • D. ethernet1/5

Answer: A

 

NEW QUESTION 138
Click the Exhibit button

An administrator has noticed a large increase in bittorrent activity. The administrator wants to determine where the traffic is going on the company.
What would be the administrator's next step?

  • A. Right-Click on the bittorrent link and select Value from the context menu
  • B. Create a global filter for bittorrent traffic and then view Traffic logs.
  • C. Click on the bittorrent application link to view network activity
  • D. Create local filter for bittorrent traffic and then view Traffic logs.

Answer: C

 

NEW QUESTION 139
A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone which options differentiates multiple VLAN into separate zones?

  • A. Create Layer 3 subinterfaces that are each assigned tA. single VLAN ID and a common virtual router.
    The physical Layer 3 interface would handle untagged traffic. Assign each interface/subinterface tA.
    unique zone. Do not assign any interface an IP address.
  • B. Create V-Wire objects with two V-Wire interfaces and define a range of "0-4096 in the "Tag Allowed" field of the V-Wire object.
  • C. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the Tag Allowed" field of the V-Wire object. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each iinterface/sub interface to a unique zone.
  • D. Create VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/sub interface to a unique zone.

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire- Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic.You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet.

 

NEW QUESTION 140
After pushing a security policy from Panorama to a PA-3020 firewall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs. What could be the problem?

  • A. The firewall is not licensed for logging to this Panorama device.
  • B. A Server Profile has not been configured for logging to this Panorama device.
  • C. None of the firewall's policies have been assigned a Log Forwarding profile
  • D. Panorama is not licensed to receive logs from this particular firewall.

Answer: C

Explanation:
In order to see entries in the Panorama Monitor > Traffic or Monitor > Log screens, a profile must be created on the Palo Alto Networks device (or pushed from Panorama) to forward log traffic to Panorama.
Steps:
1. Go to Policies > Security and open the Options for a rule.
2. Under Log Setting, select New for Log Forwarding to create a new forwarding profile:

Etc.
https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-a-Profile-to-Forward- Logs-to-Panorama/ta-p/54038

 

NEW QUESTION 141
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet
1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP address of Ethernet
1/4 is 10.1.1.7. The default gateway is attached to Ethernet 1/1. A default route is properly configured.
What can be the cause of this problem?

  • A. DNS has not been properly configured on the firewall.
  • B. DNS has not been properly configured on the host.
  • C. Interface Ethernet 1/1 is in Virtual Wire Mode.
  • D. No Zone has been configured on Ethernet 1/4.

Answer: D

 

NEW QUESTION 142
Which two actions would be part of an automatic solution that would block sites with untrusted certificates
without enabling SSL Forward Proxy? (Choose two.)

  • A. Create a Security Policy rule with vulnerability Security Profile attached.
  • B. Enable the "Block sessions with untrusted issuers" setting.
  • C. Create a Dynamic Address Group for untrusted sites
  • D. Create a no-decrypt Decryption Policy rule.
  • E. Configure an EDL to pull IP addresses of known sites resolved from a CRL.

Answer: A,D

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/objects/
objects-decryption-profile

 

NEW QUESTION 143
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)

  • A. .dll
  • B. .apk
  • C. .src
  • D. .pdf
  • E. .jar
  • F. .exe

Answer: B,D,E

Explanation:
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/getting-started/enable-basic-wildfire-forwarding

 

NEW QUESTION 144
Refer to exhibit.

An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN.
How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all existing monitoring/ security platforms?

  • A. Forward logs from external sources to Panorama for correlation, and from Panorama send them to the NGFW.
  • B. Configure log compression and optimization features on all remote firewalls.
  • C. Any configuration on an M-500 would address the insufficient bandwidth concerns.
  • D. Forward logs from firewalls only to Panorama and have Panorama forward logs to other external services.

Answer: D

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/panorama-overview/centralized-logging-and-

 

NEW QUESTION 145
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans. Which Security Profile type will protect against worms and trojans?

  • A. Vulnerability Protection
  • B. WildFire
  • C. Antivirus
  • D. Anti-Spyware

Answer: D

Explanation:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/antivirus-profiles

 

NEW QUESTION 146
Which three firewall states are valid? (Choose three.)

  • A. Suspended
  • B. Passive
  • C. Pending
  • D. Active
  • E. Functional

Answer: A,B,D

 

NEW QUESTION 147
Which virtual router feature determines if a specific destination IP address is reachable?

  • A. Ping-Path
  • B. Path Monitoring
  • C. Heartbeat Monitoring
  • D. Failover

Answer: B

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/pbf

 

NEW QUESTION 148
......


Target Audience and Prerequisites

The candidates for the PCNSE certification should have at least three to five years of practice work experience in the security or networking industries. They also need to possess at least six to twelve months of experience in configuring and deploying Palo Alto Networks NGFW in the product portfolio of Palo Alto Networks. The students for the qualifying exam should also have a good understanding of the technologies available in Palo Alto Networks, including value-added resellers, system integrators, support staff, pre-sales system engineers, and Palo Alto Networks products users.

 

PCNSE Exam Dumps - 100% Marks In PCNSE Exam: https://www.testsdumps.com/PCNSE_real-exam-dumps.html

Exam Dumps Use Real PCNSE Dumps With 363 Questions: https://drive.google.com/open?id=1NhUOJeEolsy1eEHn8DJy07Ayit149wNX