Unique Top-selling PCNSE Exams - New 2022 Palo Alto Networks Pratice Exam [Q47-Q62]

Share

Unique Top-selling PCNSE Exams - New 2022 Palo Alto Networks Pratice Exam

PCNSE Dumps PCNSE Exam for Full Questions - Exam Study Guide


PCNSE: Target Audience

The target audience for the PCNSE certification exam is those candidates who want to demonstrate their knowledge of the Palo Alto Networks technologies, such as customers, partners, system & support engineers, as well as system integrators. This test also evaluates their skills in configuring implementations that are based on the Palo Alto Networks platform.

 

NEW QUESTION 47
Which CLI command can be used to export the tedium capture?

  • A. download mgmt.-pcap
  • B. scp extract mgmt-pcap from mgmt.pcap to <username@host:path>
  • C. scp export mgmt-pcap from mgmt.pcap to <username@host:path>
  • D. scp export tcpdump from mgmt.pcap to <username@host:path>

Answer: C

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-I p/55415

 

NEW QUESTION 48
Decrypted packets from the website https://www.microsoft.com will appear as which application and service within the Traffic log?

  • A. web-browsing and 80
  • B. SSL and 443
  • C. web-browsing and 443
  • D. SSL and 80

Answer: C

 

NEW QUESTION 49
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?

  • A. First four letters of the username matching any valid corporate username.
  • B. Mapping to the IP address of the logged-in user.
  • C. Using the same user's corporate username and password.
  • D. Marching any valid corporate username.

Answer: C

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/credential- ention Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/content-inspection-features/crede phishing-prevention

 

NEW QUESTION 50
The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is configured to translate both IP address and report to 10.1.1.100 on TCP Port 8080.

Which NAT and security rules must be configured on the firewall? (Choose two)

  • A. A security policy with a source of any from untrust-I3 Zone to a destination of 10.1.1.100 in dmz-I3 zone using web-browsing application
  • B. A NAT rule with a source of any from untrust-I3 zone to a destination of 1.1.1.100 in untrust-I3 zone using service-http service.
  • C. A NAT rule with a source of any from untrust-I3 zone to a destination of 10.1.1.100 in dmz-zone using service-http service.
  • D. A security policy with a source of any from untrust-I3 zone to a destination of 1.1.100 in dmz-I3 zone using web-browsing application.

Answer: C,D

 

NEW QUESTION 51
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port which it connects. How would an administrator configure the interface to 1Gbps?

  • A. set deviceconfig system speed-duplex 1Gbps-full-duplex
  • B. set deviceconfig interface speed-duplex 1Gbps-full-duplex
  • C. set deviceconfig Interface speed-duplex 1Gbps-half-duplex
  • D. set deviceconfig system speed-duplex 1Gbps-duplex

Answer: A

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Speed-and-Duplex-of-the-Management- Port/ta-p/59034 user@PA# set deviceconfig system speed-duplex 100Mbps-full-duplex 100Mbps-full-duplex 100Mbps-half-duplex 100Mbps-half-duplex 10Mbps-full-duplex 10Mbps-full-duplex 10Mbps-half-duplex 10Mbps-half-duplex 1Gbps-full-duplex 1Gbps-full-duplex 1Gbps-half-duplex 1Gbps-half-duplex auto-negotiate auto-negotiate

 

NEW QUESTION 52
In a virtual router, which object contains all potential routes?

  • A. SIP
  • B. FIB
  • C. RIB
  • D. MIB

Answer: C

 

NEW QUESTION 53
A company.com wants to enable Application Override. Given the following screenshot:

Which two statements are true if Source and Destination traffic match the Application Override policy?
(Choose two)

  • A. Traffic that matches "rtp-base" will bypass the App-ID and Content-ID engines.
  • B. Traffic utilizing UDP Port 16384 will now be identified as "rtp-base".
  • C. Traffic utilizing UDP Port 16384 will bypass the App-ID and Content-ID engines.
  • D. Traffic will be forced to operate over UDP Port 16384.

Answer: A,B

 

NEW QUESTION 54
Which URL Filtering Security Profile action logs the URL Filtering category to the URL Filtering log?

  • A. Default
  • B. Alert
  • C. Log
  • D. Allow

Answer: B

Explanation:
https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/url-filtering/url-filtering- profile-actions

 

NEW QUESTION 55
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.
Which VPN configuration would adapt to changes when deployed to the future site?

  • A. Preconfigured GlobalProtect client
  • B. Preconfigured PPTP Tunnels
  • C. Preconfigured PIsec tunnels
  • D. Preconfigured GlobalProtect satellite

Answer: D

 

NEW QUESTION 56
An administrator needs to upgrade an NGFW to the most current version of PAN-OS?software.
The following is occurring:
- Firewall has internet connectivity through e 1/1.
- Default security rules and security rules allowing all SSL and web-
browsing traffic to and from any zone.
- Service route is configured, sourcing update traffic from e1/1.
- A communication error appears in the System logs when updates are
performed.
- Download does not complete.
What must be configured to enable the firewall to download the current version of PAN-OS software?

  • A. Security policy rule allowing PaloAlto-updates as the application
  • B. DNS settings for the firewall to use for resolution
  • C. Scheduler for timed downloads of PAN-OS software
  • D. Static route pointing application PaloAlto-updates to the update servers

Answer: B

 

NEW QUESTION 57
Where can an administrator see both the management plane and data plane CPU utilization in the WebUI?

  • A. Resources widget
  • B. System Utilization log
  • C. System log
  • D. CPU Utilization widget

Answer: A

Explanation:
Explanation
System Resources (widget)Displays the Management CPU usage, Data Plane usage, and the Session Count (the number of sessions established through the firewall or Panorama).https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/dashboard/dashboard-widge

 

NEW QUESTION 58
An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panorama?

  • A. Both the active and passive firewalls independently, with no synchronization afterward
  • B. The Passive firewall, which then synchronizes to the active firewall
  • C. The active firewall, which then synchronizes to the passive firewall
  • D. Both the active and passive firewalls, which then synchronize with each other

Answer: A

Explanation:
Palo Alto NetworksPanorama 7.0 Administrator's Guide *77Manage FirewallsManage Device GroupsManage Device GroupspAdd a Device GrouppCreate a Device Group HierarchypCreate Objects for Use in Shared or Device Group PolicypRevert to Inherited Object ValuespManage Unused Shared ObjectspManage Precedence of Inherited ObjectspMove or Clone a Policy Rule or Object to a Different Device GrouppSelect a URL Filtering Vendor on PanoramapPush a Policy Rule to a Subset of FirewallspManage the Rule HierarchyAdd a Device GroupAfter adding firewalls (see Add a Firewall as a Managed Device), you can group them into Device Groups (up to 256), as follows. Be sure to assign both firewalls in an active-passive high availability (HA) configuration to the same device group so that Panorama will push the same policy rules and objects to those firewalls. #############PAN-OS doesn't synchronize pushed rules across HA peers.######### To manage rules and objects at different administrative levels in your organization, Create a Device Group Hierarchy.
https://docs.paloaltonetworks.com/panorama/8-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleOCAS

 

NEW QUESTION 59
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image. Which configuration change should the administrator make?
A:

B:

C:

D:

E:

  • A. Option E
  • B. Option B
  • C. Option D
  • D. Option C
  • E. Option A

Answer: B

 

NEW QUESTION 60
When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?

  • A. To enable user authentication to the Portal
  • B. To enable client machine authentication to the Portal
  • C. To enable Portal authentication to the Gateway
  • D. To enable Gateway authentication to the Portal

Answer: A

Explanation:
The additional options of Browser and Satellite enable you to specify the authentication profile to use for specific scenarios. Select Browser to specify the authentication profile to use to authenticate a user accessing the portal from a web browser with the intent of downloading the GlobalProtect agent (Windows and Mac). Select Satellite to specify the authentication profile to use to authenticate the satellite.
https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/globalprotect/network-globalprotect-portals

 

NEW QUESTION 61
Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a "No Decrypt" action? (Choose two.)

  • A. Block sessions with expired certificates
  • B. Block sessions with client authentication
  • C. Block sessions with untrusted issuers
  • D. Block sessions with unsupported cipher suites
  • E. Block credential phishing

Answer: A,C

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/define-traffic- to-decrypt/create-a-decryption-profile

 

NEW QUESTION 62
......

Best way to practice test for Palo Alto Networks PCNSE: https://torrentvce.pass4guide.com/PCNSE-dumps-questions.html