Real Exam Questions PCNSE Dumps Exam Questions in here [Oct-2021]
Get Latest Oct-2021 Conduct effective penetration tests using PCNSE
NEW QUESTION 156
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
- A. Verify AutoFocus status using CLI.
- B. Check for WildFire forwarding logs.
- C. Check the WebUI Dashboard AutoFocus widget.
- D. Verify AutoFocus is enabled below Device Management tab.
- E. Check the license
Answer: D,E
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/getting-started/enable-autofocus-threat-intelligence
NEW QUESTION 157
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- A. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)
- B. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
- C. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
- D. Restful API or the VMware API on the firewall or on the User-ID agent
Answer: D
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/register-ip-addresses-and-tags-dynam
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/
NEW QUESTION 158
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image.
Which configuration change should the administrator make?
A:
B:
C:
D:
E:
- A. Option D
- B. Option B
- C. Option A
- D. Option C
- E. Option E
Answer: B
NEW QUESTION 159
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
- A. Matching any valid corporate username.
- B. Using the same user's corporate username and password.
- C. Mapping to the IP address of the logged-in user.
- D. First four letters of the username matching any valid corporate username.
Answer: C
Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/content-inspection- features/credential-phishing-prevention
NEW QUESTION 160
An organization is building a Bootstrap Package to deploy Palo Alto Networks VM-Series firewalls into their AWS tenant Which two statements are correct regarding the bootstrap package contents? (Choose two )
- A. The directory structure must include a /config /content, /software and /license folders
- B. The bootstrap package is stored on an AFS share or a discrete container file bucket
- C. The init-cfg txt and bootstrap.xml files are both optional configuration items for the /config folder
- D. The bootstrap xml file allows for automated deployment of VM-Senes firewalls with full network and policy configurations.
- E. The /config /content and /software folders are mandatory while the /license and /plugin folders are optional
Answer: C,D
NEW QUESTION 161
What must be used in Security Policy Rule that contain addresses where NAT policy applies?
- A. Pre-NAT addresse and Pre-NAT zones
- B. Pre-NAT addresse and Post-Nat zones
- C. Post-Nat addresses and Pre-NAT zones
- D. Post-NAT addresse and Post-Nat zones
Answer: B
Explanation:
NAT Policy Rule Functionality
Upon ingress, the firewall inspects the packet and does a route lookup to determine the egress interface and zone. Then the firewall determines if the packet matches one of the NAT rules that have been defined, based on source and/or destination zone. It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones.
https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-policy-rules
NEW QUESTION 162
An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panorama?
- A. The active firewall, which then synchronizes to the passive firewall
- B. Both the active and passive firewalls independently, with no synchronization afterward
- C. The Passive firewall, which then synchronizes to the active firewall
- D. Both the active and passive firewalls, which then synchronize with each other
Answer: D
NEW QUESTION 163
An engineer must configure the Decryption Broker feature
Which Decryption Broker security chain supports bi-directional traffic flow?
- A. Layer 2 security chain
- B. Transparent Bridge security chain
- C. Layer 3 security chain
- D. Transparent Proxy security chain
Answer: C
Explanation:
Together, the primary and secondary interfaces form a pair of decryption forwarding interfaces. Only interfaces that you have enabled to be Decrypt Forward interfaces are displayed here. Your security chain type (Layer 3 or Transparent Bridge) and the traffic flow direction (unidirectional or bidirectional) determine which of the two interfaces forwards allowed, clear text traffic to the security chain, and which interface receives the traffic back from the security chain after it has undergone additional enforcement.
NEW QUESTION 164
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN- OS software. The firewall has internet connectivity through an Ethernet interface, but no internet connectivity from the management interface. The Security policy has the default security rules and a rule that allows all web-browsing traffic from any to any zone. What must the administrator configure so that the PAN-OS software can be upgraded?
- A. CRL
- B. Scheduler
- C. Service route
- D. Security policy rule
Answer: D
NEW QUESTION 165
Panorama provides which two SD-WAN functions? (Choose two.)
- A. data plane
- B. network monitoring
- C. control plane
- D. physical network links
Answer: A,C
Explanation:
Explanation/Reference:
NEW QUESTION 166
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
- A. Verify AutoFocus status using CLI.
- B. Check for WildFire forwarding logs.
- C. Verify AutoFocus is enabled below Device Management tab.
- D. Check the WebUI Dashboard AutoFocus widget.
- E. Check the license
Answer: D,E
Explanation:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/getting- started/enable-autofocus-threat-intelligence
NEW QUESTION 167
Refer to the exhibit.
Which certificates can be used as a Forwarded Trust certificate?
- A. Domain Sub-CA
- B. Certificate from Default Trust Certificate Authorities
- C. Forward_Trust
- D. Domain-Root-Cert
Answer: B
NEW QUESTION 168
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)
- A. View the System logs and look for the error messages about BGP.
- B. View the ACC tab to isolate routing issues.
- C. Perform a traffic pcap on the NGFW to see any BGP problems.
- D. View the Runtime Stats and look for problems with BGP configuration.
Answer: A,D
Explanation:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEWCA0
NEW QUESTION 169
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image. Which configuration change should the administrator make?
A: Option
B: Option
C: Option
D: Option
E: Option
- A. Option D
- B. Option B
- C. Option A
- D. Option C
- E. Option E
Answer: B
NEW QUESTION 170
Which feature must you configure to prevent users form accidentally submitting their corporate credentials to a phishing website?
- A. Anti-Spyware profile
- B. Vulnerability Protection profile
- C. Zone Protection profile
- D. URL Filtering profile
Answer: D
Explanation:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat- prevention/prevent-credential-phishing
NEW QUESTION 171
When setting up a security profile which three items can you use? (Choose three )
- A. anti-ransom ware
- B. antivirus
- C. Wildfire analysis
- D. decryption profile
- E. URL filtering
Answer: B,C,E
Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-profiles
NEW QUESTION 172
A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks.
How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?
- A. Define a custom App-ID to ensure that only legitimate application traffic reaches the server
- B. Add a tuned DoS Protection Profile
- C. Add QoS Profiles to throttle incoming requests
- D. Add an Anti-Spyware Profile to block attacking IP address
Answer: B
NEW QUESTION 173
If a DNS sinkhole is configured, any sinkhole actions indicating a potentially infected host are recorded in which log type?
- A. Threat
- B. WildFire Submissions
- C. Data Filtering
- D. Traffic
Answer: A
NEW QUESTION 174
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's firewall.
Which interface configuration will accept specific VLAN IDs?
Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)
- A. Different security profiles can be applied to traffic matching rules 2 and 3.
- B. Rule 2 and 3 apply to traffic on different ports.
- C. Separate Log Forwarding profiles can be applied to rules 2 and 3.
- D. A report can be created that identifies unclassified traffic on the network.
Answer: A,C
NEW QUESTION 175
Based on the image, what caused the commit warning?
- A. The CA certificate for FWDtrust has not been imported into the firewall.
- B. SSL Forward Proxy requires a public certificate to be imported into the firewall.
- C. The FWDtrust certificate has not been flagged as Trusted Root CA.
- D. The FWDtrust certificate does not have a certificate chain.
Answer: D
NEW QUESTION 176
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10.1.1.22 Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?
- A.
- B.
- C. Option D
- D.
- E. Option A
- F. Option B
- G. Option C
- H.
Answer: H
NEW QUESTION 177
......
Authentic Best resources for PCNSE Online Practice Exam: https://www.pass4surecert.com/Palo-Alto-Networks/PCNSE-practice-exam-dumps.html
Get the superior quality PCNSE Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1S0UvGMIgk0WEuZcZMcimy4eeWfhCujF3