Pass Palo Alto Networks PCNSE Exam with Guarantee Updated 363 Questions [Q108-Q129]

Share

Pass Palo Alto Networks PCNSE Exam with Guarantee Updated 363 Questions

Latest PCNSE Pass Guaranteed Exam Dumps Certification Sample Questions


Certification Overview

The Palo Alto Networks Certified Network Security Engineer is an advanced-level certification. This formal certificate validates that one possesses in-depth knowledge of the Palo Alto Networks product portfolio and can deploy it in a vast number of implementations. Commonly, the Palo Alto Networks product portfolio comprises multiple separate technologies working in unison to ward off cyber attacks. To a security-conscious employer, being PCNSE-certified provides additional assurance of one’s ability to correctly deploy the Palo Alto Networks Next-Generation Firewalls and manage the Palo Alto Networks technology. The Palo Alto Network’s reputation as a high-end security provider makes their validations highly valued by many organizations. This is why all of their certifications are considered prestigious. Are you wondering what the earnings potential and opportunities for IT specialists with the PCNSE certification look like? Well, PCNSE-certified IT professionals can expect to earn around $94,000 annually, according to Payscale.

 

NEW QUESTION 108
A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone which options differentiates multiple VLAN into separate zones?

  • A. Create V-Wire objects with two V-Wire interfaces and define a range of "0-4096″ in the "Tag Allowed" field of the V-Wire object.
  • B. Create VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/sub interface to a unique zone.
  • C. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the Tag Allowed" field of the V-Wire object. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each iinterface/sub interface to a unique zone.
  • D. Create Layer 3 subinterfaces that are each assigned tA. single VLAN ID and a common virtual router. The physical Layer 3 interface would handle untagged traffic. Assign each interface/subinterface tA. unique zone. Do not assign any interface an IP address.

Answer: C

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/vlan-tagged-traffic Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet.

 

NEW QUESTION 109
Which User-ID method maps IP addresses to usernames for users connecting through an 802.1x-enabled wireless network device that has no native integration with PAN-OS® software?

  • A. Client Probing
  • B. Server Monitoring
  • C. XML API
  • D. Port Mapping

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Captive Portal and the other standard user mapping methods might not work for certain types of user access. For example, the standard methods cannot add mappings of users connecting from a third-party VPN solution or users connecting to a 802.1x-enabled wireless network. For such cases, you can use the PAN-OS XML API to capture login events and send them to the PAN-OS integrated User-ID agent Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts

 

NEW QUESTION 110
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?

  • A. Apply an Anti-Spyware Profile with DNS sinkholing.
  • B. Use the DNS App-ID with application-default.
  • C. Enable packet buffer protection on the Zone Protection Profile.
  • D. Apply a classified DoS Protection Profile.

Answer: D

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/dos-protection-profiles To protect critical web or DNS servers on your network, protect the individual servers. To do this, set appropriate flooding and resource protection thresholds in a DoS protection profile, and create a DoS protection policy rule that applies the profile to each server's IP address by adding the IP addresses as the rule's destination criteria.

 

NEW QUESTION 111
Given the following table.

Which configuration change on the firewall would cause it to use 10.66.24.88 as the next hop for the
192.168.93.0/30 network?

  • A. Configuring the metric for RIP to be higher than that of OSPF Int.
  • B. Configuring the administrative Distance for RIP to be lower than that of OSPF Int.
  • C. Configuring the administrative Distance for RIP to be higher than that of OSPF Ext.
  • D. Configuring the metric for RIP to be lower than that OSPF Ext.

Answer: B

 

NEW QUESTION 112
SAML SLO is supported for which two firewall features? (Choose two.)

  • A. GlobalProtect Portal
  • B. CLI
  • C. CaptivePortal
  • D. WebUI

Answer: A,C

 

NEW QUESTION 113
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's firewall.

Which interface configuration will accept specific VLAN IDs?
Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)

  • A. Separate Log Forwarding profiles can be applied to rules 2 and 3.
  • B. Rule 2 and 3 apply to traffic on different ports.
  • C. A report can be created that identifies unclassified traffic on the network.
  • D. Different security profiles can be applied to traffic matching rules 2 and 3.

Answer: A,D

 

NEW QUESTION 114
A Security policy rule is configured with a Vulnerability Protection Profile and an action of 'Deny". Which action will this cause configuration on the matched traffic?

  • A. The configuration will allow the matched session unless a vulnerability signature is detected. The
    "Deny" action will supersede theper-severity defined actions defined in the associated Vulnerability Protection Profile.
  • B. The configuration is invalid. The Profile Settings section will be grayed out when the Action is set to
    "Deny".
  • C. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect ifthe Security policy rule action is set to "Deny."
  • D. The configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.

Answer: C

Explanation:
Explanation
"Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy."
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/security-profiles.html#

 

NEW QUESTION 115
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN-OS software. The firewall has internet connectivity through an Ethernet interface, but no internet connectivity from the management interface. The Security policy has the default security rules and a rule that allows all web-browsing traffic from any to any zone. What must the administrator configure so that the PAN-OS software can be upgraded?

  • A. Service route
  • B. Security policy rule
  • C. CRL
  • D. Scheduler

Answer: A

 

NEW QUESTION 116
Which three log-forwarding destinations require a server profile to be configured? (Choose three)

  • A. Panorama
  • B. Syslog
  • C. RADIUS
  • D. Kerberos
  • E. SNMP Trap
  • F. Email

Answer: B,E,F

Explanation:
Enable a Log Forwarding Profile (see step 4 below).
1. Select Objects > Log Forwarding Profile and Add a new security profile group.
2. Give the profile group a descriptive Name to help identify it when adding the profile to security policies or security zones.
3. If the firewall is in Multiple Virtual System Mode, enable the profile to be Shared by all virtual systems.
4. Add settings for the Traffic logs, Threat logs, and WildFire logs:
Select the Panorama check box for the severity of the Traffic, Threat, or WildFire logs that you want to be forwarded to Panorama.
Specify logs that you want to forward to additional destinations: SNMP Trap destinations, Email servers, or Syslog servers.
5. Click OK to save the log forwarding profile.
https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/reports-and-logging/log- forwarding-profiles.html

 

NEW QUESTION 117
Which three options are supported in HA Lite? (Choose three.)

  • A. Session synchronization
  • B. Configuration synchronization
  • C. Virtual link
  • D. Synchronization of IPsec security associations
  • E. Active/passive deployment

Answer: B,D,E

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/device/device- high-availability/ha-lite

 

NEW QUESTION 118
Which event will happen if an administrator uses an Application Override Policy?

  • A. App-ID processing time is increased.
  • B. Threat-ID processing time is decreased.
  • C. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.
  • D. The application name assigned to the traffic by the security rule is written to the Traffic log.

Answer: C

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override

 

NEW QUESTION 119
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of that commit task? (Choose two.)


  • A. Exhibit D
  • B. Exhibit A
  • C. Exhibit B
  • D. Exhibit C

Answer: A,B

 

NEW QUESTION 120
Which administrative authentication method supports authorization by an external service?

  • A. RADIUS
  • B. LDAP
  • C. SSH keys
  • D. Certificates

Answer: A

 

NEW QUESTION 121
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration Once deployed each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers Which VPN preconfigured configuration would adapt to changes when deployed to the future site?

  • A. GlobalProtect satellite
  • B. IPsec tunnels using IKEv2
  • C. GlobalProtect client
  • D. PPTP tunnels

Answer: A

 

NEW QUESTION 122
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a
third-party, deep-level packet inspection appliance.
Which interface type and license feature are necessary to meet the requirement?

  • A. Decryption Mirror interface with the Threat Analysis license
  • B. Decryption Mirror interface with the associated Decryption Port Mirror license
  • C. Virtual Wire interface with the Decryption Port Export license
  • D. Tap interface with the Decryption Port Mirror license

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/decryption-
concepts/decryption-mirroring

 

NEW QUESTION 123
Which three settings are defined within the Templates object of Panorama? (Choose three.)

  • A. Interfaces
  • B. Security
  • C. Application Override
  • D. Virtual Routers
  • E. Setup

Answer: A,D,E

 

NEW QUESTION 124
After pushing a security policy from Panorama to a PA-3020 firwall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs. What could be the problem?

  • A. The firewall is not licensed for logging to this Panorama device.
  • B. None of the firwwall's policies have been assigned a Log Forwarding profile
  • C. A Server Profile has not been configured for logging to this Panorama device.
  • D. Panorama is not licensed to receive logs from this particular firewall.

Answer: B

 

NEW QUESTION 125
Refer to the exhibit.

An administrator cannot see any of the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?
A)

B)

C)

D)

  • A. Option A
  • B. Option C
  • C. Option B
  • D. Option D

Answer: D

 

NEW QUESTION 126
Decrypted packets from the website https://www.microsoft.com will appear as which application and service within the Traffic log?

  • A. web-browsing and 80
  • B. web-browsing and 443
  • C. SSL and 443
  • D. SSL and 80

Answer: B

Explanation:
We know that SSL decryption is supposed to give us visibility of traffic that would otherwise be encrypted. Therefore, we'd expect decrypted traffic to be identified as the underlying applications, such as web-browsing, facebook-base or other, but not as SSL.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmdLCAS

 

NEW QUESTION 127
Which operation will impact performance of the management plane?

  • A. WildFire submissions
  • B. generating a SaaS Application report
  • C. decrypting SSL sessions
  • D. DoS protection

Answer: B

Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSvCAK

 

NEW QUESTION 128
Refer to the exhibit.

An administrator cannot see any if the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?
A:

B:

C:

D:

  • A. Option A
  • B. Option C
  • C. Option B
  • D. Option D

Answer: D

 

NEW QUESTION 129
......


Prerequisites for Taking PCNSE Certification Exam

The PCNSE certification has no prerequisites. However, to ensure that you’re well prepared for the real exam, Palo Alto recommends a couple of training sessions you should take. These courses were developed and authorized by the vendor itself:

  • The PCNSE Study Guide.
  • The Firewall Essentials: Configuration and Management (EDU-210);
  • The Firewall: Troubleshooting (330);
  • The Panorama: Managing Firewalls at Scale (EDU-220);

In addition to this, you’re expected to have six months of hands-on experience with the product being deployed.

 

New PCNSE Test Materials & Valid PCNSE Test Engine: https://www.actualtestsquiz.com/PCNSE-test-torrent.html

PCNSE Updated Exam Dumps [2021] Practice Valid Exam Dumps Question: https://drive.google.com/open?id=10GRvs2sI1F_mjwxcW1bf3fAeVVWC-fz1