Buy Latest Jan 25, 2022 PCNSE Exam Q&A PDF - One Year Free Update [Q216-Q235]

Share

Buy Latest Jan 25, 2022 PCNSE Exam Q&A PDF - One Year Free Update

Download the Latest PCNSE Dump - 2022 PCNSE Exam Questions

NEW QUESTION 216
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)

  • A. The traffic does not match the packet capture filter.
  • B. The firewall is in multi-vsys mode.
  • C. The traffic is offloaded.
  • D. The firewall's DP CPU is higher than 50%.

Answer: A,C

 

NEW QUESTION 217
A VPN connection is set up between Site-A and Site-B, but no traffic is passing in the system log of Site-A, there is an event logged as like-nego-p1-fail-psk.
What action will bring the VPN up and allow traffic to start passing between the sites?

  • A. Change the Site-B IKE Gateway profile version to match Site-A,
  • B. Change the Site-A IKE Gateway profile exchange mode to aggressive mode.
  • C. Enable NAT Traversal on the Site-A IKE Gateway profile.
  • D. Change the pre-shared key of Site-B to match the pre-shared key of Site-A

Answer: D

 

NEW QUESTION 218
An enterprise information Security team has deployed policies based on AD groups to restrict user access to critical infrastructure systems However a recent phisning campaign against the organization has prompted Information Security to look for more controls that can secure access to critical assets For users that need to access these systems Information Security wants to use PAN-OS multi-factor authentication (MFA) integration to enforce MFA.
What should the enterprise do to use PAN-OS MFA1?

  • A. Use a Credential Phishing agent to detect prevent and mitigate credential phishing campaigns
  • B. Configure a Captive Portal authentication policy that uses an authentication sequence
  • C. Create an authentication profile and assign another authentication factor to be used by a Captive Portal authentication policy
  • D. Configure a Captive Porta1 authentication policy that uses an authentication profile that references a RADIUS profile

Answer: B

 

NEW QUESTION 219
Site-A and Site-B have a site-to-site VPN set up between them. OSPF is configured to dynamically create the routes between the sites. The OSPF configuration in Site-A is configured properly, but the route for the tunner is not being established. The Site-B interfaces in the graphic are using a broadcast Link Type. The administrator has determined that the OSPF configuration in Site-B is using the wrong Link Type for one of its interfaces.

Which Link Type setting will correct the error?

  • A. Set tunnel. 1 to p2p
  • B. Set Ethernet 1/1 to p2p
  • C. Set Ethernet 1/1 to p2mp
  • D. Set tunnel. 1 to p2mp

Answer: A

 

NEW QUESTION 220
Which two settings can be configured only locally on the firewall and not pushed from a Panorama
template or template stack? (Choose two.)

  • A. Zone Protection Profile
  • B. HA1 IP Address
  • C. Network Interface Type
  • D. Master Key

Answer: B,D

 

NEW QUESTION 221
When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?

  • A. To enable client machine authentication to the Portal
  • B. To enable user authentication to the Portal
  • C. To enable Portal authentication to the Gateway
  • D. To enable Gateway authentication to the Portal

Answer: B

Explanation:
The additional options of Browser and Satellite enable you to specify the authentication profile to use for specific scenarios. Select Browser to specify the authentication profile to use to authenticate a user accessing the portal from a web browser with the intent of downloading the GlobalProtect agent (Windows and Mac). Select Satellite to specify the authentication profile to use to authenticate the satellite.
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface- help/globalprotect/network-globalprotect-portals

 

NEW QUESTION 222
In High Availability, which information is transferred via the HA data link?

  • A. session information
  • B. HA state information
  • C. User-ID information
  • D. heartbeats

Answer: A

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/ha- concepts/ha-links-and-backup-links

 

NEW QUESTION 223
In a firewall, which three decryption methods are valid? (Choose three )

  • A. Decryption Mirror
  • B. SSL Outbound Proxyless Inspection
  • C. SSL Inbound Inspection
  • D. SSH Proxy
  • E. SSL Inbound Proxy

Answer: A,C,D

 

NEW QUESTION 224
Which feature prevents the submission of corporate login information into website forms?

  • A. Credential phishing prevention
  • B. Data filtering
  • C. File blocking
  • D. User-ID

Answer: A

Explanation:
Reference:
https://www.paloaltonetworks.com/cyberpedia/how-the-next-generation-security-platform-contributes-to-gdpr-co
"Credential phishing prevention works by scanning username and password submissions to websites and comparing those submissions against valid corporate credentials. You can choose what websites you want to either allow, alert on, or block corporate credential submissions to based on the URL category of the website. Alternatively, you can present a page that warns users against submitting credentials to sites classified in certain URL categories. This gives you the opportunity to educate users against reusing corporate credentials, even on legitimate, non-phishing sites. In the event that corporate credentials are compromised, this feature allows you to identify the user who submitted credentials so that you can remediate."

 

NEW QUESTION 225
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's firewall.

Which interface configuration will accept specific VLAN IDs?
Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)

  • A. Different security profiles can be applied to traffic matching rules 2 and 3.
  • B. A report can be created that identifies unclassified traffic on the network.
  • C. Rule 2 and 3 apply to traffic on different ports.
  • D. Separate Log Forwarding profiles can be applied to rules 2 and 3.

Answer: A,D

 

NEW QUESTION 226
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)

  • A. SAML
  • B. TACACS+
  • C. PAP
  • D. RADIUS
  • E. Kerberos
  • F. LDAP

Answer: A,B,D

Explanation:
Explanation/Reference:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manage-firewall- administrators/administrative-authentication

 

NEW QUESTION 227
An administrator has configured the Palo Alto Networks NGFW's management interface to connect to the internet through a dedicated path that does not traverse back through the NGFW itself.
Which configuration setting or step will allow the firewall to get automatic application signature updates?

  • A. A scheduler will need to be configured for application signatures.
  • B. A service route will need to be configured.
  • C. A Threat Prevention license will need to be installed.
  • D. A Security policy rule will need to be configured to allow the update requests from the firewall to the update servers.

Answer: B

Explanation:
The firewall uses the service route to connect to the Update Server and checks for new content release versions and, if there are updates available, displays them at the top of the list.
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface- help/device/device-dynamic-updates

 

NEW QUESTION 228
Refer to the exhibit.

Which will be the egress interface if the traffic's ingress interface is ethernet 1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?

  • A. ethernet1/3
  • B. ethernet1/5
  • C. ethernet1/6
  • D. ethernet1/7

Answer: B

 

NEW QUESTION 229
In a security-first network what is the recommended threshold value for content updates to be dynamically updated?

  • A. 36 hours
  • B. 1 to 4 hours
  • C. 24 hours
  • D. 6 to 12 hours

Answer: D

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/best-practices-for-content-and-thre

 

NEW QUESTION 230
A network security engineer for a large company has just installed a PA-5060 Firewall to isolate the company's PCI environment from its production network. The company's network engineers made configuration changes to the switches on both network segments, and connected them to the new firewall.
Soon after the cutover, however, users began to complain about latency and some servers stopped communicating. There are no security policies that deny traffic between the two network segments. You suspect that there is an interface misconfiguration on ethernet1/1.
Which two commands should be used to troubleshoot the issue? (Choose two.)

  • A. show interface management
  • B. show interface ethernet1/1
  • C. show interface logical
  • D. show interface hardware

Answer: B,C

 

NEW QUESTION 231
A network security engineer needs to configure a virtual router using IPv6 addresses.
Which two routing options support these addresses? (Choose two)

  • A. Static Route
  • B. RIP
  • C. OSPFv3
  • D. BGP not sure

Answer: A,C

Explanation:
Explanation: https://live.paloaltonetworks.com/t5/Management-Articles/Does-PAN-OS- Support-Dynamic-Routing-Protocols-OSPF-or-BGP-with/ta-p/62773

 

NEW QUESTION 232
Refer to the exhibit.

Which will be the egress interface if the traffic's ingress interface is ethernet 1/7 sourcing from
192.168.111.3 and to the destination 10.46.41.113?

  • A. ethernet1/3
  • B. ethernet1/5
  • C. ethernet1/6
  • D. ethernet1/7

Answer: B

 

NEW QUESTION 233
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the Runtime Stats and look for problems with BGP configuration.
  • B. Perform a traffic pcap on the NGFW to see any BGP problems.
  • C. View the System logs and look for the error messages about BGP.
  • D. View the ACC tab to isolate routing issues.

Answer: A,D

 

NEW QUESTION 234
An administrator has a PA-820 firewall with an active Threat Prevention subscription The administrator is considering adding a WildFire subscription.
How does adding the WildFire subscription improve the security posture of the organization1?

  • A. WildFire and Threat Prevention combine to provide the utmost security posture for the firewall
  • B. WildFire and Threat Prevention combine to minimize the attack surface
  • C. Protection against unknown malware can be provided in near real-time
  • D. After 24 hours WildFire signatures are included in the antivirus update

Answer: D

 

NEW QUESTION 235
......

Verified PCNSE Dumps Q&As - 1 Year Free & Quickly Updates: https://www.dumpsreview.com/PCNSE-exam-dumps-review.html

Latest Palo Alto Networks PCNSE Certification Practice Test Questions: https://drive.google.com/open?id=1ncpxdcRDdEJe1INUY8JkjDkkQTq1j47z