[Sep-2021] Pass Palo Alto Networks PCNSE Exam in First Attempt Guaranteed!
Full PCNSE Practice Test and 337 unique questions with explanations waiting just for you, get it now!
NEW QUESTION 55
Which CLI command can be used to export the tcpdump capture?
- A. download mgmt.-pcap
- B. scp export tcpdump from mgmt.pcap to <username@host:path>
- C. scp extract mgmt-pcap from mgmt.pcap to <username@host:path>
- D. scp export mgmt-pcap from mgmt.pcap to <username@host:path>
Answer: D
Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-Interface/ta- p/55415
NEW QUESTION 56
To protect your firewall and network from single source denial of service (DoS) attacks that can overwhelm its packet buffer and cause legitimate traffic to drop, you can configure:
- A. PBP (Protocol Based Protection)
- B. BGP (Border Gateway Protocol)
- C. PGP (Packet Gateway Protocol)
- D. PBP (Packet Buffer Protection)
Answer: D
Explanation:
Explanation/Reference: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/zone-protection-and-dos- protection/zone-defense/packet-buffer-protection
NEW QUESTION 57
Which version of GlobalProtect supports split tunneling based on destination domain, client process, and HTTP/HTTPS video streaming application?
- A. GlobalProtect version 4.0 with PAN-OS 8.0
- B. GlobalProtect version 4.0 with PAN-OS 8.1
- C. GlobalProtect version 4.1 with PAN-OS 8.1
- D. GlobalProtect version 4.1 with PAN-OS 8.0
Answer: C
NEW QUESTION 58
Which CLI command can be used to export the tcpdump capture?
- A. download mgmt.-pcap
- B. scp export tcpdump from mgmt.pcap to <username@host:path>
- C. scp extract mgmt-pcap from mgmt.pcap to <username@host:path>
- D. scp export mgmt-pcap from mgmt.pcap to <username@host:path>
Answer: D
NEW QUESTION 59
What are three valid options when creating a new security policy? (Choose three.)
- A. Alert
- B. Block
- C. Deny
- D. Reset client
- E. Allow
- F. Deny All
- G. Reset All
Answer: C,D,E
Explanation:
NEW QUESTION 60
Which virtual router feature determines if a specific destination IP address is reachable?
- A. Path Monitoring
- B. Ping-Path
- C. Heartbeat Monitoring
- D. Failover
Answer: A
Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/pbf
NEW QUESTION 61
In High Availability, which information is transferred via the HA data link?
- A. session information
- B. User-ID information
- C. heartbeats
- D. HA state information
Answer: A
Explanation:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high- availability/ha-links-and-backup-links
NEW QUESTION 62
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- A. Restful API or the VMware API on the firewall or on the User-ID agent
- B. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)
- C. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
- D. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
Answer: C
NEW QUESTION 63
Which method does an administrator use to integrate all non-native MFA platforms in PAN-OS® software?
- A. Okta
- B. PingID
- C. RADIUS
- D. DUO
Answer: C
Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/authentication-types/multi-factor-authentication
NEW QUESTION 64
How can a candidate or running configuration be copied to a host external from Panorama?
- A. Save a configuration snapshot.
- B. Commit a running configuration.
- C. Save a candidate configuration.
- D. Export a named configuration snapshot.
Answer: D
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/administer-panorama/ba panorama-and-firewall-configurations
NEW QUESTION 65
What are two benefits of nested device groups in Panorama? (Choose two.)
- A. All device groups inherit settings form the Shared group
- B. Reuse of the existing Security policy rules and objects
- C. Requires configuring both function and location for every device
- D. Overwrites local firewall configuration
Answer: A,B
Explanation:
Creation of a device group hierarchy enables you to organize firewalls based on common policy requirements without redundant configuration. When you create objects for use in shared or device group policy once and use them many times, you reduce administrative overhead and ensure consistency across firewall policies.
NEW QUESTION 66
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance.
Which interface type and license feature are necessary to meet the requirement?
- A. Virtual Wire interface with the Decryption Port Export license
- B. Decryption Mirror interface with the associated Decryption Port Mirror license
- C. Tap interface with the Decryption Port Mirror license
- D. Decryption Mirror interface with the Threat Analysis license
Answer: B
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/decryption-mirroring
NEW QUESTION 67
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet
1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP address of Ethernet
1/4 is 10.1.1.7. The default gateway is attached to Ethernet 1/1. A default route is properly configured.
What can be the cause of this problem?
- A. Interface Ethernet 1/1 is in Virtual Wire Mode.
- B. DNS has not been properly configured on the firewall.
- C. No Zone has been configured on Ethernet 1/4.
- D. DNS has not been properly configured on the host.
Answer: C
NEW QUESTION 68
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS software, the administrator enables log forwarding from the firewalls to Panorama. Pre-existing logs from the firewalls are not appearing in Panorama.
Which action would enable the firewalls to send their pre-existing logs to Panorama?
- A. A CLI command will forward the pre-existing logs to Panorama.
- B. Use the import option to pull logs into Panorama.
- C. The log database will need to exported form the firewalls and manually imported into Panorama.
- D. Use the ACC to consolidate pre-existing logs.
Answer: A
NEW QUESTION 69
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.
Which configuration will enable this HA scenario?
- A. The firewalls will share the same interface IP address, and device 1 will use the floating IP if device 0 fails.
- B. The two firewalls will share a single floating IP and will use gratuitous ARP to share the floating IP.
- C. Each firewall will have a separate floating IP, and priority will determine which firewall has the primary IP.
- D. The firewalls do not use floating IPs in active/active HA.
Answer: B
Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability/floating-ip- address-and-virtual-mac-address
NEW QUESTION 70
Which three steps will reduce the CPU utilization on the management plane? (Choose three.)
- A. Disable SNMP on the management interface.
- B. Disable logging at session start in Security policies.
- C. Reduce the traffic being decrypted by the firewall.
- D. Disable predefined reports.
- E. Application override of SSL application.
Answer: A,B,D
Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleLCAS
NEW QUESTION 71
An administrator wants to upgrade an NGFW from PAN-OS 7.1.2 to PAN-OS 8.1.0. The firewall is not a part of an HA pair.
What needs to be updated first?
- A. PAN-OS Upgrade Agent
- B. WildFire
- C. Applications and Threats
- D. XML Agent
Answer: B
NEW QUESTION 72
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
- A. .apk
- B. .exe
- C. .jar
- D. .dll
- E. .pdf
- F. .src
Answer: A,C,E
Explanation:
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/getting-started/enable-basic-wildfire-forwarding
NEW QUESTION 73 
What will be the source address in the ICMP packet?
- A. 10.30.0.93
- B. 192.168.93.1
- C. 10.46.72.93
- D. 10.46.64.94
Answer: D
NEW QUESTION 74
Which three function are found on the dataplane of a PA-5050? (Choose three)
- A. Dynamic routing
- B. Signature Match
- C. Network Processing
- D. Protocol Decoder
- E. Management
Answer: A,B,C
Explanation:
In these devices, dataplane zero, or dp0 for short, functions as the master dataplane and determines which dataplane will be used as the session owner that is responsible for processing and inspection.
The data plane provides all data processing and security detection and enforcement, including:
* (B) All networking connectivity, packet forwarding, switching, routing, and network address translation
* Application identification, using the content of the applications, not just port or protocol
* SSL forward proxy, including decryption and re-encryption
* Policy lookups to determine what security policy to enforce and what actions to take, including scanning for threats, logging, and packet marking
* Application decoding, threat scanning for all types of threats and threat prevention
* Logging, with all logs sent to the control plane for processing and storage E: The following diagram depicts both the hardware and software architecture of the next- generation firewall
Incorrect Answers:
C: Management is done in the control plane.
https://www.niap-ccevs.org/st/st_vid10392-st.pdf
NEW QUESTION 75
When performing the "ping" test shown in this CLI output:
What will be the source address in the ICMP packet?
- A. 10.30.0.93
- B. 192.168.93.1
- C. 10.46.72.93
- D. 10.46.64.94
Answer: D
NEW QUESTION 76
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10.1.1.22 Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?
- A.
- B.
- C. Option D
- D.
- E. Option A
- F. Option B
- G. Option C
- H.
Answer: H
NEW QUESTION 77
A customer has an application that is being identified as unknown-top for one of their custom PostgreSQL database connections. Which two configuration options can be used to correctly categorize their custom database application? (Choose two.)
- A. Custom application.
- B. Application Override policy.
- C. Security policy to identify the custom application.
- D. Custom Service object.
Answer: A,B
Explanation:
Explanation
Unlike the App-ID engine, which inspects application packet contents for unique signature elements, the Application Override policy's matching conditions are limited to header-based data only. Traffic matched by an Application Override policy is identified by the App-ID entered in the Application entry box.Choices are limited to applications currently in the App-ID database.Because this traffic bypasses all Layer 7 inspection, the resulting security is that of a Layer-4 firewall. Thus, this traffic should be trusted without the need for Content-ID inspection. The resulting application assignment can be used in other firewall functions such as Security policy and QoS.Use CasesThree primary uses cases for Application Override Policy are:
To identify "Unknown" App-IDs with a different or custom application signature To re-identify an existing application signature To bypass the Signature Match Engine (within the SP3 architecture) to improve processing timesA discussion of typical uses of application override and specific implementation examples is here:https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application- Ov
NEW QUESTION 78
An administrator creates an SSL decryption rule decrypting traffic on all ports.
The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs.
There are three entries. The first entry shows traffic dropped as application Unknown.
The next two entries show traffic allowed as application SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?
- A. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the top of the Security policy.
- B. Disable the exclude cache option for the firewall.
- C. Create a decryption rule matching the encrypted BitTorrent traffic with action "No-Decrypt," and place the rule at the top of the Decryption policy.
- D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.
Answer: D
NEW QUESTION 79
......
Prepare for your Palo Alto Networks certification with the updated TestBraindump PCNSE exam questions: https://drive.google.com/open?id=1bAIuW8jq9JLw0kou_BZUZ-BdE-9SftL2
Get Latest PCNSE Dumps Exam Questions in here: https://www.testbraindump.com/PCNSE-exam-prep.html
