[Sep-2021] PCNSE PCNSE Exam Practice Dumps [Q39-Q59]

Share

[Sep-2021] PCNSE PCNSE Exam Practice Dumps

2021 PCNSE Premium Files Test pdf - Free Dumps Collection

NEW QUESTION 39
TRUE or FALSE: Many customers purchase Palo Alto Networks NGFWs (Next Generation Firewalls) just to gain previously unavailable levels of visibility into their traffic flows.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 40
To connect the Palo Alto Networks firewall to AutoFocus, which setting must be enabled?

  • A. AutoFocus is enabled by default on the Palo Alto Networks NGFW
  • B. Device>Setup> Management> Logging and Reporting Settings
  • C. Device> Setup>Management >AutoFocus
  • D. Device>Setup>WildFire>AutoFocus
  • E. Device>Setup>Services>AutoFocus

Answer: C

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/getting-started/enable-
autofocus-threat-intelligence

 

NEW QUESTION 41
Which four NGFW multi-factor authentication factors are supported by PAN-OS? (Choose four.)

  • A. Short message service
  • B. Voice
  • C. Push
  • D. One-Time Password
  • E. SSH key
  • F. User logon

Answer: A,B,C,D

 

NEW QUESTION 42
Which is not a valid reason for receiving a decrypt-cert-validation error?

  • A. Client authentication
  • B. Unsupported HSM
  • C. Untrusted issuer
  • D. Unknown certificate status

Answer: D

 

NEW QUESTION 43
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?

  • A. The IP Address of the command-and-control server
  • B. The IP Address specified in the sinkhole configuration
  • C. The IP Address of sinkhole.paloaltonetworks.com
  • D. The IP Address of one of the external DNS servers identified in the anti-spyware database

Answer: B

Explanation:
https://live.paloaltonetworks.com/t5/MaHYPERLINK
"https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Verify-DNS-Sinkhole-Function- is-Working/ta-p/65864"naHYPERLINK "https://live.paloaltonetworks.com/t5/Management- Articles/How-to-Verify-DNS-Sinkhole-Function-is-Working/ta-p/65864"gement-Articles/How-to- Verify-DNS-Sinkhole-Function-is-Working/ta-p/65864

 

NEW QUESTION 44
Which DoS protection mechanism detects and prevents session exhaustion attacks?

  • A. TCP Port Scan Protection
  • B. Flood Protection
  • C. Packet Based Attack Protection
  • D. Resource Protection

Answer: D

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/dos-protection- profiles

 

NEW QUESTION 45
Refer to the exhibit.

Which certificates can be used as a Forward Trust certificate?

  • A. Domain Sub-CA
  • B. Certificate from Default Trust Certificate Authorities
  • C. Forward_Trust
  • D. Domain-Root-Cert

Answer: B

 

NEW QUESTION 46
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown.
The next two entries show traffic allowed as application SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?

  • A. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the top of the Security policy.
  • B. Disable the exclude cache option for the firewall.
  • C. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.
  • D. Create a decryption rule matching the encrypted BitTorrent traffic with action "No- Decrypt," and place the rule at the top of the Decryption policy.

Answer: C

 

NEW QUESTION 47
Which two settings can be configured only locally on the firewall and not pushed from a Panorama
template or template stack? (Choose two.)

  • A. Network Interface Type
  • B. Master Key
  • C. HA1 IP Address
  • D. Zone Protection Profile

Answer: B,C

 

NEW QUESTION 48
A company has a web server behind a Palo Alto Networks next-generation firewall that it wants to make accessible to the public at 1.1.1.1. The company has decided to configure a destination NAT Policy rule.
Given the following zone information:
DMZ zone: DMZ-L3
Public zone: Untrust-L3
Guest zone: Guest-L3
Web server zone: Trust-L3
Public IP address (Untrust-L3): 1.1.1.1
Private IP address (Trust-L3): 192.168.1.50
What should be configured as the destination zone on the Original Packet tab of NAT Policy rule?

  • A. Untrust-L3
  • B. Trust-L3
  • C. DMZ-L3
  • D. Guest-L3

Answer: A

Explanation:
Create the NAT policy.
1. Select Policies > NAT and click Add.
2. Enter a descriptive Name for the policy.
3. On the Original Packet tab, select the zone you created for your internal network in the Source Zone section (click Add and then select the zone) and the zone you created for the external network from the Destination Zone drop down.
4. On the Translated Packet tab, select Dynamic IP And Port from the Translation Type drop- down in the Source Address Translation section of the screen and then click Add. Select the address object you just created.
5. Click OK to save the NAT policy.
https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/configure-nat- policies

 

NEW QUESTION 49
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service?
(Choose three.)

  • A. .apk
  • B. .exe
  • C. .jar
  • D. .dll
  • E. .pdf
  • F. .src

Answer: A,C,E

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/wildfire-overview/wildfire-file-type-su

 

NEW QUESTION 50
Panorama provides which two SD_WAN functions? (Choose two.)

  • A. network monitoring
  • B. control plane
  • C. data plane
  • D. physical network links

Answer: B,D

 

NEW QUESTION 51
Which CLI command displays the current management plane memory utilization?

  • A. > show running resource-monitor
  • B. > show system resources
  • C. > show system info
  • D. > debug management-server show

Answer: B

Explanation:
When running show system resources from the PAN-OS CLI, the top process in the output shows
9999% CPU utilization.
The following is an example output:
> show system resources

https://live.paloaltonetworks.com/t5/Management-Articles/Show-System-Resource- CommandDisplays-CPU-Utilization-of-9999/ta-p/58149

 

NEW QUESTION 52
PBF can address which two scenarios? (Select Two)

  • A. enabling the firewall to bypass Layer 7 inspection
  • B. forwarding all traffic by using source port 78249 to a specific egress interface
  • C. routing FTP to a backup ISP link to save bandwidth on the primary ISP link
  • D. providing application connectivity the primary circuit fails

Answer: A,B

 

NEW QUESTION 53
Refer to the exhibit.

Which certificates can be used as a Forwarded Trust certificate?

  • A. Certificate from Default Trust Certificate Authorities
  • B. Forward_Trust
  • C. Domain Sub-CA
  • D. Domain-Root-Cert

Answer: C

 

NEW QUESTION 54
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance.
Which interface type and license feature are necessary to meet the requirement?

  • A. Virtual Wire interface with the Decryption Port Export license
  • B. Decryption Mirror interface with the associated Decryption Port Mirror license
  • C. Tap interface with the Decryption Port Mirror license
  • D. Decryption Mirror interface with the Threat Analysis license

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/decryption- concepts/decryption-mirroring

 

NEW QUESTION 55
Click the Exhibit button below,


A firewall has three PBF rules and a default route with a next hop of 172.20.10.1 that is configured in the default VR. A user named Will has a PC with a 192.168.10.10 IP address. He makes an HTTPS connection to
172.16.10.20.
Which is the next hop IP address for the HTTPS traffic from Will's PC?

  • A. 172.20.10.1
  • B. 172.20.30.1
  • C. 172.20.40.1
  • D. 172.20.20.1

Answer: D

 

NEW QUESTION 56
An administrator wants to upgrade an NGFW from PAN-OS® 8.0.2 to PAN-OS® 9.0. The firewall is not a part of an HA pair. What needs to be updated first?

  • A. PAN-OS® Upgrade Agent
  • B. WildFire
  • C. Applications and Threats
  • D. XML Agent

Answer: C

Explanation:
https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/upgrade-to-pan-os-80/upgrade-the-firewall-to-pan-os-80/upgrade-a-firewall-to-pan-os-80

 

NEW QUESTION 57
Which is the maximum number of samples that can be submitted to WildFire per day, based on a WildFire subscription?

  • A. 7,500
  • B. 5,000
  • C. 15,000
  • D. 10,000

Answer: D

 

NEW QUESTION 58
Which log file can be used to identify SSL decryption failures?

  • A. Configuration
  • B. Threats
  • C. Traffic
  • D. ACC

Answer: D

 

NEW QUESTION 59
......

Get ready to pass the PCNSE Exam right now using our PCNSE  Exam Package: https://www.passtestking.com/Palo-Alto-Networks/PCNSE-practice-exam-dumps.html

A fully updated 2021 PCNSE Exam Dumps exam guide from training expert PassTestking: https://drive.google.com/open?id=1L0RP2yF6vXCz6gBufYm0UaE4oog_x-UT