[Oct-2021] PCNSC Pre-Exam Practice Tests | Exam Questions and Answers for Paloalto Certifications and Accreditations Study Guide
Palo Alto Networks Certified Network Security Consultant Certification Sample Questions
NEW QUESTION 44
An organization has Palo Alto Networks MGfWs that send logs to remote monitoring and security management platforms. The network team has report has excessive traffic on the corporate WAN. How could the Palo Alto Networks NOFW administrator reduce WAN traffic while maintaining support for all the existing monitoring/security platforms?
- A. Any configuration on an M-500 would address the insufficient bandwidth concerns.
- B. Configure log compression and optimization features on all remote firewalls.
- C. forward logs from firewalls only to Panorama, and have Panorama forward log* lo other external service.
- D. Forward logs from external sources to Panorama for correlation, arid from Panorama send to the NGFW
Answer: C
NEW QUESTION 45
An administrator has left a firewall to used default port for all management services.
Which three function performed by the dataplane? (Choose three.)
- A. file blocking
- B. antivirus
- C. NTP
- D. NAT
- E. WildFire updates
Answer: C,D,E
NEW QUESTION 46
Which two methods can be configured to validate the revocation status of a certificate? (Choose two)
- A. CRL
- B. SSL /TLS Service Profile
- C. CRT
- D. Cert-Validation-Profile
- E. OCSP
Answer: C,D
NEW QUESTION 47
A user's traffic traversing a Palo Alto Networks NGFW sometime can reach http//www company com At the session times out.
The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http //www company com.
How con the firewall be configured to automatically disable the PBF rule if the next hop goes down?
- A. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question.
- B. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.
- C. Enable and configure a Link Monitoring Profile for the external interface of the firewall.
- D. Configure path monitoring for tine next hop gateway on the default route in tin- virtual router.
Answer: B
NEW QUESTION 48
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using Link aggregation.
Which two formats are correct for naming aggregate interlaces? (Choose two.)
- A. ae.1
- B. aggregate.8
- C. aggregate.1
- D. ae.8
Answer: A,D
NEW QUESTION 49
Refer to the exhibit.
An administrator cannot see any of the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?
A)
B)
C)
D)
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: B
NEW QUESTION 50
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between panorama and the managed firewall and Log Collectors. How would the administrator establish the chain of trust?
- A. Set up multiple-factor authentication.
- B. Configure strong password
- C. Enable LDAP or RADIUS integration.
- D. Use custom certificates.
Answer: D
NEW QUESTION 51
A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN -OS software would help in this case?
- A. Virtual Wire mode
- B. application override
- C. content inspection
- D. redistribution of user mappings
Answer: D
NEW QUESTION 52
Which feature can be configured on VM-Series firewalls'?
- A. aggregate interlaces
- B. machine learning
- C. multiple virtual systems
- D. Globallprotect
Answer: D
NEW QUESTION 53
An administrator deploys PA-500 NGFWs as an active/passive high availability pair . The devices are not participating in dynamic router and preemption is disabled.
What must be verified to upgrade the firewalls to the most recent version of PAN OS software?
- A. Wildfire update package
- B. Applications and Threats update package
- C. User-ID agent
- D. Antivirus update package
Answer: B
NEW QUESTION 54
Which virtual router feature determines if a specific destination IP address is reachable'?
- A. Path Monitoring
- B. Ping-Path
- C. Heartbeat Monitoring
- D. Failover
Answer: A
NEW QUESTION 55
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-number or bacon out to eternal command-and-control (C2) servers.
Which Security Profile type will prevent these behaviors?
- A. Vulnerability Protection
- B. Antivirus
- C. Anti-Spyware
- D. Wildfire
Answer: C
NEW QUESTION 56
Which event will happen administrator uses an Application Override Policy?
- A. The Palo Alto Networks NGFW Steps App-ID processing at Layer 4.
- B. App-ID processing time is increased.
- C. The application name assigned to the traffic by the security rule is written to the traffic log.
- D. Threat-ID processing time is decreased.
Answer: A
NEW QUESTION 57
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?
- A. Security policy rule allowing SSL to the target server
- B. firewall connectivity to a CRL
- C. Root certificate imported into the firewall with "Trust" enabled
- D. importation of a certificate from an HSM
Answer: A
NEW QUESTION 58
An administrator has users accessing network resources through Citrix XenApp 7 .x. Which User-ID mapping solution will map multiple mat who using Citrix to connect to the network and access resources?
- A. Syslog Monitoring
- B. Globa1Protect
- C. Terminal Services agent
- D. Client Probing
Answer: C
NEW QUESTION 59
How would an administrator monitor/capture traffic on the management interface of the Palo Alto Networks NGFW?
- A. Enable all four stage of traffic capture (TX, RX, DROP, Firewall)
- B. Use the tcpdump command
- C. USe the debug dataplane packet-dia set capture stage firewall file command
- D. Use the debug dataplane packet-diag set capture stage management file command
Answer: B
NEW QUESTION 60
Which two methods can be used to verify firewall connectivity to Autofocus? (Choose two. )
- A. Check the WebUl Dashboard Autofocus widget
- B. Check for WildFire forwarding logs.
- C. Verify AutoFocus is enabled below Device Management tab
- D. Check the license
- E. Verify AutoFocus status using the CLI "test"command.
Answer: A,D
NEW QUESTION 61
What is exchanged through the HA2 link?
- A. hello heartbeats
- B. User-ID in information
- C. session synchronization
- D. HA state information
Answer: C
NEW QUESTION 62
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?
- A. The IP Address of the command-and-control server
- B. The IP Address specified in the sinkhole configuration
- C. The IP Address of sinkhole.paloaltonetworks.com
- D. The IP Address of one of the external DNS servers identified in the anti-spyware database
Answer: B
Explanation:
Explanation
https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Verify-DNS-Sinkhole-Function-is-Working/t
NEW QUESTION 63
Which three user authentication services can be modified in to provide the Palo Alto Networks NGFW with both username and role names? (Choose three.)
- A. TACACS+
- B. LDAP
- C. Kerberos
- D. RADIUS
- E. SAML
- F. PAP
Answer: A,B,D
NEW QUESTION 64
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch it connect.
How would an administrator configure the interface to IGbps?
- A. set deviceconfig interface speed-duplex 1Gbs--full-duplex
- B. set deviceconfig interface speed-duplex 1Gbs--half-duplex
- C. set deviceconfig system speed-duplex 10Gbps-full-duplex
- D. set deviceconfig system speed-duplex 1Gbs--half-duplex.
Answer: D
NEW QUESTION 65
Which PAN-OS policy must you configure to force a user to provide additional credential before he is allowed to access an internal application that contains highly sensitive business data?
- A. Decryption policy
- B. Authentication policy
- C. Application Override policy
- D. Security policy
Answer: B
NEW QUESTION 66
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- A. Restful API or the VMware API on the firewall or on the User.-D agent or the ready -only domain controller
- B. XML- API or lite VM Monitoring agent on the NGFW or on the User- ID agent
- C. Restful API or the VMware API on the firewall or on the User-ID Agent
- D. XML API or the VMware API on the firewall on the User-ID agent or the CLI
Answer: B
NEW QUESTION 67
Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.)
- A. Content-ID
- B. User-ID
- C. Application and Threats
- D. Antivirus
Answer: C,D
NEW QUESTION 68
View the GlobalProtect configuration screen capture.
What is the purpose of this configuration?
- A. It forces the firewall to perform a dynamic DNS update, Which adds the internal gateway's hostname and IP address to the DNS server.
- B. It configures the tunnel address of all internal clients lo an IP address range starting at 192 168 10 1.
- C. It enables a Client to perform a reverse DNS lookup on 192 .168. 10 .1. to delect it is an internal client.
- D. It forces an internal client to connect to an internal gateway at IP address 192 168 10 I.
Answer: C
NEW QUESTION 69
......
Palo Alto Networks Exam Practice Test To Gain Brilliante Result: https://www.dumpexams.com/PCNSC-real-answers.html
Tested Material Used To PCNSC: https://drive.google.com/open?id=1DUUiucH0t_CG8u1_8lWAr4bDJY9cHk1i