Summer Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

PCNSC Sample Questions Answers

Questions 4

Which Captive Portal mode must becontoured to support MFA authentication?

Options:

A.

Single Sign-On

B.

Redirect

C.

Transparent

D.

NTLM

Buy Now
Questions 5

VPN traffic intended for an administrator's Palo Alto Networks NGfW is being maliciously intercepted and retransmitted by the interceptor. When Creating a VPN tunnel, which protection profile cm be enabled to prevent this malicious behavior?

Options:

A.

zone Protection

B.

Web Application

C.

DoS Protection

D.

Replay

Buy Now
Questions 6

A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch it connect.

How would an administrator configure the interface to IGbps?

Options:

A.

set deviceconfig system speed-duplex 10Gbps-full-duplex

B.

set deviceconfig interface speed-duplex 1Gbs--full-duplex

C.

set deviceconfig interface speed-duplex 1Gbs--half-duplex

D.

set deviceconfig system speed-duplex 1Gbs--half-duplex.

Buy Now
Questions 7

A user's traffic traversing a Palo Alto Networks NGFW sometime can reach http//www company com At the session times out. The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http //www company com.

How con the firewall be configured to automatically disable the PBF rule if thenext hop goes down?

Options:

A.

Configure path monitoring for tine next hop gateway on the default route in tin- virtual router.

B.

Enable and configure a Link Monitoring Profile for the external interface of the firewall.

C.

Create and add a Monitor Profile withan action of Wait Recover in the PBF rule in question.

D.

Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.

Buy Now
Questions 8

Winch three steps will reduce the CPU utilization on the management plane? (Choose three. ) Disable logging at session start in Security policies.

Options:

A.

Disable predefined reports.

B.

Reduce the traffic being decrypted by the firewall.

C.

Disable SNMP on the management interface.

D.

Application override of SSL application.

Buy Now
Questions 9

How does Panorama prompt VMware NSX to quarantine an in6erface VM??

Options:

A.

Syslog Server Profile

B.

Email Server Profile

C.

SNMP Server Profile

D.

HTTP Server Profile

Buy Now
Questions 10

What is exchanged through the HA2 link?

Options:

A.

hello heartbeats

B.

User-ID in information

C.

session synchronization

D.

HA state information

Buy Now
Questions 11

Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?

Options:

A.

No prerequisites are required

B.

SSH keys must be manually generated

C.

Both SSH keys and SSL certificates must be generated

D.

SSL certificates must be generated

Buy Now
Questions 12

View theGlobalProtect configuration screen capture.

What is the purpose of this configuration?

Options:

A.

It forces an internal client to connect to an internal gateway at IP address 192 168 10 I.

B.

It configures the tunnel address of all internal clients lo an IP address range starting at 192 168 10 1.

C.

It forces the firewall to perform a dynamic DNS update, Which adds the internal gateway's hostname and IP address to the DNS server.

D.

It enables a Client to perform a reverse DNS lookup on 192 .168. 10 .1. to delectit is an internal client.

Buy Now
Questions 13

What will be the egress interface if the traffic’s ingress interface is Ethernet 1/6 sourcing form 192.168.11.3 and to the destination 10.46.41.113.during the.

Options:

A.

ethernet 1/6

B.

ethernet 1/5

C.

ethernet 1/3

D.

ethernet 1/7

Buy Now
Questions 14

An administrator is using Panorama and multiple Palo Alto NetworksNGFWs. After upgrading all devices to the latest PAN-OS® software, the administrator enables logs forwarding from the firewalls to panorama Pre-existing logs from the firewall are not appearing in Panorama.

Which action would enables the firewalls to sendtheir preexisting logs to Panorama?

Options:

A.

A CLI command will forward the pre-existing logs to Panorama.

B.

Use the import option to pull logs panorama.

C.

Use the ACC to consolidate pre-existing logs.

D.

The- log database will need to be exported from thefirewall and manually imported into Panorama.

Buy Now
Questions 15

Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.)

Options:

A.

User-ID

B.

Antivirus

C.

Application and Threats

D.

Content-ID

Buy Now
Questions 16

Which feature prevents the submission of corporate login information into website forms?

Options:

A.

credential submission prevention

B.

file blocking

C.

User-ID

D.

data filtering

Buy Now
Questions 17

An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs. The administrator assigns priority 100 to the active firewall.

Which priority is collect tot the passive firewall?

Options:

A.

0

B.

1

C.

90

D.

255

Buy Now
Questions 18

When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.

Whatwill be the destination IP Address in that log entry?

Options:

A.

The IP Address of sinkhole.paloaltonetworks.com

B.

The IP Address of the command-and-control server

C.

The IP Address specified in the sinkhole configuration

D.

The IP Address of one of the externalDNS servers identified in the anti-spyware database

Buy Now
Questions 19

A web server is hosted in the DMZ and the server re configured to listen for income connections on TCP port 443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server host its contents over Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule.

Which combination of service and application, and order of Security policy rules needs to be configured to allow cleaned web-browsing traffic to the server on tcp/443?

Options:

A.

Rule# 1 application: ssl; service application-default: action allow

Role # 2 application web browsing, service application default, action allow

B.

Rule #1application web-browsing, service service imp action allow

Rule #2 application ssl. service application -default, action allow

C.

Rule#1 application web-brows.no service application-default, action allow

Rule #2 application ssl. Service application-default, action allow

D.

Rule#1application: web-biows.no;service service-https action allow

Rule#2 application ssl. Service application-default, action allow

Buy Now
Questions 20

Which option would an administration choose to define the certificate and protect that Panorama and its managed devices uses for SSL/ITS services?

Options:

A.

Set Up SSL/TLS under Policies > Service/URL Category > Service.

B.

Configure on SSL/TLS Profile.

C.

Configure a Decryption Profile and select SSL/TLS services.

D.

Set up Security policy rule to allow SSL communication.

Buy Now
Questions 21

A session in the Traffic log is reporting the application as "incomplete”

What does "incomplete" mean?

Options:

A.

The three-way TCP handshake did notcomplete.

B.

Data was received but wan instantly discarded because of a Deny policy was applied before App ID could be applied.

C.

The three-way TCP handshake was observed, but the application could not be identified.

D.

The traffic is coming across UDP, and the application could not be identified.

Buy Now
Questions 22

Which User-ID method should b configured to map addresses to usernames for users connected through a terminal server?

Options:

A.

XFF header

B.

Client probing

C.

port mapping

D.

server monitoring

Buy Now
Exam Code: PCNSC
Exam Name: Palo Alto Networks Certified Network Security Consultant
Last Update: May 16, 2024
Questions: 75
$64  $159.99
$48  $119.99
$40  $99.99
buy now PCNSC