Get Nov-2022 updated Exam PCNSE Dumps with New Questions [Q85-Q104]

Share

Get Nov-2022 updated Exam PCNSE Dumps with New Questions

100% Pass Guarantee for PCNSE Exam Dumps with Actual Exam Questions


PCNSE: Career Bonuses

The professionals with the PCNSE certification will have a good position and will be chosen over other candidates. Besides that, they can receive higher salaries. Their knowledge base can be useful for the job roles, such as a Network Security Engineer, an Enterprise Network Engineer/Admin, an Information Security Analyst, a Senior Palo Alto Network Specialist, a Network Administrator, and more. The average salary ranges from $75,000 to $120,000 per year.

 

NEW QUESTION 85
While troubleshooting an SSL Forward Proxy decryption issue which PAN-OS CLI command would you use to check the details of the end-entity certificate that is signed by the Forward Trust Certificate or Forward Untrust Certificate?

  • A. show systen setting ssl-decrypt certificate
  • B. show systea setting ssl-decrypt certificate-cache
  • C. show system setting ssl-decrypt certs
  • D. debug dataplane show ssl-decrypt ssl-stats

Answer: A

 

NEW QUESTION 86
An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panorama?

  • A. Both the active and passive firewalls, which then synchronize with each other
  • B. The Passive firewall, which then synchronizes to the active firewall
  • C. The active firewall, which then synchronizes to the passive firewall
  • D. Both the active and passive firewalls independently, with no synchronization afterward

Answer: D

Explanation:
Explanation
Palo Alto NetworksPanorama 7.0 Administrator's Guide *77Manage FirewallsManage Device GroupsManage Device GroupsAdd a Device GroupCreate a Device Group HierarchyCreate Objects for Use in Shared or Device Group PolicyRevert to Inherited Object ValuesManage Unused Shared Objects Manage Precedence of Inherited ObjectsMove or Clone a Policy Rule or Object to a Different Device GroupSelect a URL Filtering Vendor on PanoramaPush a Policy Rule to a Subset of FirewallsManage the Rule HierarchyAdd a Device GroupAfter adding firewalls (see Add a Firewall as a Managed Device), you can group them into Device Groups (up to 256), as follows. Be sure to assign both firewalls in an active-passive high availability (HA) configuration to the same device group so that Panorama will push the same policy rules and objects to those firewalls. #############PAN-OS doesn't synchronize pushed rules across HA peers.######### To manage rules and objects at different administrative levels in your organization, Create a Device Group Hierarchy.
https://docs.paloaltonetworks.com/panorama/8-0/panorama-admin/manage-firewalls/transition-a-firewall-to-pano

 

NEW QUESTION 87
Which event will happen if an administrator uses an Application Override Policy?

  • A. The application name assigned to the traffic by the security rule is written to the Traffic log.
  • B. App-ID processing time is increased.
  • C. Threat-ID processing time is decreased.
  • D. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.

Answer: D

Explanation:
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override

 

NEW QUESTION 88
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)

  • A. The firewall is in multi-vsys mode.
  • B. The traffic is offloaded.
  • C. The firewall's DP CPU is higher than 50%.
  • D. The traffic does not match the packet capture filter.

Answer: B,D

Explanation:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/monitoring/take-packet- captures/disable-hardware-offload

 

NEW QUESTION 89
Which method will dynamically register tags on the Palo Alto Networks NGFW?

  • A. Restful API or the VMware API on the firewall or on the User-ID agent
  • B. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
  • C. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
  • D. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)

Answer: B

Explanation:
Reference:
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/monitor-changes-in-the-virtual-environmen dynamically register tags, you can use the XML API or the VM Monitoring agent on the firewall or on the User-ID agent. Each tag is a metadata element or attribute-value pair that is registered on the firewall or Panorama. For example, IP1 {tag1, tag2,.....tag32}, w"

 

NEW QUESTION 90
Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?

  • A. No Direct Access to local networks
  • B. Tunnel mode
  • C. Satellite mode
  • D. IPSec mode

Answer: A

Explanation:
https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-access-route.html

 

NEW QUESTION 91
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.
Which configuration will enable this HA scenario?

  • A. Each firewall will have a separate floating IP, and priority will determine which firewall has the primary IP.
  • B. The two firewalls will share a single floating IP and will use gratuitous ARP to share the floating IP.
  • C. The firewalls do not use floating IPs in active/active HA.
  • D. The firewalls will share the same interface IP address, and device 1 will use the floating IP if device 0 fails.

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability/floating-ip- address-and-virtual-mac-address

 

NEW QUESTION 92
Refer to the exhibit.

A web server in the DMZ is being mapped to a public address through DNAT.
Which Security policy rule will allow traffic to flow to the web server?

  • A. Untrust (any) to DMZ (10. 1. 1. 100), web browsing - Allow
  • B. Untrust (any) to DMZ (1. 1. 1. 100), web browsing - Allow
  • C. Untrust (any) to Untrust (1. 1. 1. 100), web browsing - Allow
  • D. Untrust (any) to Untrust (10. 1.1. 100), web browsing - Allow

Answer: B

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/nat/nat-configuration-examples/destinat

 

NEW QUESTION 93
An administrator needs to upgrade an NGFW to the most current version of PAN-OS software. The following is occurring:
*Firewall has Internet connectivity through e1/1.
*Default security rules and security rules allowing all SSL and web-browsing traffic to and from any zone.
*Service route is configured, sourcing update traffic from e1/1.
*A communication error appears in the System logs when updates are performed.
*Download does not complete.
What must be configured to enable the firewall to download the current version of PAN-OS software?

  • A. Security policy rule allowing PaloAlto-updates as the application
  • B. DNS settings for the firewall to use for resolution
  • C. scheduler for timed downloads of PAN-OS software
  • D. static route pointing application PaloAlto-updates to the update servers

Answer: A

 

NEW QUESTION 94

  • A. Pre-existing logs from the firewalls are not appearing in PanoramA.
    Which action would enable the firewalls to send their pre-existing logs to Panorama?
  • B. The log database will need to exported form the firewalls and manually imported into Panorama.
  • C. Use the ACC to consolidate pre-existing logs.
  • D. A CLI command will forward the pre-existing logs to Panorama.
  • E. Use the import option to pull logs into Panorama.

Answer: D

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/management-features/pa-7000-series-firewall-log-forwarding-to-panorama

 

NEW QUESTION 95
A Security policy rule is configured with a Vulnerability Protection Profile and an action of 'Deny".
Which action will this cause configuration on the matched traffic?

  • A. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to "Deny."
  • B. The configuration will allow the matched session unless a vulnerability signature is detected. The
    "Deny" action will supersede the per-severity defined actions defined in the associated Vulnerability Protection Profile.
  • C. The configuration is invalid. The Profile Settings section will be grayed out when the Action is set to
    "Deny".
  • D. The configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.

Answer: B

 

NEW QUESTION 96
A remote administrator needs firewall access on an untrusted interface Which two components are required on the firewall to configure certificate-based administrator authentication to the web Ul? (Choose two)

  • A. server certificate
  • B. client certificate
  • C. certificate profile
  • D. certificate authority (CA) certificate

Answer: C,D

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface.html

 

NEW QUESTION 97
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)

  • A. .exe
  • B. .pdf
  • C. .dll
  • D. .src
  • E. .apk
  • F. .jar

Answer: A,C,D

Explanation:
The question is asking for the free basic Wildfire Service which only allows for PE (Portable executables) files.
pe
Portable Executable (PE) files. PEs include executable files, object code, DLLs, FON (fonts), and LNK files. A subscription is not required to forward PE files for WildFire analysis, but is required for all other supported file types.
"With the basic WildFire service, the firewall can forward portable executable (PE) files for WildFire analysis", look online for PE files and you will get:
.acm, .ax, .cpl, .dll, .drv, .efi, .exe, .mui, .ocx, .scr, .sys, .tsp
https://docs.paloaltonetworks.com/wildfire/10-0/wildfire-admin/wildfire-overview/wildfire- concepts/file-analysis.html

 

NEW QUESTION 98
An administrator has enabled OSPF on a virtual router on the NGFW. OSPF is not adding new routes to
the virtual router.
Which two options enable the administrator to troubleshoot this issue? (Choose two.)

  • A. Perform a traffic pcap at the routing stage.
  • B. View System logs.
  • C. Add a redistribution profile to forward as BGP updates.
  • D. View Runtime Stats in the virtual router.

Answer: B,D

 

NEW QUESTION 99
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the Runtime Stats and look for problems with BGP configuration.
  • B. View the ACC tab to isolate routing issues.
  • C. Perform a traffic pcap on the NGFW to see any BGP problems.
  • D. View the System logs and look for the error messages about BGP.

Answer: A,D

Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEWCA0

 

NEW QUESTION 100
A
user's traffic traversing a Palo Alto Networks NGFW sometimes can reach http://www.company.com. At other times the session times out. The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http://www.company.com.
How can the firewall be configured automatically disable the PBF rule if the next hop goes down?

  • A. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question:.
  • B. Configure path monitoring for the next hop gateway on the default route in the virtual router.
  • C. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question:.
  • D. Enable and configure a Link Monitoring Profile for the external interface of the firewall.

Answer: D

 

NEW QUESTION 101
An administrator just submitted a newly found piece of spyware for WildFire analysis.
The spyware monitors behavior without the user's knowledge.
What is the expected verdict from WildFire?

  • A. Malware
  • B. Grayware
  • C. Spyware
  • D. Phishing

Answer: B

Explanation:

https://docs.paloaltonetworks.com/wildfire/10-0/wildfire-admin/wildfire-overview/wildfire- concepts/verdicts.html

 

NEW QUESTION 102
The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is configured to translate both IP address and report to 10.1.1.100 on TCP Port 8080.

Which NAT and security rules must be configured on the firewall? (Choose two)

  • A. A NAT rule with a source of any from untrust-I3 zone to a destination of 10.1.1.100 in dmz-zone using service-http service.
  • B. A security policy with a source of any from untrust-I3 zone to a destination of 1.1.100 in dmz-I3 zone using web-browsing application.
  • C. A security policy with a source of any from untrust-I3 Zone to a destination of 10.1.1.100 in dmz-I3 zone using web-browsing application
  • D. A NAT rule with a source of any from untrust-I3 zone to a destination of 1.1.1.100 in untrust-I3 zone using service-http service.

Answer: A,B

 

NEW QUESTION 103
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown. The next two entries show traffic allowed as application SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?

  • A. Disable the exclude cache option for the firewall.
  • B. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the top of the Security policy.
  • C. Create a decryption rule matching the encrypted BitTorrent traffic with action "No-Decrypt," and place the rule at the top of the Decryption policy.
  • D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.

Answer: D

Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRtCAK
Block sessions that use cipher suites you don't support. You configure which cipher suites (encryption algorithms) to allow on the SSL Protocol Settings tab. Don't allow users to connect to sites with weak cipher suites.

 

NEW QUESTION 104
......


Exam Details and Topics

The certification test is delivered through the official exam administrator, Pearson VUE. The candidates for the test can expect 75 questions to be completed within 80 minutes. The questions cover different formats, including matching, scenario-based with graphics, and multiple choice. The PCNSE exam is available in two languages: English and Japanese. The individuals should possess product competence as well as a good understanding of the unique areas of the product portfolio of Palo Alto Networks and know how to appropriately deploy at least one of them.

 

PCNSE exam dumps with real Palo Alto Networks questions and answers: https://prepaway.testkingpdf.com/PCNSE-testking-pdf-torrent.html