Palo Alto Networks PCNSE Exam Practice Questions (P. 5)
- Full Access (619 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
Which Palo Alto Networks VM-Series firewall is valid?
- AVM-25
- BVM-800
- CVM-50Most Voted
- DVM-400
Correct Answer:
C
Reference:
https://www.paloaltonetworks.com/products/secure-the-network/virtualized-next-generation-firewall/vm-series
C
Reference:
https://www.paloaltonetworks.com/products/secure-the-network/virtualized-next-generation-firewall/vm-series
send
light_mode
delete
Question #42
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the server at 10.1.1.22
Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?

A.

B.

C.

D.

Based on the information shown in the image, which NAT rule will forward web-browsing traffic correctly?

A.

B.

C.

D.

send
light_mode
delete
Question #43
An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW.
The update contains an application that matches the same traffic signatures as the custom application.
Which application should be used to identify traffic traversing the NGFW?
The update contains an application that matches the same traffic signatures as the custom application.
Which application should be used to identify traffic traversing the NGFW?
- ACustom application
- BSystem logs show an application error and neither signature is used.
- CDownloaded applicationMost Voted
- DCustom and downloaded application signature files are merged and both are used
Correct Answer:
A
A
send
light_mode
delete
Question #44
Starting with PAN-OS version 9.1, GlobalProtect logging information is now recorded in which firewall log?
- AGlobalProtectMost Voted
- BSystem
- CAuthentication
- DConfiguration
Correct Answer:
A
Reference:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/globalprotect-features/enhanced-logging-for-globalprotect.html
A
Reference:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/globalprotect-features/enhanced-logging-for-globalprotect.html
send
light_mode
delete
Question #45
Refer to the exhibit.

Which will be the egress interface if the traffic's ingress interface is ethernet1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?

Which will be the egress interface if the traffic's ingress interface is ethernet1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?
send
light_mode
delete
Question #46
Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)
- AKerberos
- BPAP
- CSAMLMost Voted
- DTACACS+Most Voted
- ERADIUSMost Voted
- FLDAP
Correct Answer:
CDE
CDE
send
light_mode
delete
Question #47
Which event will happen if an administrator uses an Application Override Policy?
- AThreat-ID processing time is decreased.
- BThe Palo Alto Networks NGFW stops App-ID processing at Layer 4.Most Voted
- CThe application name assigned to the traffic by the security rule is written to the Traffic log.
- DApp-ID processing time is increased.
Correct Answer:
B
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513
B
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513
send
light_mode
delete
Question #48
Which Security policy rule will allow an admin to block facebook chat but allow Facebook in general?
- ADeny application facebook-chat before allowing application facebookMost Voted
- BDeny application facebook on top
- CAllow application facebook on top
- DAllow application facebook before denying application facebook-chat
Correct Answer:
A
Reference:
https://live.paloaltonetworks.com/t5/Configuration-Articles/Failed-to-Block-Facebook-Chat-Consistently/ta-p/115673
A
Reference:
https://live.paloaltonetworks.com/t5/Configuration-Articles/Failed-to-Block-Facebook-Chat-Consistently/ta-p/115673
send
light_mode
delete
Question #49
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers.
Which option will protect the individual servers?
Which option will protect the individual servers?
- AEnable packet buffer protection on the Zone Protection Profile.
- BApply an Anti-Spyware Profile with DNS sinkholing.
- CUse the DNS App-ID with application-default.
- DApply a classified DoS Protection Profile.Most Voted
Correct Answer:
D
D
send
light_mode
delete
Question #50
If the firewall is configured for credential phishing prevention using the `Domain Credential Filter` method, which login will be detected as credential theft?
- AMapping to the IP address of the logged-in user.
- BFirst four letters of the username matching any valid corporate username.
- CUsing the same user's corporate username and password.Most Voted
- DMatching any valid corporate username.
Correct Answer:
C
C
send
light_mode
delete
All Pages