Certification Provider:Â Palo Alto Networks
Exam: Palo Alto Networks Certified Network Security Engineer (PCNSE)
Exam Code: PCNSE v10
Total Question: 181
Question per Quiz: 75
Updated On: 20 April 2023
Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam.
1.
In a Panorama template which three types of objects are configurable? (Choose three)
2.
Your company has to Active Directory domain controllers spread across multiple WAN links All users authenticate to Active Directory Each link has substantial network bandwidth to support all mission-critical applications. The firewalls management plane is highly utilized Given this scenario which type of User-ID agent is considered a best practice by Palo Alto Networks?
3.
In an HA failover scenario what occurs when sessions match an SSL Forward Proxy Decryption policy?
4.
The following objects and policies are defined in a device group hierarchy. Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group NYC-DC has NYC-FW as a member of the NYC-DC device-group What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?
5.
A network administrator wants to use a certificate for the SSL/TLS Service Profile. Which type of certificate should the administrator use?
6.
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
7.
When you navigate to Network: > GlobalProtect > Portals > Method section, which three options are available? (Choose three)
8.
An engineer is designing a deployment of multi-vsys firewalls. What must be taken into consideration when designing the device group structure?
9.
Which two mechanisms help prevent a spilt brain scenario an Active/Passive High Availability (HA) pair? (Choose two)
10.
An existing NGFW customer requires direct interne! access offload locally at each site and iPSec connectivity to all branches over public internet. One requirement is mat no new SD-WAN hardware be introduced to the environment. What is the best solution for the customer?
11.
You have upgraded your Panorama with Log Collectors to 10.2. Before upgrading your firewalls using Panorama, what do you need do?
12.
During a laptop-replacement project, remote users must be able to establish a GlobalProtect VPN connection to the corporate network before logging in to their new Windows 10 endpoints. The new laptops have the 5.2.10 GlobalProtect Agent installed, so the administrator chooses to use the Connect Before Logon feature to solve this issue. What must be configured to enable the Connect Before Logon feature?
13.
An Administrator is configuring Authentication Enforcement and they would like to create an exemption rule to exempt a specific group from authentication. Which authentication enforcement object should they select?
14.
Which action disables Zero Touch Provisioning (ZTP) functionality on a ZTP firewall during the onboarding process?
15.
The decision to upgrade to PAN-OS 10.2 has been approved. The engineer begins the process by upgrading the Panorama servers, but gets an error when trying to install. When performing an upgrade on Panorama to PAN-OS 10.2, what is the potential cause of a failed install?
16.
Match each GlobalProtect component to the purpose of that component
17.
Four configuration choices are listed, and each could be used to block access to a specific URL. If you configured each choice to block the same URL, then which choice would be evaluated last in the processing order to block access to the URL?
18.
Which value in the Application column indicates UDP traffic that did not match an App-ID signature?
19.
Which option is part of the content inspection process?
20.
A company requires that a specific set of ciphers be used when remotely managing their Palo Alto Networks appliances. Which profile should be configured in order to achieve this?
21.
Which two features require another license on the NGFW? (Choose two.)
22.
Which option describes the operation of the automatic commit recovery feature?
23.
An organization is building a Bootstrap Package to deploy Palo Alto Networks VM-Series firewalls into their AWS tenant. Which two statements are correct regarding the bootstrap package contents? (Choose two.)
24.
An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used After looking at the configuration, the administrator believes that the firewall is not using a static route What are two reasons why the firewall might not use a static route"? (Choose two.)
25.
Which three items are import considerations during SD-WAN configuration planning? (Choose three.)
26.
Updates to dynamic user group membership are automatic therefore using dynamic user groups instead of static group objects allows you to:
27.
Which two features can be used to tag a username so that it is included in a dynamic user group? (Choose two.)
28.
An administrator discovers that a file blocked by the WildFire inline ML feature on the firewall is a false-positive action. How can the administrator create an exception for this particular file?
29.
Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?
30.
An administrator is building Security rules within a device group to block traffic to and from malicious locations. How should those rules be configured to ensure that they are evaluated with a high priority?
31.
An engineer must configure the Decryption Broker feature Which Decryption Broker security chain supports bi-directional traffic flow?
32.
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
33.
An administrator wants to upgrade a firewall HA pair to PAN-OS 10.1. The firewalls are currently running PAN-OS 8.1.17. Which upgrade path maintains synchronization of the HA session (and prevents network outage)?
34.
Which three items are important considerations during SD-WAN configuration planning? (Choose three.)
35.
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
36.
Which rule type controls end user SSL traffic to external websites?
37.
A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)
38.
A variable name must start with which symbol?
39.
An engineer is pushing configuration from Panorama to a managed firewall. What happens when the pushed Panorama configuration has Address Object names that duplicate the Address Objects already configured on the firewall?
40.
A network administrator troubleshoots a VPN issue and suspects an IKE Crypto mismatch between peers. Where can the administrator find the corresponding logs after running a test command to initiate the VPN?
41.
The Aggregate Ethernet interface is showing down on a passive PA-7050 firewall of an active/passive HA pair. The HA Passive Link State is set to "Auto" under Device > High Availability > General > Active/Passive Settings. The AE interface is configured with LACP enabled and is up only on the active firewall. Why is the AE interface showing down on the passive firewall?
42.
Which function is handled by the management plane (control plane) of a Palo Alto Networks firewall?
43.
When setting up a security profile, which three items can you use? (Choose three.)
44.
How should an administrator enable the Advance Routing Engine on a Palo Alto Networks firewall?
45.
An organization is building a Bootstrap Package to deploy Palo Alto Networks VM-Series firewalls into their Microsoft Azure. Which two statements are correct regarding the bootstrap package contents? (Choose two)
46.
During the packet flow process, which two processes are performed in application identification? (Choose two.)
47.
In a security-first network what is the recommended threshold value for content updates to be dynamically updated?
48.
During the process of developing a decryption strategy and evaluating which websites are required for corporate users to access, several sites have been identified that cannot be decrypted due to technical reasons. In this case, the technical reason is unsupported ciphers. Traffic to these sites will therefore be blocked if decrypted How should the engineer proceed?
49.
When you import the configuration of an HA pair into Panorama, how do you prevent the import from affecting ongoing traffic?
50.
A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system. Where is the best place to validate if the firewall is blocking the user's TAR file?
51.
An organization has recently migrated its infrastructure and configuration to NGFWs, for which Panorama manages the devices. The organization is coming from a L2-L4 firewall vendor, but wants to use App-ID while identifying policies that are no longer needed. Which Panorama tool can help this organization?
52.
PBF can address which two scenarios? (Select Two)
53.
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
54.
Which two events trigger the operation of automatic commit recovery? (Choose two.)
55.
Which statement about High Availability timer settings is true?
56.
Which two statements correctly identify the number of Decryption Broker security chains that are supported on a pair of decryption-forwarding interfaces'? (Choose two)
57.
A network administrator wants to use a certificate for the SSL/TLS Service Profile Which type of certificate should the administrator use?
58.
Which configuration is backed up using the Scheduled Config Export feature in Panorama?
59.
A firewall administrator has been tasked with ensuring that all Panorama-managed firewalls forward traffic logs to Panorama. In which section is this configured?
60.
An administrator receives the following error message. How should the administrator identify the root cause of this error message?
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id
172.16.33.33/24 type IPv4 address protocol 0 port 0."
61.
An engineer has been given approval to upgrade their environment 10 PAN-OS 10.2. The environment consists of both physical and virtual firewalls a virtual Panorama HA pair, and virtual log collectors. What is the recommended order when upgrading to PAN-OS 10.2?
62.
A network engineer has discovered that asymmetric routing is causing a Palo Alto Networks firewall to drop traffic. The network architecture cannot be changed to correct this. Which two actions can be taken on the firewall to allow the dropped traffic permanently? (Choose two.)
63.
The UDP-4501 protocol-port is used between which two GlobalProtect components?
64.
SD-WAN is designed to support which two network topology types? (Choose two.)
65.
How can Panorama help with troubleshooting problems such as high CPU or resource exhaustion on a managed firewall?
66.
A company with already deployed Palo Alto firewalls has purchased their first Panorama server. The security team has already configured all firewalls with the Panorama IP address and added all the firewall serial numbers in Panorama. What are the next steps to migrate configuration from the firewalls to Panorama?
67.
Which feature checks Panorama connectivity status after a commit?
68.
Which value in the Application column indicates UDP traffic that did not match an App-ID signature?
69.
Place the steps in the WildFire process workflow in their correct order. Select and Place:
70.
To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?
71.
Which three split tunnel methods are supported by a GlobalProtect Gateway? (Choose three.)
72.
Starting with PAN-OS version 9.1, application dependency information is now reported in which two locations? (Choose two.)
73.
A network security administrator wants to begin inspecting bulk user HTTPS traffic flows egressing out of the internet edge firewall. Which certificate is the best choice to configure as an SSL Forward Trust certificate?
74.
An administrator wants to enable WildFire inline machine learning. Which three file types does WildFire inline ML analyze? (Choose three.)
75.
A network administrator plans a Prisma Access deployment with three service connections, each with a BGP peering to a CPE. The administrator needs to minimize the BGP configuration and management overhead on on-prem network devices. What should the administrator implement?