Certification Provider:Â Palo Alto Networks
Exam: Palo Alto Networks Certified Network Security Engineer (PCNSE)
Exam Code: PCNSE v10
Total Question: 181
Question per Quiz: 75
Updated On: 20 April 2023
Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam.
1.
What are three reasons for excluding a site from SSL decryption? (Choose three.)
2.
During the process of developing a decryption strategy and evaluating which websites are required for corporate users to access, several sites have been identified that cannot be decrypted due to technical reasons. In this case, the technical reason is unsupported ciphers. Traffic to these sites will therefore be blocked if decrypted How should the engineer proceed?
3.
An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls. The firewalls will provide access to mobile users and act as edge locations to on-premises infrastructure. The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration. Which two solutions can the administrator use to scale this configuration? (Choose two.)
4.
An engineer is planning an SSL decryption implementation. Which of the following statements is a best practice for SSL decryption?
5.
An administrator receives the following error message. How should the administrator identify the root cause of this error message?
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id
172.16.33.33/24 type IPv4 address protocol 0 port 0."
6.
Which feature checks Panorama connectivity status after a commit?
7.
Which three items are important considerations during SD-WAN configuration planning? (Choose three.)
8.
An administrator is considering upgrading the Palo Alto Networks NGFW and central management Panorama version What is considered best practice for this scenario?
9.
Which two features require another license on the NGFW? (Choose two.)
10.
An existing NGFW customer requires direct interne! access offload locally at each site and iPSec connectivity to all branches over public internet. One requirement is mat no new SD-WAN hardware be introduced to the environment. What is the best solution for the customer?
11.
What is the dependency for users to access services that require authentication?
12.
When overriding a template configuration locally on a firewall, what should you consider?
13.
Place the steps to onboard a ZTP firewall into Panorama/CSP/ZTP-Service in the correct order.
14.
Which two are valid ACC GlobalProtect Activity tab widgets? (Choose two.)
15.
Given the following snippet of a WildFire submission log. did the end-user get access to the requested information and why or why not?
16.
When an in-band data port is set up to provide access to required services, what is required for an interface that is assigned to service routes?
17.
An organization has recently migrated its infrastructure and configuration to NGFWs, for which Panorama manages the devices. The organization is coming from a L2-L4 firewall vendor, but wants to use App-ID while identifying policies that are no longer needed. Which Panorama tool can help this organization?
18.
What are two characteristic types that can be defined for a variable? (Choose two)
19.
A firewall has been assigned to a new template stack that contains both "Global" and "Local" templates in Panorama, and a successful commit and push has been performed. While validating the configuration on the local firewall, the engineer discovers that some settings are not being applied as intended. The setting values from the "Global" template are applied to the firewall instead of the "Local" template that has different values for the same settings. What should be done to ensure that the settings in the "Local" template are applied while maintaining settings from both templates?
20.
A network administrator is troubleshooting an issue with Phase 2 of an IPSec VPN tunnel. The administrator determines that the lifetime needs to be changed to match the peer. Where should this change be made?
21.
An administrator needs to assign a specific DNS server to one firewall within a device group. Where would the administrator go to edit a template variable at the device level?
22.
Which option is part of the content inspection process?
23.
An engineer is designing a deployment of multi-vsys firewalls. What must be taken into consideration when designing the device group structure?
24.
An engineer must configure the Decryption Broker feature Which Decryption Broker security chain supports bi-directional traffic flow?
25.
PBF can address which two scenarios? (Choose two.)
26.
An administrator needs to troubleshoot a User-ID deployment. The administrator believes that there is an issue related to LDAP authentication. The administrator wants to create a packet capture on the management plane. Which CLI command should the administrator use to obtain the packet capture for validating the configuration?
27.
The following objects and policies are defined in a device group hierarchy. Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group NYC-DC has NYC-FW as a member of the NYC-DC device-group What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?
28.
Which option describes the operation of the automatic commit recovery feature?
29.
Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?
30.
Which Security Policy Rule configuration option disables antivirus and anti-spyware scanning of server-to-client flows only?
31.
An administrator wants to upgrade a firewall HA pair to PAN-OS 10.1. The firewalls are currently running PAN-OS 8.1.17. Which upgrade path maintains synchronization of the HA session (and prevents network outage)?
32.
What is a correct statement regarding administrative authentication using external services with a local authorization method?
33.
An engineer needs to configure SSL Forward Proxy to decrypt traffic on a PA-5260. The engineer uses a forward trust certificate from the enterprise PKI that expires December 31, 2025. The validity date on the PA-generated certificate is taken from what?
34.
Refer to the exhibit. An administrator cannot see any if the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?
35.
In an HA failover scenario what occurs when sessions match an SSL Forward Proxy Decryption policy?
36.
Which three statements accurately describe Decryption Mirror? (Choose three.)
37.
A network security engineer is attempting to peer a virtual router on a PAN-OS firewall with an external router using the BGP protocol. The peer relationship is not establishing. What command could the engineer run to see the current state of the BGP state between the two devices?
38.
What does SSL decryption require to establish a firewall as a trusted third party and to establish trust between a client and server to secure an SSL/TLS connection?
39.
When configuring forward error correction (FEC) for PAN-OS SD-WAN, an administrator would turn on the feature inside which type of SD-WAN profile?
40.
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
41.
What are two best practices for incorporating new and modified App-IDs? (Choose two.)
42.
An administrator wants to enable WildFire inline machine learning. Which three file types does WildFire inline ML analyze? (Choose three.)
43.
The following objects and policies are defined in a device group hierarchy. Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group NYC-DC has NYC-FW as a member of the NYC-DC device-group What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?
44.
A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system. Where is the best place to validate if the firewall is blocking the user's TAR file?
45.
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
46.
Place the steps in the WildFire process workflow in their correct order. Select and Place:
47.
An administrator is attempting to create policies tor deployment of a device group and template stack When creating the policies, the zone drop down list does not include the required zone. What must the administrator do to correct this issue?
48.
Match each type of DoS attack to an example of that type of attack
49.
Which two features require another license on the NGFW? (Choose two.)
50.
When setting up a security profile, which three items can you use? (Choose three.)
51.
You have upgraded your Panorama with Log Collectors to 10.2. Before upgrading your firewalls using Panorama, what do you need do?
52.
An administrator needs to implement an NGFW between their DMZ and Core network EIGRP Routing between the two environments is required Which interface type would support this business requirement?
53.
Which three statements accurately describe Decryption Mirror? (Choose three.)
54.
A network administrator wants to use a certificate for the SSL/TLS Service Profile. Which type of certificate should the administrator use?
55.
What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)
56.
An administrator needs firewall access on a trusted interface. Which two components are required to configure certificate based, secure authentication to the Web Ul? (Choose two )
57.
Which two statements correctly identify the number of Decryption Broker security chains that are supported on a pair of decryption-forwarding interfaces'? (Choose two)
58.
An organization wishes to roll out decryption but gets some resistance from engineering leadership regarding the guest network. What is a common obstacle for decrypting traffic from guest devices?
59.
Which two events trigger the operation of automatic commit recovery? (Choose two.)
60.
An organization is building a Bootstrap Package to deploy Palo Alto Networks VM-Series firewalls into their Microsoft Azure. Which two statements are correct regarding the bootstrap package contents? (Choose two)
61.
Match each GlobalProtect component to the purpose of that component
62.
The SSL Forward Proxy decryption policy is configured. The following four certificate authority (CA) certificates are installed on the firewall. An end-user visits the untrusted website https://www.firewall-do-not-trust-website.com. Which certificate authority (CA) certificate will be used to sign the untrusted webserver certificate?
63.
What are two valid deployment options for Decryption Broker? (Choose two)
64.
An administrator wants to enable Palo Alto Networks cloud services for Device Telemetry and IoT. Which type of certificate must be installed?
65.
Which two features can be used to tag a username so that it is included in a dynamic user group? (Choose two.)
66.
An administrator receives the following error message. How should the administrator identify the root cause of this error message?
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id
172.16.33.33/24 type IPv4 address protocol 0 port 0."
67.
What are two characteristic types that can be defined for a variable? (Choose two.)
68.
An engineer is planning an SSL decryption implementation Which of the following statements is a best practice for SSL decryption?
69.
Updates to dynamic user group membership are automatic therefore using dynamic user groups instead of static group objects allows you to:
70.
Which rule type controls end user SSL traffic to external websites?
71.
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
72.
What are three types of Decryption Policy rules? (Choose three.)
73.
Which two mechanisms help prevent a spilt brain scenario an Active/Passive High Availability (HA) pair? (Choose two)
74.
An administrator has a PA-820 firewall with an active Threat Prevention subscription. The administrator is considering adding a WildFire subscription How does adding the WildFire subscription improve the security posture of the organization?
75.
Which Device Group option is assigned by default in Panorama whenever a new device group is created to manage a Firewall?