[Apr 30, 2023] Genuine PCNSE Exam Dumps New 2023 Palo Alto Networks Pratice Exam [Q118-Q140]

Share

[Apr 30, 2023] Genuine PCNSE Exam Dumps New 2023 Palo Alto Networks Pratice Exam

New 2023 Realistic PCNSE Dumps Test Engine Exam Questions in here

NEW QUESTION # 118
An administrator needs firewall access on a trusted interface. Which two components are required to configure certificate based, secure authentication to the web Ul? (Choose two )

  • A. server certificate
  • B. SSL/TLS Service Profile
  • C. certificate profile
  • D. SSH Service Profile

Answer: B,C


NEW QUESTION # 119
Which data flow describes redistribution of user mappings?

  • A. User-ID agent to firewall
  • B. Domain Controller to User-ID agent
  • C. User-ID agent to Panorama
  • D. firewall to firewall

Answer: D

Explanation:
Explanation
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-firewalls-to-redistribute-u
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/deploy-user-id-in-a-large-scale-network/redi


NEW QUESTION # 120
Place the steps in the WildFire process workflow in their correct order.

Answer:

Explanation:


NEW QUESTION # 121
A web server is hosted in the DMZ, and the server is configured to listen for incoming connections only on TCP port 8080. A Security policy rule allowing access from the Trust zone to the DMZ zone need to be configured to enable we browsing access to the server.
Which application and service need to be configured to allow only cleartext web-browsing traffic to thins server on tcp/8080.

  • A. application: web-browsing; service: (custom with destination TCP port 8080)
  • B. application: web-browsing; service: application-default
  • C. application: web-browsing; service: service-https
  • D. application: ssl; service: any

Answer: B

Explanation:
https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D8MJAA0&field=Attachment_1__Body__s


NEW QUESTION # 122
Below are the steps in the workflow for creating a Best Practice Assessment in a firewall and Panorama configuration Place the steps in order.

Answer:

Explanation:

Reference:
https://www.paloaltonetworks.com/resources/videos/how-to-run-a-bpa


NEW QUESTION # 123
A company is using wireless controllers to authenticate users. Which source should be used for User-ID mappings?

  • A. server monitoring
  • B. XFF headers
  • C. Syslog
  • D. client probing

Answer: C


NEW QUESTION # 124
Which two actions are required to make Microsoft Active Directory users appear in a firewall traffic log? (Choose two.)

  • A. Configure a RADIUS server profile to point to a domain controller
  • B. Run the User-ID Agent using an Active Directory account that has "event log viewer" permissions
  • C. Enable User-ID on the zone object for the source zone
  • D. Run the User-ID Agent using an Active Directory account that has "domain administrator" permissions
  • E. Enable User-ID on the zone object for the destination zone

Answer: B,C


NEW QUESTION # 125
An administrator wants to upgrade an NGFW from PAN-OS 7.1.2 to PAN-OS 8.0.2. The firewall is not a part of an HA pair.
What needs to be updated first?

  • A. WildFire
  • B. Applications and Threats
  • C. PAN-OS Upgrade Agent
  • D. XML Agent

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/upgrade-to-pan-os-
80/upgrade-the-firewall-to-pan-os-80/upgrade-a-firewall-to-pan-os-80


NEW QUESTION # 126
Which option describes the operation of the automatic commit recovery feature?

  • A. It enables a firewall to revert to the previous configuration if rule shadowing is detected.
  • B. It enables a firewall to revert to the previous configuration if application dependency errors are found.
  • C. It enables a firewall to revert to the previous configuration if a commit causes Panorama connectivity failure.
  • D. It enables a firewall to revert to the previous configuration if a commit causes HA partner connectivity failure.

Answer: C

Explanation:
Explanation/Reference: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/panorama-features/automatic- panorama-connection-recovery.html


NEW QUESTION # 127
If the firewall has the link monitoring configuration, what will cause a failover?

  • A. ethernet1/3 going down
  • B. ethernet1/3 and ethernet1/6 going down
  • C. ethernet1/6 going down
  • D. ethernet1/3 or Ethernet1/6 going down

Answer: B


NEW QUESTION # 128
How can Panorama help with troubleshooting problems such as high CPU or resource exhaustion on a managed firewall?

  • A. Panorama provides visibility into all the system and traffic logs received from firewalls it does not offer any ability to see or monitor resource utilization on managed firewalls
  • B. Panorama provides information about system resources of the managed devices in the Managed Devices
    > Health menu
  • C. Panorama monitors all firewalls using SNMP It generates a system log and can send email alerts when resource exhaustion is detected on a managed firewall
  • D. Firewalls send SNMP traps to Panorama when resource exhaustion is detected Panorama generates a system log and can send email alerts

Answer: B


NEW QUESTION # 129
If the firewall has the link monitoring configuration, what will cause a failover?

  • A. ethernet1/3 going down
  • B. ethernet1/3 and ethernet1/6 going down
  • C. ethernet1/6 going down
  • D. ethernet1/3 or Ethernet1/6 going down

Answer: B


NEW QUESTION # 130
An engineer has discovered that certain real-time traffic is being treated as best effort due to it exceeding defined bandwidth Which QoS setting should the engineer adjust?

  • A. QoS profile: Egress Max
  • B. QoS interface: Egress Guaranteed
  • C. QoS interface: Egress Max
  • D. QoS profile: Egress Guaranteed

Answer: D

Explanation:
Explanation
When the egress guaranteed bandwidth is exceeded, the firewall passes traffic on a best-effort basis.
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/qos-concepts/qos-bandwidth-ma


NEW QUESTION # 131
If an administrator does not possess a website's certificate, which SSL decryption mode will allow the Palo Alto Networks NGFW to inspect traffic when users browse to HTTP(S) websites?

  • A. SSL Outbound Inspection
  • B. SSL Forward Proxy
  • C. TLS Bidirectional proxy
  • D. SSL Inbound Inspection

Answer: D


NEW QUESTION # 132
Refer to the exhibit.

Which will be the egress interface if the traffic's ingress interface is ethernet 1/7 sourcing from
192.168.111.3 and to the destination 10.46.41.113?

  • A. ethernet1/5
  • B. ethernet1/6
  • C. ethernet1/7
  • D. ethernet1/3

Answer: A


NEW QUESTION # 133
You need to allow users to access the office-suite applications of their choice. How should you configure the firewall to allow access to any office-suite application?

  • A. Create an Application Group and add business-systems to it.
  • B. Create an Application Filter and name it Office Programs then filter on the business-systems category.
  • C. Create an Application Filter and name it Office Programs, then filter it on the office programs subcategory.
  • D. Create an Application Group and add Office 365, Evernote Google Docs and Libre Office

Answer: C

Explanation:
Explanation
According to the Palo Alto Networks documentation, "Application filters enable you to create groups of applications based on specific characteristics such as subcategory, technology, risk factor, and so on. You can then use these groups in Security policy rules to allow or block access to the applications. For example, you can create an application filter that includes all applications in the office-programs subcategory and use it in a Security policy rule to allow access to any office-suite application." References:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/manage-applications-in-a-policy/use-applic


NEW QUESTION # 134
SAML SLO is supported for which two firewall features? (Choose two.)

  • A. CLI
  • B. CaptivePortal
  • C. WebUI
  • D. GlobalProtect Portal

Answer: C,D

Explanation:
SSO is available to administrators who access the web interface and to end users who access applications through GlobalProtect or Captive Portal. SLO is available to administrators and GlobalProtect end users, but not to Captive Portal end users. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/authentication/authentication-types/saml
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/device/device-server-profiles-saml-identity-provider


NEW QUESTION # 135
An administrator is attempting to create policies for deployment of a device group and template stack. When creating the policies, the zone drop-down list does not include the required zone.
What can the administrator do to correct this issue?

  • A. Add a firewall to both the device group and the template.
  • B. Add the template as a reference template in the device group.
  • C. Enable "Share Unused Address and Service Objects with Devices" in Panorama settings.
  • D. Specify the target device as the master device in the device group.

Answer: B


NEW QUESTION # 136
If the firewall has the link monitoring configuration, what will cause a failover?

  • A. ethernet1/3 going down
  • B. ethernet1/3 and ethernet1/6 going down
  • C. ethernet1/6 going down
  • D. ethernet1/3 or Ethernet1/6 going down

Answer: B


NEW QUESTION # 137
A customer wants to set up a site-to-site VPN using tunnel interfaces.
Which two formats are correct for naming tunnel interfaces? (Choose two.)

  • A. vpn-tunnel.1024
  • B. tunnel.1025
  • C. vpn-tunnel.1
  • D. tunnel.1

Answer: B,D

Explanation:
Explanation/Reference:


NEW QUESTION # 138
An administrator plans to deploy 15 firewalls to act as GlobalProtect gateways around the world Panorama will manage the firewalls The firewalls will provide access to mobile users and act as edge locations to on-premises infrastructure The administrator wants to scale the configuration out quickly and wants all of the firewalls to use the same template configuration Which two solutions can the administrator use to scale this configuration? (Choose two.)

  • A. collector groups
  • B. virtual systems
  • C. variables
  • D. template stacks

Answer: A


NEW QUESTION # 139
Which Panorama administrator types require the configuration of at least one access domain? (Choose two.)

  • A. Template Admin
  • B. Dynamic
  • C. Custom Panorama Admin
  • D. Device Group
  • E. Role Based

Answer: A,D


NEW QUESTION # 140
......

Grab latest Amazon PCNSE Dumps as PDF Updated: https://examcollection.realvce.com/PCNSE-original-questions.html