Real PCNSA Exam PDF Test Engine Practice Test Questions
Palo Alto Networks PCNSA Real 2023 Braindumps Mock Exam Dumps
NEW QUESTION # 115
Which statement is true regarding a Best Practice Assessment?
- A. It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture
- B. The BPA tool can be run only on firewalls
- C. The assessment, guided by an experienced sales engineer, helps determine the areas of greatest risk where you should focus prevention activities
- D. It provides a percentage of adoption for each assessment data
Answer: D
Explanation:
Best Practice Assessment (BPA) Tool -The BPA for next-generation firewalls and Panorama evaluates a device's configuration by measuring the adoption of capabilities, validating whether the policies adhere to best practices, and providing recommendations and instructions for how to remediate failed best practice checks.
The Security Policy Adoption Heatmap component filters the information by device groups, serial numbers, zones, areas of architecture, and other categories. The results include trending data, which shows the rate of security improvement as you adopt new capabilities, fix gaps, and progress toward a Zero-Trust network.
The BPA component performs more than 200 security checks on a firewall or Panorama configuration and provides a pass/fail score for each check. Each check is a best practice identified by Palo Alto Networks security experts. If a check returns a failing score, the tool provides the justification for the failing score and how to fix the issue.
https://docs.paloaltonetworks.com/best-practices/8-1/data-center-best-practices/data-center-best- practice-security-policy/use-palo-alto-networks-assessment-and-review-tools
NEW QUESTION # 116
Based on the graphic which statement accurately describes the output shown in the server monitoring panel?
- A. The host lab-client has been found by the User-ID agent.
- B. The User-ID agent is connected to the firewall labeled lab-client.
- C. The host lab-client has been found by a domain controller.
- D. The User-ID agent is connected to a domain controller labeled lab-client.
Answer: C
NEW QUESTION # 117
Match the network device with the correct User-ID technology.
Answer:
Explanation:
NEW QUESTION # 118
Which license is required to use the Palo Alto Networks built-in IP address EDLs?
- A. SD-Wan
- B. Threat Prevention
- C. WildFire
- D. DNS Security
Answer: B
Explanation:
An active Threat Prevention license is required to obtain Palo Alto Networks built-in EDLs. These built-in EDLs protect your network against malicious hosts.
NEW QUESTION # 119
Which Security Profile can provide protection against ICMP floods, based on individual combinations of a packet's source and destination IP addresses?
- A. anti-spyware
- B. packet buffering
- C. DoS protection
- D. URL filtering
Answer: C
NEW QUESTION # 120
Given the topology, which zone type should zone A and zone B to be configured with?
- A. Layer2
- B. Tap
- C. Layer3
- D. Virtual Wire
Answer: C
NEW QUESTION # 121
Given the topology, which zone type should zone A and zone B to be configured with?
- A. Layer2
- B. Tap
- C. Layer3
- D. Virtual Wire
Answer: C
NEW QUESTION # 122
What are the three DNS Security categories available to control DNS traffic? (Choose three.)
- A. Vulnerability Domains
- B. Malware Domains
- C. Parked Domains
- D. Spyware Domains
- E. Phishing Domains
Answer: B,C,E
Explanation:
To show this go to Ani-Spyware Profile to DNS policy > DNS Security
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns- security/enable-dns-security
NEW QUESTION # 123
What is considered best practice with regards to committing configuration changes?
- A. Wait until all running and pending jobs are finished before committing.
- B. Validate configuration changes prior to committing.
- C. Export configuration after each single configuration change performed.
- D. Disable the automatic commit feature that prioritizes content database installations before committing.
Answer: B
Explanation:
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-cli-quick-start/use-the-cli/commit- configuration-changes As a best practice, validate configuration changes prior to committing so that you can fix any errors that will cause a commit failure, thereby ensuring that the commit will succeed. This is particularly useful in environments with a strict change window.
NEW QUESTION # 124
An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems.
From the Pre-defined Categories tab within the URL Filtering profile, what is the right configuration to prevent such connections?
- A. Set the hacking category to continue.
- B. Set the malware category to block.
- C. Set the phishing category to override.
- D. Set the Command and Control category to block.
Answer: B
NEW QUESTION # 125
Complete the statement. A security profile can block or allow traffic____________
- A. after it is matched by a security policy that allows traffic
- B. after it is matched by a security policy that allows or blocks traffic Security profiles are objects added to policy rules that are configured with an action of allow.
- C. on unknown-tcp or unknown-udp traffic
- D. before it is matched by a security policy
Answer: A
NEW QUESTION # 126
Based on the screenshot presented which column contains the link that when clicked opens a window to display all applications matched to the policy rule?
- A. Apps Allowed
- B. Service
- C. Name
- D. Apps Seen
Answer: D
NEW QUESTION # 127
An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs.
What is the correct process to enable this logging1?
- A. Select the interzone-default rule and edit the rule on the Actions tab select Log at Session Start and click OK
- B. This rule has traffic logging enabled by default no further action is required
- C. Select the interzone-default rule and click Override on the Actions tab select Log at Session End and click OK
- D. Select the interzone-default rule and edit the rule on the Actions tab select Log at Session End and click OK
Answer: C
NEW QUESTION # 128
A server-admin in the USERS-zone requires SSH-access to all possible servers in all current and future Public Cloud environments. All other required connections have already been enabled between the USERS- and the OUTSIDE-zone. What configuration-changes should the Firewall-admin make?
- A. In addition to option a, a custom-service-object called SERVICE-SSH-RETURN that contains source-port-TCP-22 should be created. A second security-rule is required that allows traffic from zone OUTSIDE to USERS for SERVICE-SSH-RETURN for any source-IP-address to any destination-Ip-address
- B. In addition to option c, an additional rule from zone OUTSIDE to USERS for application SSH from any source-IP-address to any destination-IP-address is required to allow the return-traffic from the SSH-servers to reach the server-admin
- C. Create a security-rule that allows traffic from zone USERS to OUTSIDE to allow traffic from any source IP-address to any destination IP-address for application SSH
- D. Create a custom-service-object called SERVICE-SSH for destination-port-TCP-22. Create a security-rule between zone USERS and OUTSIDE to allow traffic from any source IP-address to any destination IP-address for SERVICE-SSH
Answer: C
NEW QUESTION # 129
Based on the show security policy rule would match all FTP traffic from the inside zone to the outside zone?
- A. engress outside
- B. inside-portal
- C. intercone-default
- D. internal-inside-dmz
Answer: C
NEW QUESTION # 130
Match the cyber-attack lifecycle stage to its correct description.
Answer:
Explanation:
NEW QUESTION # 131
Ethernet 2/1 has an IP Address of 10.0.1.2 in Zone 'trust' (LAN).
If both interfaces are connected to the same virtual router, which IP address information will an administrator need to enter in the Destination field to access the internet?
- A. 10.0.1.254/32
- B. 0.0.0.0/0
- C. 10.0.2.1/32
- D. 0.0.0.0
Answer: B
NEW QUESTION # 132
Drag and Drop Question
Match the cyber-attack lifecycle stage to its correct description.
Select and Place:
Answer:
Explanation:
NEW QUESTION # 133
To protect against illegal code execution, which Security profile should be applied?
- A. Vulnerability Protection profile on denied traffic
- B. Vulnerability Protection profile on allowed traffic
- C. Antivirus profile on allowed traffic
- D. Antivirus profile on denied traffic
Answer: B
Explanation:
You do not create security profiles on Denied Rules. Having security profiles on denied rules will just eat up CPU. It is not needed and there is no benefits
NEW QUESTION # 134
Place the following steps in the packet processing order of operations from first to last.
Answer:
Explanation:
NEW QUESTION # 135
An administrator is implementing an exception to an external dynamic list by adding an entry to the list manually. The administrator wants to save the changes, but the OK button is grayed out.
What are two possible reasons the OK button is grayed out? (Choose two.)
- A. The entry doesn't match a list entry.
- B. The entry matches a list entry.
- C. The entry is duplicated.
- D. The entry contains wildcards.
Answer: A,C
NEW QUESTION # 136
A website is unexpectedly allowed due to miscategorization.
What are two ways to resolve this issue for a proper response? (Choose two.)
- A. Review the categorization of the website on https://urlfiltering paloaltonetworks.com.
Submit for "request change", identifying the appropriate categorization, and wait for confirmation before testing again. - B. Create a URL category and assign the affected URL.
Update the active URL Filtering profile site access setting for the custom URL category to block. - C. Create a URL category and assign the affected URL.
Add a Security policy with a URL category qualifier of the custom URL category below the original policy.
Set the policy action to Deny. - D. Identify the URL category being assigned to the website.
Edit the active URL Filtering profile and update that category's site access settings to block.
Answer: A,B
NEW QUESTION # 137
The Palo Alto Networks NGFW was configured with a single virtual router named VR-1.
What changes are required on VR-1 to route traffic between two interfaces on the NGFW?
- A. Add zones attached to interfaces to the virtual router
- B. Enable the redistribution profile to redistribute connected routes
- C. Add interfaces to the virtual router
- D. Add static routes to route between the two interfaces
Answer: C
Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/virtual-routers.html
NEW QUESTION # 138
Based on the graphic which statement accurately describes the output shown in the server monitoring panel?
- A. The host lab-client has been found by the User-ID agent.
- B. The User-ID agent is connected to a domain controller labeled lab-client.
- C. The User-ID agent is connected to the firewall labeled lab-client.
- D. The host lab-client has been found by a domain controller.
Answer: B
NEW QUESTION # 139
Match each feature to the DoS Protection Policy or the DoS Protection Profile.
Answer:
Explanation:
NEW QUESTION # 140
......
Prepare For The PCNSA Question Papers In Advance: https://www.dumpexam.com/PCNSA-valid-torrent.html
Released Palo Alto Networks PCNSA Updated Questions PDF: https://drive.google.com/open?id=1QaDDUjq8hemgWBuQUWzRlIApGsw0PwwF
