Palo Alto PCNSA UPDATED Exam
Questions and CORRECT Answers
Match the Palo Alto Networks Security Operating Platform architecture to its description. -
CORRECT ANSWER - Threat Intelligence Cloud = Gathers, analyzes, correlates, and
disseminates threats to and from the network and endpoints located within the network.
Next-Generation Firewall = Identifies and inspects all traffic to block known threats.
Advanced Endpoint Protection = Inspects processes and files to prevent known and unknown
exploits
Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting
functions on a separate processor?
A. management
B. network processing
C. data
D. security processing - CORRECT ANSWER - A. management
A security administrator has configured App-ID updates to be automatically downloaded and
installed. The company is currently using an application identified byApp-ID as
SuperApp_base.On a content update notice, Palo Alto Networks is adding new app signatures
labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.Based on
the information, how is the SuperApp traffic affected after the 30 days have passed?
A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no
longer matches the SuperApp-base application
B. No impact because the apps were automatically downloaded and installed
C. No impact because the firewall automatically adds the rules to the App-ID interface
D. All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied
until the security administrator approves the applications - CORRECT ANSWER - A. All
traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer
matches the SuperApp-base application
, How many zones can an interface be assigned with a Palo Alto Networks firewall?
A. two
B. three
C. four
D. one - CORRECT ANSWER - D. one
Which two configuration settings shown are not the default? (Choose two.)
A. Enable Security Log
B. Server Log Monitor Frequency (sec)
C. Enable Session
D. Enable Probing - CORRECT ANSWER - B. Server Log Monitor Frequency (sec);
C. Enable Session
Which dataplane layer of the graphic shown provides pattern protection for spyware and
vulnerability exploits on a Palo Alto Networks Firewall?
A. Signature Matching
B. Network Processing
C. Security Processing
D. Data Interfaces - CORRECT ANSWER - A. Signature Matching
Which option shows the attributes that are selectable when setting up application filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology - CORRECT
ANSWER - B. Category, Subcategory, Technology, Risk, and Characteristic
Questions and CORRECT Answers
Match the Palo Alto Networks Security Operating Platform architecture to its description. -
CORRECT ANSWER - Threat Intelligence Cloud = Gathers, analyzes, correlates, and
disseminates threats to and from the network and endpoints located within the network.
Next-Generation Firewall = Identifies and inspects all traffic to block known threats.
Advanced Endpoint Protection = Inspects processes and files to prevent known and unknown
exploits
Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting
functions on a separate processor?
A. management
B. network processing
C. data
D. security processing - CORRECT ANSWER - A. management
A security administrator has configured App-ID updates to be automatically downloaded and
installed. The company is currently using an application identified byApp-ID as
SuperApp_base.On a content update notice, Palo Alto Networks is adding new app signatures
labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.Based on
the information, how is the SuperApp traffic affected after the 30 days have passed?
A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no
longer matches the SuperApp-base application
B. No impact because the apps were automatically downloaded and installed
C. No impact because the firewall automatically adds the rules to the App-ID interface
D. All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied
until the security administrator approves the applications - CORRECT ANSWER - A. All
traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer
matches the SuperApp-base application
, How many zones can an interface be assigned with a Palo Alto Networks firewall?
A. two
B. three
C. four
D. one - CORRECT ANSWER - D. one
Which two configuration settings shown are not the default? (Choose two.)
A. Enable Security Log
B. Server Log Monitor Frequency (sec)
C. Enable Session
D. Enable Probing - CORRECT ANSWER - B. Server Log Monitor Frequency (sec);
C. Enable Session
Which dataplane layer of the graphic shown provides pattern protection for spyware and
vulnerability exploits on a Palo Alto Networks Firewall?
A. Signature Matching
B. Network Processing
C. Security Processing
D. Data Interfaces - CORRECT ANSWER - A. Signature Matching
Which option shows the attributes that are selectable when setting up application filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology - CORRECT
ANSWER - B. Category, Subcategory, Technology, Risk, and Characteristic