Summary Palo Alto PCNSA Certification Practice Test Bank Questions & Answers (all correct) 2022.
Palo Alto PCNSA Practice Test Bank Questions & Answers (all correct) 2022. What are two valid tag types for use in a DAG? (Choose two.) A. dynamic tag B. membership tag C. wildcard tag D. static tag *ANS- AD Which interface type is used to monitor traffic and cannot be used to perform traffic shaping? A. Virtual Wire B. Layer3 C. Layer2 D. Tap *ANS- D What is true about Panorama managed firewalls? A. Commit on local firewalls can be prohibited, which results in no configuration backups on local firewalls. B. By default, Panorama stores up to ten backups for each firewall. C. By default, Panorama stores up to ten device states for each firewall. D. After a commit on a local firewall, a backup is sent of its running configuration to Panorama. *ANS- D If the NGFW reboots before you commit your changes, how can you revert the candidate configuration to the current snapshot to restore changes you made between the last commit and the last snapshot? A. revert to the last saved configuration B. revert to the first saved configuration C. reverse the saved config D. Undo *ANS- A What are two types of Security profiles? (Choose two.) A. URL Filtering B. Antivirus C. Spyware Filtering D. File Filtering *ANS- AB PAN-OS® software supports which two authentication types? (Choose two.) A. Token B. LMS C. kerberos D. RADIUS *ANS- CD Which Layer 2 interfaces can be used to switch traffic between VLANs? A. Tap interfaces B. other Layer 2 interfaces C. other subnets D. Layer 2 and 3 interfaces *ANS- B How often are new antivirus signatures published? A. weekly B. monthly C. hourly D. daily *ANS- D An administrator is reviewing the security policy configuration and notices that the policy to block traffic to an internal web server uses the reset-both action. What are two potential risks associated with the reset-both Security policy action? (Choose two.) A. Sending a reset allows the TCP session to send data, which may allow malicious traffic. B. Sending a reset can facilitate malicious use such as reverse mapping through port scanning. C. Sending a reset yields a poor end-user experience. D. Sending a reset will consume server resources with half-open sockets. *ANS- AB Which two agents can be used to monitor servers and gather User-ID information? (Choose two.) A. Windows-based client B. Traps agent C. Built-in agent inside the PAN-OS® firewall D. Cortex Data Lake *ANS- AC Which license must an administrator acquire prior to downloading Antivirus updates for use with the firewall? A. Antivirus B. WildFire C. Threat Prevention D. URL Filtering *ANS- C You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact a command-and-control server. Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection? A. Anti-Spyware Profile B. Data Filtering Profile C. Antivirus Profile D. Vulnerability Protection Profile *ANS- A How often are new and modified threat signatures and modified application signatures published? A. hourly B. monthly C. weekly D. daily *ANS- C What are two predefined anti-spyware profiles? (Choose two.) A. Secure B. Standard C. Strict D. Default *ANS- CD What are two dynamic roles? (Choose two.) A. Dynamic User B. Device User C. Superuser D. Device Administrator *ANS- CD Based on the Security policy rules shown, SSH will be allowed on which port? A. any port B. the default port C. same port as ssl and snmpv3 D. port 443 or 161 *ANS- B What is the percentage of malware that is estimated to use DNS for Command and Control (C2) procedures? A. 50% B. 10% C. 25% D. 80% *ANS- D During the packet flow process, which two processes are performed in application identification? (Choose two.) A. session application identified B. pattern-based application identification C. application changed from content inspection D. application override policy match *ANS- BD In order for the firewall to query Active Directory to authenticate users, which Server Profile is required in the Authentication Profile? A. SAML B. LDAP C. RADIUS D. TACACS+ *ANS- B What are three types of address objects that can be created? (Choose three.) A. EDL B. IP Netmask C. FQDN D. IP Range E. Tag *ANS- BCD What is an "application shift?" A. an application change during the lifetime of a session B. a session change during the lifetime of an application C. a packet change during the lifetime of a session D. application dependency *ANS- A What are two URL Filtering Security Profile actions? (Choose two.) A. Allow B. Continue C. Deny D. Approved *ANS- AB Which statement is true about the App-ID database? A. App-ID always requires an explicit Security policy rule for parent applications. B. If an App-ID has a web-browsing dependency, you will not need to add web-browsing to other Security polices to use web-browsing C. Every application has a parent application. D. Some App-IDs implicitly allow required application without the need to explicitly add the parent to the Security policy. *ANS- D What is the advantage of using application tags? A. Identify applications capable of exploitation B. Identify applications with unknown vulnerabilities C. Use to determine application tunneling D. Dynamically enforce new and updated App-IDs *ANS- D An administrator wants to act upon websites that match a set of categories, where each website matches all categories in the set. Which object should the administrator create to enable this function? A. URL Filtering profile B. service C. address D. URL category *ANS- D What process would an administrator use to customize the entries in a built-in IP address EDL? A. Administrators cannot modify the content of the built-in lists B. Objects - External Dynamic Lists - Edit C. Device - Dynamic Updates - Upload D. Objects - Address Groups - Add *ANS- A The data plane provides which two data processing features of the firewall? (Choose two.) A. reporting B. signature matching C. network processing D. logging *ANS- BC Which type of Security policy rule would match traffic that flows between the Outside zone and Inside zone, but would not match traffic that flows within the zones? A. global B. interzone C. universal D. intrazone *ANS- B Given the topology, which interface type should you configure for firewall interface E1/1? A. virtual wire B. mirror port C. Layer 2 D. tap *ANS- D Which type of Security policy rule would match traffic flowing between the Inside zone and Outside zone, as well as within the Inside zone, and within the Outside zone? A. intrazone B. global C. interzone D. universal *ANS- D Given the following information with regards to IP-addressing, which NAT type needs to be configured? Original Packet: Src IP 10.10.10.10 and Dst IP 204.204.204.204 Translated Packet: Src IP 204.204.204.204 and Dst IP 10.10.10.10 A. Bi-Directional NAT B. U-Turn NAT C. Source DIPP NAT D. Source NAT *ANS- A Which two methods can be used to manage Palo Alto Networks next-generation firewalls? (Choose two.) A. XML API B. wireless C. sandbox D. web interface *ANS- AD Which data-plane processor layer proactively identifies and defends against unknown, new or custom malware and exploits? A. Network Processing B. Signature Matching C. Security Matching D. Security Processing *ANS- B Config logs display entries for which kind of firewall changes? A. configuration B. resets C. debugs D. system logs *ANS- A An administrator wants to secure a specific server in the DMZ. Which Security profile can provide protection against ICMP floods, based on individual combinations of a packet's source and destination IP addresses? A. DoS Protection B. Packet Buffering C. Anti-Spyware D. Zone Protection *ANS- A URL site-access options will generate a log for each of the following permissions except one, which does not log the event? A. alert B. continue C. block D. allow *ANS- D What is the default metric value of static routes? A. 20 B. 1 C. 2 D. 10 *ANS- D Which file is used to save the running configuration on a Palo Alto Networks firewall? A. B. C. D. *ANS- A An administrator wants to allow employees to use only Facebook Messenger but not Facebook email. Which two App-ID applications will you need to allow in your Security policy to use facebook-chat only? (Choose two.) A. facebook B. facebook-chat C. facebook-base D. web-browsing *ANS- BC Which interface type uses virtual routers and routing protocols? A. Virtual Wire B. Layer 3 C. Layer 2 D. HA *ANS- B What does the Save Named Configuration Snapshot option do? A. creates a candidate configuration snapshot that does not overwrite the default snapshot (.) B. deletes a candidate configuration snapshot that does not overwrite the default snapshot (.) C. creates a candidate configuration snapshot that does not overwrite the default snapshot (.) D. creates a tentative configuration snapshot that does not overwrite the default snapshot (.) *ANS- A Which two interface types can be used for firewall management? (Choose two.) A. Loopback B. Layer 2 C. Virtual Wire D. VLAN *ANS- AD In the example Security policy, which two websites would be blocked? (Choose two.) A. LinkedIn B. Facebook C. Amazon D. YouTube *ANS- AB What are four components of the Palo Alto Networks Cybersecurity Portfolio? (Choose four.) a) Cortex DynamicDNS b) WildFire c) Cortex XDR d) OpenConnect e) Prisma Access f) AutoFocus *ANS- BCEF Which cloud-delivered security service provides instant access to community-based threat data? a) Prisma SaaS b) AutoFocus c) Unit 42 d) Cortex XDR *ANS- B CONTINUES (30 pages)
Información del documento
- ¿Un libro?
- Sí
- Subido en
- 16 de octubre de 2022
- Número de páginas
- 30
- Escrito en
- 2022/2023
- Tipo
- Resumen