Palo Alto - PCNSA
Study online at https://quizlet.com/_hu5at1
1. Match the Palo Alto Networks Security Operating Platform architecture to its
description.: Threat Intelligence Cloud = Gathers, analyzes, correlates, and disseminates threats to and from the
network and endpoints located within the network.
Next-Generation Firewall = Identifies and inspects all traffic to block known threats.
Advanced Endpoint Protection = Inspects processes and files to prevent known and unknown exploits
2. Which plane on a Palo Alto Networks Firewall provides configuration, logging,
and reporting functions on a separate processor?
A. management
B. network processing
C. data
D. security processing: A. management
3. A security administrator has configured App-ID updates to be automatical-
ly downloaded and installed. The company is currently using an application
identified byApp-ID as SuperApp_base.On a content update notice, Palo Alto
Networks is adding new app signatures labeled SuperApp_chat and Super-
App_download, which will be deployed in 30 days.Based on the information,
how is the SuperApp traffic affected after the 30 days have passed?
A. All traffic matching the SuperApp_chat, and SuperApp_download is denied
because it no longer matches the SuperApp-base application
B. No impact because the apps were automatically downloaded and installed
C. No impact because the firewall automatically adds the rules to the App-ID
interface
D. All traffic matching the SuperApp_base, SuperApp_chat, and Super-
App_download is denied until the security administrator approves the applica-
tions: A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches
the SuperApp-base application
4. How many zones can an interface be assigned with a Palo Alto Networks
firewall?
A. two
B. three
1/7
, Palo Alto - PCNSA
Study online at https://quizlet.com/_hu5at1
C. four
D. one: D. one
5. Which two configuration settings shown are not the default? (Choose two.)
A. Enable Security Log
B. Server Log Monitor Frequency (sec)
C. Enable Session
D. Enable Probing: B. Server Log Monitor Frequency (sec);
C. Enable Session
6. Which dataplane layer of the graphic shown provides pattern protection for
spyware and vulnerability exploits on a Palo Alto Networks Firewall?
A. Signature Matching
B. Network Processing
C. Security Processing
D. Data Interfaces: A. Signature Matching
7. Which option shows the attributes that are selectable when setting up appli-
cation filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology: B. Category, Subcat-
egory, Technology, Risk, and Characteristic
8. Actions can be set for which two items in a URL filtering security profile?
(Choose two.)
A. Block List
B. Custom URL Categories
C. PAN-DB URL Categories
D. Allow List: B. Custom URL Categories;
C. PAN-DB URL Categories
9. Match the Cyber-Attack Lifecycle stage to its correct description. Select and
Place:
reconnaissance
2/7
Study online at https://quizlet.com/_hu5at1
1. Match the Palo Alto Networks Security Operating Platform architecture to its
description.: Threat Intelligence Cloud = Gathers, analyzes, correlates, and disseminates threats to and from the
network and endpoints located within the network.
Next-Generation Firewall = Identifies and inspects all traffic to block known threats.
Advanced Endpoint Protection = Inspects processes and files to prevent known and unknown exploits
2. Which plane on a Palo Alto Networks Firewall provides configuration, logging,
and reporting functions on a separate processor?
A. management
B. network processing
C. data
D. security processing: A. management
3. A security administrator has configured App-ID updates to be automatical-
ly downloaded and installed. The company is currently using an application
identified byApp-ID as SuperApp_base.On a content update notice, Palo Alto
Networks is adding new app signatures labeled SuperApp_chat and Super-
App_download, which will be deployed in 30 days.Based on the information,
how is the SuperApp traffic affected after the 30 days have passed?
A. All traffic matching the SuperApp_chat, and SuperApp_download is denied
because it no longer matches the SuperApp-base application
B. No impact because the apps were automatically downloaded and installed
C. No impact because the firewall automatically adds the rules to the App-ID
interface
D. All traffic matching the SuperApp_base, SuperApp_chat, and Super-
App_download is denied until the security administrator approves the applica-
tions: A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches
the SuperApp-base application
4. How many zones can an interface be assigned with a Palo Alto Networks
firewall?
A. two
B. three
1/7
, Palo Alto - PCNSA
Study online at https://quizlet.com/_hu5at1
C. four
D. one: D. one
5. Which two configuration settings shown are not the default? (Choose two.)
A. Enable Security Log
B. Server Log Monitor Frequency (sec)
C. Enable Session
D. Enable Probing: B. Server Log Monitor Frequency (sec);
C. Enable Session
6. Which dataplane layer of the graphic shown provides pattern protection for
spyware and vulnerability exploits on a Palo Alto Networks Firewall?
A. Signature Matching
B. Network Processing
C. Security Processing
D. Data Interfaces: A. Signature Matching
7. Which option shows the attributes that are selectable when setting up appli-
cation filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology: B. Category, Subcat-
egory, Technology, Risk, and Characteristic
8. Actions can be set for which two items in a URL filtering security profile?
(Choose two.)
A. Block List
B. Custom URL Categories
C. PAN-DB URL Categories
D. Allow List: B. Custom URL Categories;
C. PAN-DB URL Categories
9. Match the Cyber-Attack Lifecycle stage to its correct description. Select and
Place:
reconnaissance
2/7