New 2021 Guaranteed Success with Prep4away PCNSE Dumps Palo Alto Networks PDF Questions [Q67-Q88]

Share

New 2021 Guaranteed Success with Prep4away PCNSE Dumps Palo Alto Networks PDF Questions

Exceptional Practice To Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 10.0 Pass the First Time

NEW QUESTION 67
Several offices are connected with VPNs using static IPV4 routes. An administrator has been tasked with implementing OSPF to replace static routing.
Which step is required to accoumplish this goal?

  • A. Create new VPN zones at each site to terminate each VPN connection
  • B. Assign OSPF Area ID 0.0.0.0 to all Ethernet and tunnel interfaces
  • C. Enable OSPFv3 on each tunnel interface and use Area ID 0.0.0.0
  • D. Assign an IP address on each tunnel interface at each site

Answer: B

 

NEW QUESTION 68
Which DoS protection mechanism detects and prevents session exhaustion attacks?

  • A. TCP Port Scan Protection
  • B. Flood Protection
  • C. Packet Based Attack Protection
  • D. Resource Protection

Answer: D

 

NEW QUESTION 69
If the firewall has the link monitoring configuration, what will cause a failover?

  • A. ethernet1/3 or Ethernet1/6 going down
  • B. ethernet1/6 going down
  • C. ethernet1/3 going down
  • D. ethernet1/3 and ethernet1/6 going down

Answer: D

 

NEW QUESTION 70
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes
do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the ACC tab to isolate routing issues.
  • B. Perform a traffic pcap on the NGFW to see any BGP problems.
  • C. View the System logs and look for the error messages about BGP.
  • D. View the Runtime Stats and look for problems with BGP configuration.

Answer: A,D

 

NEW QUESTION 71
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the System logs and look for the error messages about BGP.
  • B. View the ACC tab to isolate routing issues.
  • C. Perform a traffic pcap on the NGFW to see any BGP problems.
  • D. View the Runtime Stats and look for problems with BGP configuration.

Answer: A,D

Explanation:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEWCA0

 

NEW QUESTION 72
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software.
Furthermore, SSL is used to tunnel malicious traffic to command-and-control servers on the internet and SSL Forward Proxy Decryption is not enabled.
Which component once enabled on a perirneter firewall will allow the identification of existing infected hosts in an environment?

  • A. Antivirus profiles applied to outbound security policies with action set to alert
  • B. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole
  • C. Vulnerability Protection profiles applied to outbound security policies with action set to block
  • D. File Blocking profiles applied to outbound security policies with action set to alert

Answer: B

 

NEW QUESTION 73
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance.
Which interface type and license feature are necessary to meet the requirement?

  • A. Virtual Wire interface with the Decryption Port Export license
  • B. Decryption Mirror interface with the associated Decryption Port Mirror license
  • C. Tap interface with the Decryption Port Mirror license
  • D. Decryption Mirror interface with the Threat Analysis license

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/decryption- mirroring

 

NEW QUESTION 74
Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a "No Decrypt" action? (Choose two.)

  • A. Block sessions with unsupported cipher suites
  • B. Block sessions with expired certificates
  • C. Block sessions with untrusted issuers
  • D. Block credential phishing
  • E. Block sessions with client authentication

Answer: A,B,E

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/define-traffic- to-decrypt/create-a-decryption-profile

 

NEW QUESTION 75
When using the predefined default profile, the policy will inspect for viruses on the decoders. Match each decoder with its default action.
Answer options may be used more than once or not at all.

Answer:

Explanation:

 

NEW QUESTION 76
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between Panorama and the managed firewalls and Log Collectors.
How would the administrator establish the chain of trust?

  • A. Configure strong password authentication
  • B. Set up multi-factor authentication
  • C. Enable LDAP or RADIUS integration
  • D. Use custom certificates

Answer: D

 

NEW QUESTION 77
Starting with PAN-OS version 9.1, GlobalProtect logging information is now recorded in which firewall log?

  • A. GlobalProtect
  • B. Authentication
  • C. System
  • D. Configuration

Answer: A

Explanation:
Explanation/Reference: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/globalprotect-features/ enhanced-logging-for-globalprotect.html

 

NEW QUESTION 78
Which User-ID method should be configured to map IP addresses to usernames for users connected through a terminal server?

  • A. XFF headers
  • B. client probing
  • C. port mapping
  • D. server monitoring

Answer: C

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-user- mapping-for-terminal-server-users

 

NEW QUESTION 79
The firewall identifies a popular application as an unknown-tcp.
Which two options are available to identify the application? (Choose two.)

  • A. Create a custom application.
  • B. Create a Security policy to identify the custom application.
  • C. Create a custom object for the custom application server to identify the custom application.
  • D. Submit an Apple-ID request to Palo Alto Networks.

Answer: A,D

Explanation:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/app-id/manage-custom-or-unknown-applications

 

NEW QUESTION 80
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.

Which Security policy rule will allow traffic to flow to the web server?

  • A. Untrust (any) to DMZ (1.1.1.100), web browsing -Allow
  • B. Untrust (any) to Untrust (10.1.1.100), web browsing -Allow
  • C. Untrust (any) to DMZ (10.1.1.100), web browsing -Allow
  • D. Untrust (any) to Untrust (1.1.1.100), web browsing -Allow

Answer: A

 

NEW QUESTION 81
Which CLI command enables an administrator to check the CPU utilization of the dataplane?

  • A. debug running resources
  • B. show running resource-monitor
  • C. debug data-plane dp-cpu
  • D. show system resources

Answer: B

Explanation:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXwCAK

 

NEW QUESTION 82
A Security policy rule is configured with a Vulnerability Protection Profile and an action of
'Deny".
Which action will this cause configuration on the matched traffic?

  • A. The configuration will allow the matched session unless a vulnerability is detected. The
    "Deny" action will supersede the per-severity defined actions defined in the associated Vulnerability Protection Profile.
  • B. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to "Deny."
  • C. The configuration is invalid. The Profile Settings section will be grayed out when the Action is set to "Deny".
  • D. The configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.

Answer: A

 

NEW QUESTION 83
Which feature can provide NGFWs with User-ID mapping information?

  • A. GlobalProtect
  • B. Native 802.1q authentication
  • C. Native 802.1x authentication
  • D. Web Captcha

Answer: A

 

NEW QUESTION 84
What are two prerequisites for configuring a pair of Palo Alto Networks firewalls in an active/passive High Availability (HA) pair? (Choose two.)

  • A. The firewalls must have the same set of licenses.
  • B. The management interfaces must to be on the same network.
  • C. The peer HA1 IP address must be the same on both firewalls.
  • D. HA1 should be connected to HA1. Either directly or with an intermediate Layer 2 device.

Answer: A,D

 

NEW QUESTION 85
Which three fields can be included in a pcap filter? (Choose three)

  • A. Source IP
  • B. Rule number
  • C. Egress interface
  • D. Ingress interface
  • E. Destination IP

Answer: A,D,E

 

NEW QUESTION 86
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?

  • A. Importation of a certificate from an HSM
  • B. Security policy rule allowing SSL to the target server
  • C. Firewall connectivity to a CRL
  • D. Root certificate imported into the firewall with "Trust" enabled

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/decryption/configure-ssl- inbound-inspection

 

NEW QUESTION 87
If the firewall has the link monitoring configuration, what will cause a failover?

  • A. ethernet1/3 or Ethernet1/6 going down
  • B. ethernet1/6 going down
  • C. ethernet1/3 going down
  • D. ethernet1/3 and ethernet1/6 going down

Answer: D

 

NEW QUESTION 88
......

PCNSE EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.prep4away.com/Palo-Alto-Networks-certification/braindumps.PCNSE.ete.file.html

Best Quality Palo Alto Networks PCNSE Exam Questions: https://drive.google.com/open?id=1W_UX8G4SKNPn0Oz0f4JN2ztzA_nui4An