Free Sample Questions to Practice PCNSE Certification Test Engine [Jul-2024] 2024 Valid PCNSE Real Exam Questions, practice PCNSE PAN-OS NEW QUESTION # 77 Which is not a valid reason for receiving a decrypt-cert-validation error? A. Unsupported HSM B. Unknown certificate status C. Untrusted issuer D. Client authentication Answer: A Explanation:https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and- [...]

[Q77-Q99] Free Sample Questions to Practice PCNSE Certification Test Engine [Jul-2024]

Share

Free Sample Questions to Practice PCNSE Certification Test Engine [Jul-2024]

2024 Valid PCNSE Real Exam Questions, practice PCNSE PAN-OS

NEW QUESTION # 77
Which is not a valid reason for receiving a decrypt-cert-validation error?

  • A. Unsupported HSM
  • B. Unknown certificate status
  • C. Untrusted issuer
  • D. Client authentication

Answer: A

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and- monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes


NEW QUESTION # 78
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination IP address and post.
Which option when enabled with the correction threshold would mitigate this attack without dropping legitirnate traffic to other hosts insides the network?

  • A. QoS Policy to throttle traffic below maximum limit
  • B. Classified DoS Protection Policy using destination IP only with a Protect action
  • C. Security Policy rule to deny trafic to the IP address and port that is under attack
  • D. Zone Protection Policy with UDP Flood Protection

Answer: B

Explanation:
Step 1: Configure a DoS Protection profile for flood protection.
1. Select Objects > Security Profiles > DoS Protection and Add a profile Name.
2. Select Classified as the Type.
3. For Flood Protection, select the check boxes for all of the following types of flood protection:
SYN Flood

UDP Flood

ICMP Flood

ICMPv6 Flood

Other IP Flood

Step 2: Configure a DoS Protection policy rule that specifies the criteria for matching the incoming traffic.
This step include: (Optional) For Destination Address, select Any or enter the IP address of the device you want to protect.
https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/configure-dos-protection-against-flooding-of-new-sessions


NEW QUESTION # 79
Which version of GlobalProtect supports split tunneling based on destination domain, client process, and HTTP/HTTPS video streaming application?

  • A. GlobalProtect version 4.0 with PAN-OS 8.0
  • B. GlobalProtect version 4.1 with PAN-OS 8.1
  • C. GlobalProtect version 4.0 with PAN-OS 8.1
  • D. GlobalProtect version 4.1 with PAN-OS 8.0

Answer: B

Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new- features/new-features-released-in-gp-agent-4_1/split-tunnel-for-public-applications


NEW QUESTION # 80
A web server is hosted in the DMZ, and the server is configured to listen for incoming connections only on TCP port 8080. A Security policy rule allowing access from the Trust zone to the DMZ zone need to be configured to enable we browsing access to the server.
Which application and service need to be configured to allow only cleartext web-browsing traffic to thins server on tcp/8080.

  • A. application: ssl; service: any
  • B. application: web-browsing; service: (custom with destination TCP port 8080)
  • C. application: web-browsing; service: service-https
  • D. application: web-browsing; service: application-default

Answer: B

Explanation:
If you check in the FW the default port for web-browsing is TCP 80, so you will need a custom app. admin@PA-LAB-01# show predefined application web-browsing web-browsing { category general-internet; subcategory internet-utility; technology browser-based; analysis 'Web browsing continues to evolve. Initially used to simply view HTML formatted information, web browsers have become the client, through which, users can access new applications that provide functionality far beyond simple information browsing. These applications include web mail, instant messaging, streaming media, web conferencing, blogs, file sharing and other social networkingapplications. Much of the plain web-browsing activities has effectively been overshadowed by all the other applications. } default { port tcp/80; } tunnel-applications http-proxy; risk 4; } [edit]


NEW QUESTION # 81
An engineer needs to configure SSL Forward Proxy to decrypt traffic on a PA-5260. The engineer uses a forward trust certificate from the enterprise PKI that expires December 31, 2025. The validity date on the PA-generated certificate is taken from what?

  • A. The server certificate
  • B. The untrusted certificate
  • C. The trusted certificate
  • D. The root CA

Answer: A


NEW QUESTION # 82
What is the purpose of the firewall decryption broker?

  • A. Inspection traffic within IPsec tunnel
  • B. Force decryption of previously unknown cipher suites
  • C. Decrypt SSL traffic a then send it as cleartext to a security chain of inspection tools
  • D. Reduce SSL traffic to a weaker cipher before sending it to a security chain of inspection tools

Answer: C

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/decryption-features/decryption-broker


NEW QUESTION # 83
WildFire will submit for analysis blocked files that match which profile settings?

  • A. files matching Anti-Virus signatures
  • B. files that are blocked by URL filtering
  • C. files matching Anti-Spyware signatures
  • D. files that are blocked by a File Blocking profile

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wildfire-analys


NEW QUESTION # 84
An administrator creates an application-based security policy rule and commits the change to the firewall. Which two methods should be used to identify the dependent applications for the respective rule? (Choose two.)

  • A. Use the show predefined xpath <value> command and review the output.
  • B. Open the security policy rule and review the Depends On application list.
  • C. Review the App Dependency application list from the Commit Status view.
  • D. Reference another application group containing similar applications.

Answer: B,C

Explanation:
These two methods allow the administrator to see the dependent applications for a security policy rule that uses application-based criteria. The App Dependency application list shows the applications that are required for the rule to function properly1. The Depends On application list shows the applications that are implicitly added to the rule based on the predefined dependencies2. Reference: 1: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/app-id-features/simplified-application-dependency-workflow 2: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/use-application-objects-in-policy/resolve-application-dependencies


NEW QUESTION # 85
Refer to exhibit.

An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN.
How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all existing monitoring/ security platforms?

  • A. Configure log compression and optimization features on all remote firewalls.
  • B. Forward logs from firewalls only to Panorama and have Panorama forward logs to other external services.
  • C. Forward logs from external sources to Panorama for correlation, and from Panorama send them to the NGFW.
  • D. Any configuration on an M-500 would address the insufficient bandwidth concerns.

Answer: B

Explanation:
https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/panorama-overview/centralized-logging-and-reporting


NEW QUESTION # 86
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server hosts its contents over HTTP(S). Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule.
Which combination of service and application, and order of Security policy rules, needs to be configured to allow cleartext web-browsing traffic to this server on tcp/443.

  • A. Rule #1: application: web-browsing; service: service-https; action: allowRule #2:
    application: ssl; service: application-default; action: allow
  • B. Rule #1: application: web-browsing; service: application-default; action: allowRule #2:
    application: ssl; service: application-default; action: allow
  • C. Rule # 1: application: ssl; service: application-default; action: allowRule #2: application:
    web-browsing; service: application-default; action: allow
  • D. Rule #1: application: web-browsing; service: service-http; action: allowRule #2:
    application: ssl; service: application-default; action: allow

Answer: A

Explanation:
If decrypted traffic matches the web-browsing application. Then the firewall will log it as web- browsing over ssl (443) and will never match if it is set to "application-default".
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEyCAK


NEW QUESTION # 87
Match each GlobalProtect component to the purpose of that component

Answer:

Explanation:

Explanation
The GlobalProtect portal provides the management functions for your GlobalProtect infrastructure The GlobalProtect gateways provide security enforcement for traffic from GlobalProtect apps The GlobalProtect app software runs on endpoints and enables access to your network resources


NEW QUESTION # 88
A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks.
How can the Palo Alto Networks NGFW be configured to specifically protect this server against resource exhaustion originating from multiple IP addresses (DDoS attack)?

  • A. Add QoS Profiles to throttle incoming requests.
  • B. Define a custom App-ID to ensure that only legitimate application traffic reaches the server.
  • C. Add a DoS Protection Profile with defined session count.
  • D. Add a Vulnerability Protection Profile to block the attack.

Answer: C

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/dos-protection-profiles-and-policy-rules/dos-protection- profiles#ida42d52fa-3366-4695-bb4a-d39ebf3b6a5f


NEW QUESTION # 89
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)

  • A. Verify AutoFocus status using CLI.
  • B. Check for WildFire forwarding logs.
  • C. Check the license
  • D. Verify AutoFocus is enabled below Device Management tab.
  • E. Check the WebUI Dashboard AutoFocus widget.

Answer: C,E

Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/getting-started/enable-autofocus-threat-inte


NEW QUESTION # 90
A network administrator configured a site-to-site VPN tunnel where the peer device will act as initiator None of the peer addresses are known What can the administrator configure to establish the VPN connection?

  • A. Enable Passive Mode
  • B. Configure the peer address as an FQDN.
  • C. Set up certificate authentication.
  • D. Use the Dynamic IP address type.

Answer: D

Explanation:
According to the documentation, if the peer device has a dynamic IP address, the administrator can configure the peer address as an FQDN and use tunnel monitoring to establish the VPN connection. Tunnel monitoring is a feature that sends periodic ICMP pings to a specified destination IP address across the VPN tunnel and brings down the tunnel interface if the pings fail. This way, the firewall can detect when the peer device changes its IP address and re-establish the VPN connection. Reference: 1 IPSec VPN Tunnel with Peer Having Dynamic IP Address - Palo Alto Networks 2 Dual ISP VPN site to site Tunnel Failover with Tunnel Monitoring - Palo Alto Networks
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0


NEW QUESTION # 91
Drag and Drop Question
Match each type of DoS attack to an example of that type of attack.

Answer:

Explanation:

Explanation:
Plan to defend your network against different types of DoS attacks:
Application-Based Attacks
- Target weaknesses in a particular application and try to exhaust its resources so legitimate users can't use it. An example of this is the Slowloris attack.
Protocol-Based Attacks
- Also known as state-exhaustion attacks, these attacks target protocol weaknesses. A common example is a SYN flood attack.
Volumetric Attacks
- High-volume attacks that attempt to overwhelm the available network resources, especially bandwidth, and bring down the target to prevent legitimate users from accessing those resources.
An example of this is a UDP flood attack.


NEW QUESTION # 92
Which Palo Alto Networks VM-Series firewall is valid?

  • A. VM-800
  • B. VM-25
  • C. VM-50
  • D. VM-400

Answer: C

Explanation:
Reference:
https://www.paloaltonetworks.com/products/secure-the-network/virtualized-next-generation-firewall/vm-series
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series-firewall/vm-series-models.html


NEW QUESTION # 93
Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a
"No Decrypt" action? (Choose two.)

  • A. Block sessions with expired certificates
  • B. Block sessions with client authentication
  • C. Block credential phishing
  • D. Block sessions with unsupported cipher suites
  • E. Block sessions with untrusted issuers

Answer: A,E

Explanation:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/define-traffic-to- decrypt/create-a-decryption-profile


NEW QUESTION # 94
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration Once deployed each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers Which VPN preconfigured configuration would adapt to changes when deployed to the future site?

  • A. PPTP tunnels
  • B. GlobalProtect client
  • C. GlobalProtect satellite
  • D. IPsec tunnels using IKEv2

Answer: C


NEW QUESTION # 95
Which four NGFW multi-factor authentication factors are supported by PAN-OS? (Choose four.)

  • A. Push
  • B. Voice
  • C. SSH key
  • D. One-Time Password
  • E. User logon
  • F. Short message service

Answer: A,B,D,F

Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/authentication/authentication-types/multi-factor-auth Push - An endpoint device (such as a phone or tablet) prompts the user to allow or deny authentication.
Short message service (SMS) - An SMS message on the endpoint device prompts the user to allow or deny authentication. In some cases, the endpoint device provides a code that the user must enter in the MFA login page.
Voice - An automated phone call prompts the user to authenticate by pressing a key on the phone or entering a code in the MFA login page.
One-time password (OTP) - An endpoint device provides an automatically generated alphanumeric string, which the user enters in the MFA login page to enable authentication for a single transaction or session.
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authentication-types/multi-factor-auth


NEW QUESTION # 96
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)

  • A. .apk
  • B. .src
  • C. .jar
  • D. .pdf
  • E. .dll
  • F. .exe

Answer: A,C,D

Explanation:
Reference: https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/wildfire-overview/wildfire-file-type-support


NEW QUESTION # 97
An administrator logs in to the Palo Alto Networks NGFW and reports that the WebUI is missing the Policies tab. Which profile is the cause of the missing Policies tab?

  • A. WebUI
  • B. Authorization
  • C. Authentication
  • D. Admin Role

Answer: B


NEW QUESTION # 98
Which configuration is backed up using the Scheduled Config Export feature in Panorama?

  • A. Panorama candidate configuration and candidate configuration of all managed devices
  • B. Panorama running configuration
  • C. Panorama candidate configuration
  • D. Panorama running configuration and running configuration of all managed devices

Answer: D

Explanation:
Explanation
https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/administer-panorama/manage-panorama-and


NEW QUESTION # 99
......

Genuine PCNSE Exam Dumps Free Demo Valid QA's: https://freetorrent.braindumpsvce.com/PCNSE_exam-dumps-torrent.html