ExamGecko

PCNSA: Palo Alto Networks Certified Network Security Administrator

Palo Alto Networks Certified Network Security Administrator Exam Questions: 362
Palo Alto Networks Certified Network Security Administrator   2.370 Learners
Take Practice Tests
Comming soon
PDF | VPLUS
This study guide should help you understand what to expect on the exam and includes a summary of the topics the exam might cover and links to additional resources. The information and materials in this document should help you focus your studies as you prepare for the exam.

Related questions

An administrator is updating Security policy to align with best practices.

Which Policy Optimizer feature is shown in the screenshot below?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base.

On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.

Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

A.
All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
A.
All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
Answers
B.
No impact because the apps were automatically downloaded and installed
B.
No impact because the apps were automatically downloaded and installed
Answers
C.
No impact because the firewall automatically adds the rules to the App-ID interface
C.
No impact because the firewall automatically adds the rules to the App-ID interface
Answers
D.
All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
D.
All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
Answers
Suggested answer: A

Explanation:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-idsintroduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules

asked 23/09/2024
MD NAZRI BEZAMAN
30 questions

Which type of DNS signatures are used by the firewall to identify malicious and command-and-control domains?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

Which action would an administrator take to ensure that a service object will be available only to the selected device group?

A.
create the service object in the specific template
A.
create the service object in the specific template
Answers
B.
uncheck the shared option
B.
uncheck the shared option
Answers
C.
ensure that disable override is selected
C.
ensure that disable override is selected
Answers
D.
ensure that disable override is cleared
D.
ensure that disable override is cleared
Answers
Suggested answer: D

Explanation:

https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-firewalls/managedevice-groups/create-objects-for-use-in-shared-or-device-group-policy

asked 23/09/2024
BISWARUP KUNDU
41 questions

Which firewall plane provides configuration, logging, and reporting functions on a separate processor?

A.
control
A.
control
Answers
B.
network processing
B.
network processing
Answers
C.
data
C.
data
Answers
D.
security processing
D.
security processing
Answers
Suggested answer: A
asked 23/09/2024
Sacha CONTI
43 questions

Review the Screenshot:

Given the network diagram, traffic must be permitted for SSH and MYSQL from the DMZ to the SERVER zones, crossing two firewalls. In addition, traffic should be permitted from the

SERVER zone to the DMZ on SSH only.

Which rule group enables the required traffic?

A)

B)

C)

D)

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

An administrator needs to add capability to perform real-time signature lookups to block or sinkhole all known malware domains.

Which type of single unified engine will get this result?

A.
User-ID
A.
User-ID
Answers
B.
App-ID
B.
App-ID
Answers
C.
Security Processing Engine
C.
Security Processing Engine
Answers
D.
Content-ID
D.
Content-ID
Answers
Suggested answer: A
asked 23/09/2024
Subramaniam Pratheep
39 questions

Which order of steps is the correct way to create a static route?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

Which security profile will provide the best protection against ICMP floods, based on individual combinations of a packet`s source and destination IP address?

A.
DoS protection
A.
DoS protection
Answers
B.
URL filtering
B.
URL filtering
Answers
C.
packet buffering
C.
packet buffering
Answers
D.
anti-spyware
D.
anti-spyware
Answers
Suggested answer: A
asked 23/09/2024
Farrah Colson
34 questions

What are three valid source or D=destination conditions available as Security policy qualifiers? (Choose three.)

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member