ExamGecko
Home / Palo Alto Networks / PCNSA / List of questions
Ask Question

Palo Alto Networks PCNSA Practice Test - Questions Answers

List of questions

Question 1

Report
Export
Collapse

Which firewall plane provides configuration, logging, and reporting functions on a separate processor?

control
control
network processing
network processing
data
data
security processing
security processing
Suggested answer: A
asked 23/09/2024
Sacha CONTI
43 questions

Question 2

Report
Export
Collapse

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base.

On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.

Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
No impact because the apps were automatically downloaded and installed
No impact because the apps were automatically downloaded and installed
No impact because the firewall automatically adds the rules to the App-ID interface
No impact because the firewall automatically adds the rules to the App-ID interface
All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
Suggested answer: A

Explanation:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-idsintroduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules

asked 23/09/2024
MD NAZRI BEZAMAN
30 questions

Question 3

Report
Export
Collapse

How many zones can an interface be assigned with a Palo Alto Networks firewall?

two
two
three
three
four
four
one
one
Suggested answer: D

Explanation:

References:

asked 23/09/2024
Cristian Pernia
42 questions

Question 4

Report
Export
Collapse

Which two configuration settings shown are not the default? (Choose two.)

Palo Alto Networks PCNSA image Question 4 53819 09232024001155000000

Enable Security Log
Enable Security Log
Server Log Monitor Frequency (sec)
Server Log Monitor Frequency (sec)
Enable Session
Enable Session
Enable Probing
Enable Probing
Suggested answer: B, C

Explanation:

References:

asked 23/09/2024
Monique Canham
37 questions

Question 5

Report
Export
Collapse

Which data-plane processor layer of the graphic shown provides uniform matching for spyware and vulnerability exploits on a Palo Alto Networks Firewall?

Palo Alto Networks PCNSA image Question 5 53820 09232024001155000000

Signature Matching
Signature Matching
Network Processing
Network Processing
Security Processing
Security Processing
Security Matching
Security Matching
Suggested answer: A
asked 23/09/2024
Syed Azar
38 questions

Question 6

Report
Export
Collapse

Which option lists the attributes that are selectable when setting up an Application filters?

Category, Subcategory, Technology, and Characteristic
Category, Subcategory, Technology, and Characteristic
Category, Subcategory, Technology, Risk, and Characteristic
Category, Subcategory, Technology, Risk, and Characteristic
Name, Category, Technology, Risk, and Characteristic
Name, Category, Technology, Risk, and Characteristic
Category, Subcategory, Risk, Standard Ports, and Technology
Category, Subcategory, Risk, Standard Ports, and Technology
Suggested answer: B

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/objects/objectsapplication-filters

asked 23/09/2024
Eduardo Bravo
38 questions

Question 7

Report
Export
Collapse

Actions can be set for which two items in a URL filtering security profile? (Choose two.)

Block List
Block List
Custom URL Categories
Custom URL Categories
PAN-DB URL Categories
PAN-DB URL Categories
Allow List
Allow List
Suggested answer: A, D

Explanation:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/url-filtering-concepts/urlfiltering-profile-actions

asked 23/09/2024
Beena Sagayaraj
42 questions

Question 8

Report
Export
Collapse

Which two statements are correct about App-ID content updates? (Choose two.)

Updated application content may change how security policy rules are enforced
Updated application content may change how security policy rules are enforced
After an application content update, new applications must be manually classified prior to use
After an application content update, new applications must be manually classified prior to use
Existing security policy rules are not affected by application content updates
Existing security policy rules are not affected by application content updates
After an application content update, new applications are automatically identified and classified
After an application content update, new applications are automatically identified and classified
Suggested answer: A, D
asked 23/09/2024
Robert McConnell
32 questions

Question 9

Report
Export
Collapse

Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?

Windows session monitoring via a domain controller
Windows session monitoring via a domain controller
passive server monitoring using the Windows-based agent
passive server monitoring using the Windows-based agent
Captive Portal
Captive Portal
passive server monitoring using a PAN-OS integrated User-ID agent
passive server monitoring using a PAN-OS integrated User-ID agent
Suggested answer: C

Explanation:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/user-id/map-ip-addresses-tousers/map-ip-addresses-to-usernames-using-captive-portal.html

asked 23/09/2024
doaa elshazly
47 questions

Question 10

Report
Export
Collapse

An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?

Create an Application Filter and name it Office Programs, the filter it on the business-systems category, office-programs subcategory
Create an Application Filter and name it Office Programs, the filter it on the business-systems category, office-programs subcategory
Create an Application Group and add business-systems to it
Create an Application Group and add business-systems to it
Create an Application Filter and name it Office Programs, then filter it on the business-systems category
Create an Application Filter and name it Office Programs, then filter it on the business-systems category
Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office
Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office
Suggested answer: A

Explanation:

An application filter is an object that dynamically groups applications based on application attributes that you define, including category, subcategory, technology, risk factor, and characteristic. This is useful when you want to safely enable access to applications that you do not explicitly sanction, but that you want users to be able to access. For example, you may want to enable employees to choose their own office programs (such as Evernote, Google Docs, or Microsoft

Office 365) for business use.

To safely enable these types of applications, you could create an application filter that matches on the Category business-systems and the Subcategory office-programs. As new applications office programs emerge and new App-IDs get created, these new applications will automatically match the filter you defined; you will not have to make any additional changes to your policy rulebase to safely enable any application that matches the attributes you defined for the filter.

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/use-application-objects-in -policy/create-an-application-filter.html

asked 23/09/2024
Matthew Sain
39 questions
Total 362 questions
Go to page: of 37

Related questions