Palo Alto Networks PCNSA Practice Test - Questions Answers, Page 17
List of questions
Related questions
Question 161

What must be considered with regards to content updates deployed from Panorama?
Explanation:
Reference: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-licensesand-updates/deploy-updates-to-firewalls-log-collectors-and-wildfire-appliances-usingpanorama/schedule-a-content-update-using-panorama.html
Question 162

During the packet flow process, which two processes are performed in application identification?
(Choose two.)
Explanation:
Reference: http://live.paloaltonetworks.com//t5/image/serverpage/imageid/12862i950F549C7D4E6309
Question 163

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.
Which Security policy rule will allow traffic to flow to the web server?
Explanation:
Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/natconfiguration-examples/destination-nat-exampleone-to-one-mapping
Question 164

What does an administrator use to validate whether a session is matching an expected NAT policy?
Explanation:
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQSCA0
Question 165

What is the purpose of the automated commit recovery feature?
Explanation:
Reference: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/administerpanorama/enable-automated-commit-recovery.html
Question 166

According to the best practices for mission critical devices, what is the recommended interval for antivirus updates?
Explanation:
Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/bestpractices-for-content-and-threat-content-updates/best-practices-mission-critical.html
Question 167

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?
Explanation:
Reference: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/use-an-externaldynamic-list-in-policy/external-dynamic-list.html
Question 168

URL categories can be used as match criteria on which two policy types? (Choose two.)
Explanation:
Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/url-filteringconcepts/url-category-as-policy-match-criteria.html
Question 169

Given the screenshot, what are two correct statements about the logged traffic? (Choose two.)
Question 170

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address.
Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic.
Which two Security policy rules will accomplish this configuration? (Choose two.)
Question