ExamGecko
Ask Question

Palo Alto Networks PCNSA Practice Test - Questions Answers, Page 19

Question list
Search

Related questions











Question 181

Report
Export
Collapse

What two authentication methods on the Palo Alto Networks firewalls support authentication and authorization for role-based access control? (Choose two.)

SAML
SAML
TACACS+
TACACS+
LDAP
LDAP
Kerberos
Kerberos
Suggested answer: A, B

Explanation:

Reference: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewalladministration/manage-firewall-administrators/administrative-authentication.html

asked 23/09/2024
Asad yaseen
40 questions

Question 182

Report
Export
Collapse

Choose the option that correctly completes this statement. A Security Profile can block or allow traffic ____________.

on either the data place or the management plane.
on either the data place or the management plane.
after it is matched by a security policy rule that allows traffic.
after it is matched by a security policy rule that allows traffic.
before it is matched to a Security policy rule.
before it is matched to a Security policy rule.
after it is matched by a security policy rule that allows or blocks traffic.
after it is matched by a security policy rule that allows or blocks traffic.
Suggested answer: B

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-policy.html

asked 23/09/2024
Bogdan Karolic
39 questions

Question 183

Report
Export
Collapse

Palo Alto Networks PCNSA image Question 183 53998 09232024001155000000

Given the topology, which zone type should you configure for firewall interface E1/1?

Tap
Tap
Tunnel
Tunnel
Virtual Wire
Virtual Wire
Layer3
Layer3
Suggested answer: A
asked 23/09/2024
Guus Schenkelaars
28 questions

Question 184

Report
Export
Collapse

Which two features can be used to tag a username so that it is included in a dynamic user group?

(Choose two.)

GlobalProtect agent
GlobalProtect agent
XML API
XML API
User-ID Windows-based agent
User-ID Windows-based agent
log forwarding auto-tagging
log forwarding auto-tagging
Suggested answer: B, C
asked 23/09/2024
Jucelino Pinheiro de Andrade da Silva
42 questions

Question 185

Report
Export
Collapse

For the firewall to use Active Directory to authenticate users, which Server Profile is required in the Authentication Profile?

TACACS+
TACACS+
RADIUS
RADIUS
LDAP
LDAP
SAML
SAML
Suggested answer: C

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-anauthenticationprofile-and-sequence

asked 23/09/2024
Ilia Voronkov
41 questions

Question 186

Report
Export
Collapse

Which type of security policy rule will match traffic that flows between the Outside zone and inside zone, but would not match traffic that flows within the zones?

global
global
intrazone
intrazone
interzone
interzone
universal
universal
Suggested answer: C

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/software-and-contentupdates/dynamiccontentupdates.html#:~:text=WildFire%20signature%20updates%20are%20made,within%20a%20minute%20of%20availability

asked 23/09/2024
PRABHAT VAIBHAV
29 questions

Question 187

Report
Export
Collapse

Which license is required to use the Palo Alto Networks built-in IP address EDLs?

DNS Security
DNS Security
Threat Prevention
Threat Prevention
WildFire
WildFire
SD-Wan
SD-Wan
Suggested answer: B

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/use-an-external-dynamic-listin-policy/builtin-edls.html#:~:text=With%20an%

asked 23/09/2024
Grzegorz GÅ‚ogowski
32 questions

Question 188

Report
Export
Collapse

Which component is a building block in a Security policy rule?

decryption profile
decryption profile
destination interface
destination interface
timeout (min)
timeout (min)
application
application
Suggested answer: D

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/policies/policiessecurity/buildingblocks-in-a-security-policy-rule.html

asked 23/09/2024
Arkadi Popov
40 questions

Question 189

Report
Export
Collapse

An administrator would like to use App-ID's deny action for an application and would like that action updated with dynamic updates as new content becomes available.

Which security policy action causes this?

Reset server
Reset server
Reset both
Reset both
Deny
Deny
Drop
Drop
Suggested answer: C

Explanation:

Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manageconfigurationbackups/revert-firewall-configuration- changes.html

asked 23/09/2024
Mitchell Mansfield
28 questions

Question 190

Report
Export
Collapse

Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?

block
block
sinkhole
sinkhole
alert
alert
allow
allow
Suggested answer: B

Explanation:

To enable DNS sinkholing for domain queries using DNS security, you must activate your DNS Security subscription, create (or modify) an Anti-Spyware policy to reference the DNS Security service, configure the log severity and policy settings for each DNS signature category, and then attach the profile to a security policy rule.

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dnssecurity/enable-dns-security

asked 23/09/2024
K W
25 questions
Total 362 questions
Go to page: of 37