ExamGecko

Palo Alto Networks PCNSA Practice Test - Questions Answers, Page 4

Question list
Search
Search

Which interface type is used to monitor traffic and cannot be used to perform traffic shaping?

A.
Layer 2
A.
Layer 2
Answers
B.
Tap
B.
Tap
Answers
C.
Layer 3
C.
Layer 3
Answers
D.
Virtual Wire
D.
Virtual Wire
Answers
Suggested answer: B

Which administrator type provides more granular options to determine what the administrator can view and modify when creating an administrator account?

A.
Root
A.
Root
Answers
B.
Dynamic
B.
Dynamic
Answers
C.
Role-based
C.
Role-based
Answers
D.
Superuser
D.
Superuser
Answers
Suggested answer: C

Which administrator type utilizes predefined roles for a local administrator account?

A.
Superuser
A.
Superuser
Answers
B.
Role-based
B.
Role-based
Answers
C.
Dynamic
C.
Dynamic
Answers
D.
Device administrator
D.
Device administrator
Answers
Suggested answer: C

Explanation:

References:

Which two security profile types can be attached to a security policy? (Choose two.)

A.
antivirus
A.
antivirus
Answers
B.
DDoS protection
B.
DDoS protection
Answers
C.
threat
C.
threat
Answers
D.
vulnerability
D.
vulnerability
Answers
Suggested answer: A, D

Explanation:

References:

The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.

Which security profile feature could have been used to prevent the communication with the CnC server?

A.
Create an anti-spyware profile and enable DNS Sinkhole
A.
Create an anti-spyware profile and enable DNS Sinkhole
Answers
B.
Create an antivirus profile and enable DNS Sinkhole
B.
Create an antivirus profile and enable DNS Sinkhole
Answers
C.
Create a URL filtering profile and block the DNS Sinkhole category
C.
Create a URL filtering profile and block the DNS Sinkhole category
Answers
D.
Create a security policy and enable DNS Sinkhole
D.
Create a security policy and enable DNS Sinkhole
Answers
Suggested answer: A

Explanation:

References:

Which user mapping method could be used to discover user IDs in an environment with multiple Windows domain controllers?

A.
Active Directory monitoring
A.
Active Directory monitoring
Answers
B.
Windows session monitoring
B.
Windows session monitoring
Answers
C.
Windows client probing
C.
Windows client probing
Answers
D.
domain controller monitoring
D.
domain controller monitoring
Answers
Suggested answer: A

What are three differences between security policies and security profiles? (Choose three.)

A.
Security policies are attached to security profiles
A.
Security policies are attached to security profiles
Answers
B.
Security profiles are attached to security policies
B.
Security profiles are attached to security policies
Answers
C.
Security profiles should only be used on allowed traffic
C.
Security profiles should only be used on allowed traffic
Answers
D.
Security profiles are used to block traffic by themselves
D.
Security profiles are used to block traffic by themselves
Answers
E.
Security policies can block or allow traffic
E.
Security policies can block or allow traffic
Answers
Suggested answer: B, C, E

Given the image, which two options are true about the Security policy rules. (Choose two.)

A.
The Allow Office Programs rule is using an Application Filter
A.
The Allow Office Programs rule is using an Application Filter
Answers
B.
In the Allow FTP to web server rule, FTP is allowed using App-ID
B.
In the Allow FTP to web server rule, FTP is allowed using App-ID
Answers
C.
The Allow Office Programs rule is using an Application Group
C.
The Allow Office Programs rule is using an Application Group
Answers
D.
In the Allow Social Networking rule, allows all of Facebook's functions
D.
In the Allow Social Networking rule, allows all of Facebook's functions
Answers
Suggested answer: A, D

Explanation:

In the Allow FTP to web server rule, FTP is allowed using port based rule and not APP-ID.

Which type of security rule will match traffic between the Inside zone and Outside zone, within the Inside zone, and within the Outside zone?

A.
global
A.
global
Answers
B.
intrazone
B.
intrazone
Answers
C.
interzone
C.
interzone
Answers
D.
universal
D.
universal
Answers
Suggested answer: D

Explanation:

References:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClomCAC

Which Palo Alto Networks firewall security platform provides network security for mobile endpoints by inspecting traffic deployed as internet gateways?

A.
GlobalProtect
A.
GlobalProtect
Answers
B.
AutoFocus
B.
AutoFocus
Answers
C.
Aperture
C.
Aperture
Answers
D.
Panorama
D.
Panorama
Answers
Suggested answer: A
Total 362 questions
Go to page: of 37