ExamGecko
Ask Question

Palo Alto Networks PCNSC Practice Test - Questions Answers, Page 4

Question list
Search

Related questions











Question 31

Report
Export
Collapse

An administrator needs to create a new Antivirus Profile to address a virus that is spreading internally over SMB.

To create a secure posture the administrator should choose which set of actions for the SMB decoder in an Antivirus Profile?

Action - Drop; Wildfire Action - Reset-Both
Action - Drop; Wildfire Action - Reset-Both
Action - Reset-Both: Wildfire Action - Reset-Both
Action - Reset-Both: Wildfire Action - Reset-Both
Action - Allow; Wildfire Action - Allow
Action - Allow; Wildfire Action - Allow
Action - Reset-Both. WiWfire Action - Alert
Action - Reset-Both. WiWfire Action - Alert
Suggested answer: B

Explanation:

To create a secure Antivirus Profile to address a virus spreading internally over SMB, the administrator should choose the following set of actions for the SMB decoder:

B . Action - Reset-Both; Wildfire Action - Reset-Both

Choosing 'Reset-Both' for both the Antivirus Action and the Wildfire Action ensures that the connection is terminated on both the client and server sides whenever a virus is detected. This action helps prevent the spread of the virus by cutting off the infected connection immediately.

Palo Alto Networks - Antivirus Profile Best Practices: https://docs.paloaltonetworks.com/best-practices

Palo Alto Networks - Creating and Configuring Antivirus Profiles: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/threat-prevention/antivirus-profiles

asked 23/09/2024
Paul Tierney
41 questions

Question 32

Report
Export
Collapse

Instead of disabling App-IDs regularly, a security policy rule is going to be configured to temporarily allow new App-IDs. In which two circumstances is it valid to disable App-IDs as part of content update-?

(Choose two)

when planning to enable the App-IDs immediately
when planning to enable the App-IDs immediately
when you want to immediately benefit from the latest threat prevention
when you want to immediately benefit from the latest threat prevention
when disabling facebook-base to disable all other Facebook App-IDs
when disabling facebook-base to disable all other Facebook App-IDs
when an organization operates a mission-critical network and has zero tolerance for downtime
when an organization operates a mission-critical network and has zero tolerance for downtime
Suggested answer: B, D

Explanation:

Disabling App-IDs as part of a content update can be valid in the following circumstances:

B . When you want to immediately benefit from the latest threat prevention: Disabling certain App-IDs can help ensure that the latest threat prevention measures are applied without waiting for the App-IDs to be fully tested in a specific environment. This can be crucial in quickly addressing emerging threats.

D . When an organization operates a mission-critical network and has zero tolerance for downtime: In such environments, administrators might temporarily disable new or modified App-IDs to avoid potential disruptions caused by unverified or untested App-IDs. This ensures that the network remains stable and functional while the new App-IDs are evaluated in a controlled manner.

Palo Alto Networks - Best Practices for Application and Threat Content Updates: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/app-id/manage-app-id/application-and-threat-content-updates

Palo Alto Networks - Application and Threat Content Release Notes: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/application-and-threat-content-release-notes

asked 23/09/2024
Roger Warner
33 questions

Question 33

Report
Export
Collapse

Which CLI command should you use to verify whether all SFP SFP*, or QSFP modules are installed in a firewall?

show system info
show system info
show interface <interface nane> detail
show interface <interface nane> detail
show system state filter sys.s'-p'-phy
show system state filter sys.s'-p'-phy
show system state filter sys.p*.phy
show system state filter sys.p*.phy
Suggested answer: C

Explanation:

To verify whether all SFP, SFP+, or QSFP modules are installed in a firewall, you should use the following CLI command:

C . show system state filter sys.s-phy*

This command provides detailed information about the physical state of the system, including the status of SFP, SFP+, and QSFP modules installed in the firewall.

Palo Alto Networks - CLI Commands for Troubleshooting Hardware Issues: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-cli-quick-start/troubleshooting-hardware-issues

Palo Alto Networks - Understanding Hardware and Interface Details via CLI: https://knowledgebase.paloaltonetworks.com

asked 23/09/2024
Philippe Chretien
44 questions

Question 34

Report
Export
Collapse

A customer who has a multi-tenant environment needs the administrator to be restricted lo specific objects and policies in the virtual system within its tenant How can an administrators access be restricted?

Define access domains for virtual systems in the environment
Define access domains for virtual systems in the environment
Define an Admin Role Profile with Panorama enabling all access
Define an Admin Role Profile with Panorama enabling all access
Define an access domain that enables the device groups assigned to the admin
Define an access domain that enables the device groups assigned to the admin
Define an Admin Role Profile with a device group and template enabling all access
Define an Admin Role Profile with a device group and template enabling all access
Suggested answer: A

Explanation:

To restrict an administrator's access to specific objects and policies in the virtual system within a multi-tenant environment, you should:

A . Define access domains for virtual systems in the environment

Access domains allow you to control administrator access to specific virtual systems, device groups, and templates. By defining access domains, you can restrict the administrator's permissions to only the relevant sections of the configuration, ensuring they can manage only the objects and policies within their assigned virtual systems.

Palo Alto Networks - Admin Role Profiles and Access Domains: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/administering-pan-os/admin-role-profiles-and-access-domains

Palo Alto Networks - Multi-Tenancy in Virtual Systems: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/firewall-administration/multi-tenancy

asked 23/09/2024
Ashad Conley
38 questions

Question 35

Report
Export
Collapse

Which command would you use to view the current sessions on a Palo Alto firewall?

show session all
show session all
show session info
show session info
show session list
show session list
show session current
show session current
Suggested answer: B
asked 23/09/2024
Babatunde Ipaye
40 questions

Question 36

Report
Export
Collapse

Which of the following is NOT a benefit of using App-ID?

Identifies applications running on non-standard ports
Identifies applications running on non-standard ports
Blocks application traffic that uses dynamic ports
Blocks application traffic that uses dynamic ports
Reduces the attack surface by allowing only required applications
Reduces the attack surface by allowing only required applications
Ensures consistent bandwidth allocation for all applications
Ensures consistent bandwidth allocation for all applications
Suggested answer: D
asked 23/09/2024
ERIK BURDETT
42 questions

Question 37

Report
Export
Collapse

What feature should be used to decrypt and inspect inbound SSL traffic without having to install a certificate on the client devices?

SSL Inbound Inspection
SSL Inbound Inspection
SSL Outbound Inspection
SSL Outbound Inspection
SSL Forward Proxy
SSL Forward Proxy
SSL Reverse Proxy
SSL Reverse Proxy
Suggested answer: D
asked 23/09/2024
Bhavani Simhadri
29 questions

Question 38

Report
Export
Collapse

Which GlobalProtect feature ensures that only trusted endpoints can connect to the network?

Host Information Profile (HIP)
Host Information Profile (HIP)
App-ID
App-ID
User-ID
User-ID
SSL Decryption
SSL Decryption
Suggested answer: A
asked 23/09/2024
S Tharakanparampil
36 questions

Question 39

Report
Export
Collapse

What command can you use to check the status of GlobalProtect clients connected to the firewall?

show globalprotect status
show globalprotect status
show globalprotect gateway
show globalprotect gateway
show globalprotect current-user
show globalprotect current-user
show globalprotect statistics
show globalprotect statistics
Suggested answer: B
asked 23/09/2024
Dang Xuan Bao
41 questions

Question 40

Report
Export
Collapse

Which feature allows you to use multiple links simultaneously to balance the load in a Palo Alto Networks firewall?

High Availability
High Availability
Aggregate Ethernet
Aggregate Ethernet
Virtual Wire
Virtual Wire
ECMP (Equal-Cost Multi-Path)
ECMP (Equal-Cost Multi-Path)
Suggested answer: D
asked 23/09/2024
Jaimie Korik-Read
43 questions
Total 60 questions
Go to page: of 6