Palo Alto Networks PCNSE Practice Test - Questions Answers, Page 13

List of questions
Question 121

A network security administrator has an environment with multiple forms of authentication. There is a network access control system in place that authenticates and restricts access for wireless users, multiple Windows domain controllers, and an MDM solution for company-provided smartphones. All of these devices have their authentication events logged.
Given the information, what is the best choice for deploying User-ID to ensure maximum coverage?
Question 122

Refer to the diagram. Users at an internal system want to ssh to the SSH server The server is configured to respond only to the ssh requests coming from IP 172.16.16.1.
In order to reach the SSH server only from the Trust zone, which Security rule and NAT rule must be configured on the firewall?
Question 123

Which Panorama feature protects logs against data loss if a Panorama server fails?
Question 124

An administrator is seeing one of the firewalls in a HA active/passive pair moved to 'suspended" state due to Non-functional loop. Which three actions will help the administrator troubleshool this issue? (Choose three.)
Question 125

Which User-ID mapping method should be used in a high-security environment where all IP addressto- user mappings should always be explicitly known?
Question 126

What can be used to create dynamic address groups?
Question 127

A firewall administrator has been tasked with ensuring that all Panorama configuration is committed and pushed to the devices at the end of the day at a certain time. How can they achieve this?
Question 128

Which statement accurately describes service routes and virtual systems?
Question 129

You have upgraded Panorama to 10.2 and need to upgrade six Log Collectors. When upgrading Log Collectors to 10.2, you must do what?
Question 130

Which configuration is backed up using the Scheduled Config Export feature in Panorama?
Question