Palo Alto Networks PCNSE Practice Test - Questions Answers, Page 13
List of questions
Question 121
A network security administrator has an environment with multiple forms of authentication. There is a network access control system in place that authenticates and restricts access for wireless users, multiple Windows domain controllers, and an MDM solution for company-provided smartphones. All of these devices have their authentication events logged.
Given the information, what is the best choice for deploying User-ID to ensure maximum coverage?
Question 122
Refer to the diagram. Users at an internal system want to ssh to the SSH server The server is configured to respond only to the ssh requests coming from IP 172.16.16.1.
In order to reach the SSH server only from the Trust zone, which Security rule and NAT rule must be configured on the firewall?
Question 123
Which Panorama feature protects logs against data loss if a Panorama server fails?
Question 124
An administrator is seeing one of the firewalls in a HA active/passive pair moved to 'suspended" state due to Non-functional loop. Which three actions will help the administrator troubleshool this issue? (Choose three.)
Question 125
Which User-ID mapping method should be used in a high-security environment where all IP addressto- user mappings should always be explicitly known?
Question 126
What can be used to create dynamic address groups?
Question 127
A firewall administrator has been tasked with ensuring that all Panorama configuration is committed and pushed to the devices at the end of the day at a certain time. How can they achieve this?
Question 128
Which statement accurately describes service routes and virtual systems?
Question 129
You have upgraded Panorama to 10.2 and need to upgrade six Log Collectors. When upgrading Log Collectors to 10.2, you must do what?
Question 130
Which configuration is backed up using the Scheduled Config Export feature in Panorama?
Question