ExamGecko
Home / Palo Alto Networks / PCNSE / List of questions
Ask Question

Palo Alto Networks PCNSE Practice Test - Questions Answers, Page 27

List of questions

Question 261

Report Export Collapse

A network security administrator wants to enable Packet-Based Attack Protection in a Zone Protection profile.

What are two valid ways to enable Packet-Based Attack Protection? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 262

Report Export Collapse

Where can a service route be configured for a specific destination IP?

Become a Premium Member for full access
  Unlock Premium Member

Question 263

Report Export Collapse

Which feature of Panorama allows an administrator to create a single network configuration that can be reused repeatedly for large-scale deployments even if values of configured objects, such as routes and interface addresses, change?

Become a Premium Member for full access
  Unlock Premium Member

Question 264

Report Export Collapse

A firewall administrator wants to have visibility on one segment of the company network. The traffic on the segment is routed on the Backbone switch. The administrator is planning to apply Security rules on segment X after getting the visibility.

There is already a PAN-OS firewall used in L3 mode as an internet gateway, and there are enough system resources to get extra traffic on the firewall. The administrator needs to complete this operation with minimum service interruptions and without making any IP changes.

What is the best option for the administrator to take?

Become a Premium Member for full access
  Unlock Premium Member

Question 265

Report Export Collapse

Refer to the exhibit.

Palo Alto Networks PCNSE image Question 265 54502 09232024001220000000

An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN.

How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all the existing monitoring/security platforms?

Become a Premium Member for full access
  Unlock Premium Member

Question 266

Report Export Collapse

An ISP manages a Palo Alto Networks firewall with multiple virtual systems for its tenants.

Where on this firewall can the ISP configure unique service routes for different tenants?

Become a Premium Member for full access
  Unlock Premium Member

Question 267

Report Export Collapse

In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?

Become a Premium Member for full access
  Unlock Premium Member

Question 268

Report Export Collapse

Which two profiles should be configured when sharing tags from threat logs with a remote User-ID agent? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 269

Report Export Collapse

A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6 12.10, and the post-NAT IP address is 192.168.10.10.

Refer to the routing and interfaces information below.

Palo Alto Networks PCNSE image Question 269 54506 09232024001220000000

Palo Alto Networks PCNSE image Question 269 54506 09232024001220000000

What should the NAT rule destination zone be set to?

Become a Premium Member for full access
  Unlock Premium Member

Question 270

Report Export Collapse

The NAT rule destination zone should be set to Outside because that is the zone where the post-NAT IP address of the server (192.168.10.10) belongs. The destination zone of a NAT rule is the zone where the translated IP address resides.

Option A is incorrect because None is not a valid zone for a NAT rule. Option C is incorrect because DMZ is the zone where the pre-NAT IP address of the server (153.6 12.10) belongs, not the post-NAT IP address. Option D is incorrect because Inside is not a zone that is configured on the firewall.

An administrator is troubleshooting why video traffic is not being properly classified.

If this traffic does not match any QoS classes, what default class is assigned?

Become a Premium Member for full access
  Unlock Premium Member
Total 470 questions
Go to page: of 47
Search

Related questions