ExamGecko
Home / Palo Alto Networks / PCNSE / List of questions
Ask Question

Palo Alto Networks PCNSE Practice Test - Questions Answers, Page 32

List of questions

Question 311

Report Export Collapse

An engineer is configuring a template in Panorama which will contain settings that need to be applied to all firewalls in production.

Which three parts of a template an engineer can configure? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 312

Report Export Collapse

A security engineer needs firewall management access on a trusted interface.

Which three settings are required on an SSL/TLS Service Profile to provide secure Web UI authentication? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 313

Report Export Collapse

An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.

What is one way the administrator can meet this requirement?

Become a Premium Member for full access
  Unlock Premium Member

Question 314

Report Export Collapse

A firewall engineer reviews the PAN-OS GlobalProtect application and sees that it implicitly uses web-browsing and depends on SSL.

When creating a new rule, what is needed to allow the application to resolve dependencies?

Become a Premium Member for full access
  Unlock Premium Member

Question 315

Report Export Collapse

An administrator has configured OSPF with Advanced Routing enabled on a Palo Alto Networks firewall running PAN-OS 10.2. After OSPF was configured, the administrator

noticed that OSPF routes were not being learned.

Which two actions could an administrator take to troubleshoot this issue? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 316

Report Export Collapse

Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external,

public NAT IP for that server.

Given the rule below, what change should be made to make sure the NAT works as expected?

Palo Alto Networks PCNSE image Question 316 54553 09232024001220000000

Palo Alto Networks PCNSE image Question 316 54553 09232024001220000000


Become a Premium Member for full access
  Unlock Premium Member

Question 317

Report Export Collapse

An administrator needs to identify which NAT policy is being used for internet traffic.

From the Monitor tab of the firewall GUI, how can the administrator identify which NAT policy is in use for a traffic flow?

Become a Premium Member for full access
  Unlock Premium Member

Question 318

Report Export Collapse

An administrator troubleshoots an issue that causes packet drops.

Which log type will help the engineer verify whether packet buffer protection was activated?

Become a Premium Member for full access
  Unlock Premium Member

Question 319

Report Export Collapse

Which two policy components are required to block traffic in real time using a dynamic user group (DUG)? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 320

Report Export Collapse

A network security administrator wants to inspect HTTPS traffic from users as it egresses through a firewall to the Internet/Untrust zone from trusted network zones.

The security admin wishes to ensure that if users are presented with invalid or untrusted security certificates, the user will see an untrusted certificate warning.

What is the best choice for an SSL Forward Untrust certificate?

Become a Premium Member for full access
  Unlock Premium Member
Total 470 questions
Go to page: of 47
Search

Related questions