Pass the Paloalto Networks Palo Alto Certifications and Accreditations PCNSE Questions and answers with CertsForce

Viewing page 10 out of 12 pages
Viewing questions 91-100 out of questions
Questions # 91:

Which two actions must an engineer take to configure SSL Forward Proxy decryption? (Choose two.)

Options:

A.

Configure the decryption profile.


B.

Define a Forward Trust Certificate.


C.

Configure SSL decryption rules.


D.

Configure a SSL/TLS service profile.


Questions # 92:

Based on the graphic which statement accurately describes the output shown in the Server Monitoring panel?

Question # 92

Options:

A.

The User-ID agent is connected to a domain controller labeled lab-client


B.

The host lab-client has been found by a domain controller


C.

The host lab-client has been found by the User-ID agent.


D.

The User-ID aaent is connected to the firewall labeled lab-client


Questions # 93:

An administrator configures a site-to-site IPsec VPN tunnel between a PA-850 and an external customer on their policy-based VPN devices.

What should an administrator configure to route interesting traffic through the VPN tunnel?

Options:

A.

Proxy IDs


B.

GRE Encapsulation


C.

Tunnel Monitor


D.

ToS Header


Questions # 94:

Given the following snippet of a WildFire submission log did the end-user get access to the requested information and why or why not?

Question # 94

Options:

A.

Yes, because the action is set to alert


B.

No, because this is an example from a defeated phishing attack


C.

No, because the severity is high and the verdict is malicious.


D.

Yes, because the action is set to allow.


Questions # 95:

Exhibit.

Question # 95

Given the screenshot, how did the firewall handle the traffic?

Options:

A.

Traffic was allowed by profile but denied by policy as a threat.


B.

Traffic was allowed by policy but denied by profile as a threat.


C.

Traffic was allowed by policy but denied by profile as encrypted.


D.

Traffic was allowed by policy but denied by profile as a nonstandard port.


Questions # 96:

Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration.

What part of the configuration should the engineer verify?

Options:

A.

IKE Crypto Profile


B.

Security policy


C.

Proxy-IDs


D.

PAN-OS versions


Questions # 97:

What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?

Options:

A.

Phase 1 and Phase 2 SAs are synchronized over HA3 links.


B.

Phase 2 SAs are synchronized over HA2 links.


C.

Phase 1 and Phase 2 SAs are synchronized over HA2 links.


D.

Phase 1 SAs are synchronized over HA1 links.


Questions # 98:

An administrator connects a new fiber cable and transceiver Ethernet1/1 on a Palo Alto Networks firewall. However, the link does not come up. How can the administrator troubleshoot to confirm the transceiver type, tx-power, rxpower, vendor name, and part number by using the CLI?

Options:

A.

show chassis status slot s1


B.

show s/stem state filter ethernet1/1


C.

show s/stem state filter sw.dev interface config


D.

show s/stem state filter-pretty sys.sl*


Questions # 99:

An administrator is troubleshooting why video traffic is not being properly classified.

If this traffic does not match any QoS classes, what default class is assigned?

Options:

A.

1


B.

2


C.

3


D.

4


Questions # 100:

Refer to the exhibit.

Question # 100

An administrator cannot see any of the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side. Where is the best place on the Palo Alto Networks NGFW to check whether the configuration is correct?

A)

Question # 100

B)

Question # 100

C)

Question # 100

D)

Question # 100

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Viewing page 10 out of 12 pages
Viewing questions 91-100 out of questions