Pass the Paloalto Networks Palo Alto Certifications and Accreditations PCNSE Questions and answers with CertsForce

Viewing page 12 out of 12 pages
Viewing questions 111-120 out of questions
Questions # 111:

Review the screenshot of the Certificates page.

An administrator for a small LLC has created a series of certificates as shown, to use for a planned Decryption roll out. The administrator has also installed the self-signed root certificate in all client systems.

When testing, they noticed that every time a user visited an SSL site, they received unsecured website warnings.

What is the cause of the unsecured website warnings?

Options:

A.

The forward untrust certificate has not been signed by the self-singed root CA certificate.


B.

The forward trust certificate has not been installed in client systems.


C.

The self-signed CA certificate has the same CN as the forward trust and untrust certificates.


D.

The forward trust certificate has not been signed by the self-singed root CA certificate.


Expert Solution
Questions # 112:

An administrator is troubleshooting intermittent connectivity problems with a user's GlobalProtect connection. Packet captures at the firewall reveal missing UDP packets, suggesting potential packet loss on the connection. The administrator aims to resolve the issue by enforcing an SSL tunnel over TCP specifically for this user.

What configuration change is necessary to implement this troubleshooting solution for the user?

Options:

A.

Enable SSL tunnel within the GlobalProtect gateway remote user's settings.


B.

Modify the user's client to prioritize UDP traffic for GlobalProtect.


C.

Enable SSL tunnel over TCP in a new agent configuration for the specific user.


D.

Increase the user's VPN bandwidth allocation in the GlobalProtect settings.


Expert Solution
Viewing page 12 out of 12 pages
Viewing questions 111-120 out of questions