Pass the Paloalto Networks Palo Alto Certifications and Accreditations PCNSE Questions and answers with CertsForce

Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions
Questions # 71:

A firewall engineer is configuring quality of service (OoS) policy for the IP address of a specific server in an effort to limit the bandwidth consumed by frequent downloads of large files from the internet.

Which combination of pre-NAT and / or post-NAT information should be used in the QoS rule?

Options:

A.

Post-NAT source IP address Pre-NAT source zone


B.

Post-NAT source IP address Post-NAT source zone


C.

Pre-NAT source IP address Post-NAT source zone


D.

Pre-NAT source IP address Pre-NAT source zone


Questions # 72:

Which are valid ACC GlobalProtect Activity tab widgets? (Choose two.)

Options:

A.

Successful GlobalProtect Deployed Activity


B.

GlobalProtect Deployment Activity


C.

GlobalProtect Quarantine Activity


D.

Successful GlobalProtect Connection Activity


Questions # 73:

Which GlobalProtect gateway selling is required to enable split-tunneling by access route, destination domain, and application?

Options:

A.

No Direct Access to local networks


B.

Tunnel mode


C.

iPSec mode


D.

Satellite mode


Questions # 74:

An engineer is reviewing the following high availability (HA) settings to understand a recent HAfailover event.

Question # 74

Which timer determines the frequency between packets sent to verify that the HA functionality on the other HA firewall is operational?

Options:

A.

Monitor Fail Hold Up Time


B.

Promotion Hold Time


C.

Heartbeat Interval


D.

Hello Interval


Questions # 75:

Which protocol is supported by Global Protect clientless VPN

Options:

A.

FTP


B.

SSH


C.

HTTPS


D.

RDP


Questions # 76:

Which sessions does Packet Buffer Protection apply to when used on ingress zones to protect against single-session DoS attacks?

Options:

A.

New sessions and is global


B.

New sessions and is not global


C.

Existing sessions and is not global


D.

Existing sessions and is global


Questions # 77:

An engineer is configuring a firewall with three interfaces:

• MGT connects to a switch with internet access.

• Ethernet1/1 connects to an edge router.

• Ethernet1/2 connects to a visualization network.

The engineer needs to configure dynamic updates to use a dataplane interface for internet traffic. What should be configured in Setup > Services > Service Route Configuration to allow this traffic?

Options:

A.

Set DNS and Palo Alto Networks Services to use the ethernet1/1 source interface.


B.

Set DNS and Palo Alto Networks Services to use the ethernet1/2 source interface.


C.

Set DNS and Palo Alto Networks Services to use the MGT source interface.


D.

Set DDNS and Palo Alto Networks Services to use the MGT source interface.


Questions # 78:

A network security administrator has an environment with multiple forms of authentication. There is a network access control system in place that authenticates and restricts access for wireless users, multiple Windows domain controllers, and an MDM solution for company-provided smartphones. All of these devices have their authentication events logged.

Given the information, what is the best choice for deploying User-ID to ensure maximum coverage?

Options:

A.

Captive portal


B.

Standalone User-ID agent


C.

Syslog listener


D.

Agentless User-ID with redistribution


Questions # 79:

An organization uses the User-ID agent to control access to sensitive internal resources. A firewall engineer adds Security policies to ensure only User A has access to a specific resource. User A was able to access the resource without issue before the updated policies, but now is having intermittent connectivity issues. What is the most likely resolution to this issue?

Options:

A.

Add service accounts running on that machine to the "Ignore User List" in the User-ID agent setup


B.

Remove the identity redistribution rules synced from Cloud Identity Engine from the User-ID agent configuration


C.

Remove the rate-limiting rule that is assigned to User A access from the User-ID agent configuration


D.

Add the subnets of both the user machine and the resource to the "Include List" in the User-ID agent configuration


Questions # 80:

An auditor is evaluating the configuration of Panorama and notices a discrepancy between the Panorama template and the local firewall configuration.

When overriding the firewall configuration pushed from Panorama, what should you consider?

Options:

A.

The firewall template will show that it is out of sync within Panorama.


B.

The modification will not be visible in Panorama.


C.

Only Panorama can revert the override.


D.

Panorama will update the template with the overridden value.


Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions