[Mar-2023] PCNSC Questions - Truly Beneficial For Your Palo Alto Networks Exam [Q12-Q28]

Share

[Mar-2023] PCNSC Questions - Truly Beneficial For Your Palo Alto Networks Exam

Download Palo Alto Networks PCNSC Sample Questions

NEW QUESTION 12
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?

  • A. Matching any valid corporate username.
  • B. Using the name user's corporate username and password.
  • C. First four letters of the username matching any valid corporate username.
  • D. Mapping to the IP address of the logged-in user.

Answer: D

 

NEW QUESTION 13
Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)

  • A. Enable the "Block seasons with untrusted Issuers- setting.
  • B. Configure a Dynamic Address Group for untrusted sites.
  • C. Create a no-decrypt Decryption Policy rule.
  • D. Configure an EDL to pull IP Addresses of known sites resolved from a CRL.
  • E. Create a Security Policy rule with vulnerability Security Profile attached.

Answer: A,E

 

NEW QUESTION 14
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS software, the administrator enables logs forwarding from the firewalls to panorama Pre-existing logs from the firewall are not appearing in Panorama.
Which action would enables the firewalls to send their preexisting logs to Panorama?

  • A. A CLI command will forward the pre-existing logs to Panorama.
  • B. Use the import option to pull logs panorama.
  • C. The- log database will need to be exported from the firewall and manually imported into Panorama.
  • D. Use the ACC to consolidate pre-existing logs.

Answer: A

 

NEW QUESTION 15
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using Link aggregation.
Which two formats are correct for naming aggregate interlaces? (Choose two.)

  • A. ae.1
  • B. ae.8
  • C. aggregate.1
  • D. aggregate.8

Answer: A,B

 

NEW QUESTION 16
An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW. THE update contains application that matches the same traffic signatures as the customer application.
Which application should be used to identify traffic traversing the NGFW?

  • A. Custom and downloaded application signature files are merged and are used
  • B. downloaded application
  • C. System longs show an application errors and signature is used.
  • D. custom application

Answer: D

 

NEW QUESTION 17
What will be the egress interface if the traffic's ingress interface is Ethernet 1/6 sourcing form 192.168.11.3 and to the destination 10.46.41.113.during the.

  • A. ethernet 1/7
  • B. ethernet 1/3
  • C. ethernet 1/5
  • D. ethernet 1/6

Answer: B

 

NEW QUESTION 18
What is exchanged through the HA2 link?

  • A. session synchronization
  • B. User-ID in information
  • C. hello heartbeats
  • D. HA state information

Answer: A

 

NEW QUESTION 19
Which Captive Portal mode must be contoured to support MFA authentication?

  • A. Transparent
  • B. Single Sign-On
  • C. Redirect
  • D. NTLM

Answer: C

 

NEW QUESTION 20
An administrator has left a firewall to used default port for all management services.
Which three function performed by the dataplane? (Choose three.)

  • A. WildFire updates
  • B. NAT
  • C. NTP
  • D. antivirus
  • E. file blocking

Answer: A,B,C

 

NEW QUESTION 21
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between panorama and the managed firewall and Log Collectors. How would the administrator establish the chain of trust?

  • A. Use custom certificates.
  • B. Set up multiple-factor authentication.
  • C. Enable LDAP or RADIUS integration.
  • D. Configure strong password

Answer: A

 

NEW QUESTION 22
Which event will happen administrator uses an Application Override Policy?

  • A. Threat-ID processing time is decreased.
  • B. The application name assigned to the traffic by the security rule is written to the traffic log.
  • C. The Palo Alto Networks NGFW Steps App-ID processing at Layer 4.
  • D. App-ID processing time is increased.

Answer: C

 

NEW QUESTION 23
An administrator sees several inbound sessions identified as unknown tcp in the Traffic logs. The administrator determines that these sessions are from external users accessing the company's propriety accounting application. The administrator wants to reliability identity this as their accounting application and to scan this traffic for threats.
Which option would achieve this result?

  • A. Create an Application Override policy and a custom threat signature for the application.
  • B. Create a custom App-ID and enable scanning on the advanced tab.
  • C. Create a custom App-ID and use the "ordered condition cheek box.
  • D. Create an Application Override policy

Answer: A

 

NEW QUESTION 24
Which feature prevents the submission of corporate login information into website forms?

  • A. credential submission prevention
  • B. User-ID
  • C. data filtering
  • D. file blocking

Answer: A

 

NEW QUESTION 25
An administrator needs to optimize traffic to prefer business-critical applications over non-critical applications.
QoS natively integrates with which feature to provide service quality?

  • A. port inspection
  • B. Content-ID
  • C. App-ID
  • D. certification revocation

Answer: C

 

NEW QUESTION 26
Which two benefits come from assigning a Decrypting Profile to a Decryption rule with a" NO Decrypt" action? (Choose two.)

  • A. Block credential phishing.
  • B. Block sessions with unsuspected cipher suites
  • C. Block sessions with client authentication
  • D. Block sessions with expired certificates
  • E. Block sessions with untrusted issuers

Answer: D,E

 

NEW QUESTION 27
If an administrator wants to decrypt SMTP traffic and possesses the saver's certificate, which SSL decryption mode will allow the Palo Alto Networks NGFW to inspect traffic to the server?

  • A. SSH Forward now proxy
  • B. TLS Bidirectional Inspection
  • C. SMTP inbound Decryption
  • D. SSL Inbound Inspection

Answer: A

 

NEW QUESTION 28
......

Truly Beneficial For Your Palo Alto Networks Exam: https://www.prep4king.com/PCNSC-exam-prep-material.html

Real PCNSC Exam Questions and Answers FREE: https://drive.google.com/open?id=1pAH56Yh_QH5Kbjkhafa6516N524QDK5h