New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks PCNSC Palo Alto Networks Certified Network Security Consultant Exam Practice Test

Page: 1 / 6
Total 60 questions

Palo Alto Networks Certified Network Security Consultant Questions and Answers

Question 1

Which two benefits comefrom assigning a Decrypting Profile to a Decryption rule with a” NO Decrypt” action? (Choose two.)

Options:

A.

Block sessions with unsuspected cipher suites

B.

Block sessions with untrusted issuers

C.

Block credential phishing.

D.

Block sessions with clientauthentication

E.

Block sessions with expired certificates

Question 2

A session in the Traffic log is reporting the application as "incomplete”

What does "incomplete" mean?

Options:

A.

The three-way TCP handshake did notcomplete.

B.

Data was received but wan instantly discarded because of a Deny policy was applied before App ID could be applied.

C.

The three-way TCP handshake was observed, but the application could not be identified.

D.

The traffic is coming across UDP, and the application could not be identified.

Question 3

A customer wants to combine multiple Ethernet interfaces into a single virtual interface using Link aggregation.

Which two formats are correct for naming aggregate interlaces? (Choose two.)

Options:

A.

aggregate.8

B.

ae.8

C.

ae.1

D.

aggregate.1

Question 4

Which CLI command enables an administrator to view detail about the firewall including uptime. PAN -OS® version, and serial number?

Options:

A.

debug system details

B.

Show systemdetail

C.

Show system info

D.

Show session info

Question 5

A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN -OS® software would help in this case?

Options:

A.

content inspection

B.

application override

C.

Virtual Wire mode

D.

redistribution of user mappings

Question 6

Which two methods can be configured to validate the revocation status of a certificate? (Choose two)

Options:

A.

CRL

B.

Cert-Validation-Profile

C.

OCSP

D.

CRT

E.

SSL /TLS Service Profile

Question 7

How does Panorama prompt VMware NSX to quarantine an in6erface VM??

Options:

A.

Syslog Server Profile

B.

Email Server Profile

C.

SNMP Server Profile

D.

HTTP Server Profile

Question 8

Which administrative authentication method supports authorization by an external service?

Options:

A.

RADIUS

B.

SSH keys

C.

Certification

D.

LDAP

Question 9

An administrator deploys PA-500 NGFWs as an active/passive high availability pair . Thedevices are not participating in dynamic router and preemption is disabled.

What must be verified to upgrade the firewalls to the most recent version of PAN OS® software?

Options:

A.

Antivirus update package

B.

Applications and Threats update package

C.

Wildfire update package

D.

User-ID agent

Question 10

View theGlobalProtect configuration screen capture.

What is the purpose of this configuration?

Question # 10

Options:

A.

It forces an internal client to connect to an internal gateway at IP address 192 168 10 I.

B.

It configures the tunnel address of all internal clients lo an IP address range starting at 192 168 10 1.

C.

It forces the firewall to perform a dynamic DNS update, Which adds the internal gateway's hostname and IP address to the DNS server.

D.

It enables a Client to perform a reverse DNS lookup on 192 .168. 10 .1. to delectit is an internal client.

Question 11

Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSLforward proxy? (Choose two.)

Options:

A.

Configure an EDL to pull IP Addresses of known sites resolved from a CRL.

B.

Create a Security Policy rule with vulnerability Security Profile attached.

C.

Create a no-decrypt Decryption Policy rule.

D.

Enable the "Block seasons with untrusted Issuers- setting.

E.

Configure a Dynamic Address Group for untrusted sites.

Page: 1 / 6
Total 60 questions