Computer Networking > QUESTIONS & ANSWERS > PCNSA Exam Questions and Answers Already Passed (All)

PCNSA Exam Questions and Answers Already Passed

Document Content and Description Below

PCNSA Exam Questions and Answers Already Passed Recently changes were made to the firewall to optimize the policies and the security team wants to see if those changes are helping. What is the quic... kest way to reset the hit counter to zero in all the security policy rules? A. At the CLI enter the command reset rules and press Enter B. Highlight a rule and use the Reset Rule Hit Counter > Selected Rules for each rule C. Reboot the firewall D. Use the Reset Rule Hit Counter>All Rules option ✔✔D. Use the Reset Rule Hit Counter > All Rules option Which Two App-ID applications will you need to allow in your Security policy to use facebookchat? A. facebook B. facebook-chat C. facebook-base D. facebook-email ✔✔B. facebook-chat C. facebook-base Which User-ID agent would be appropriate in a network with multiple WAN links, limited network bandwidth, and limited firewall management plane resources? A. Windows-based agents deployed on the internal network B. PAN-OS integrated agent deployed on the internal network C. Citrix terminal server deployed on the internal network D. Windows-based agent deployed on each of the WAN Links ✔✔A. Windows-based agent deployed on the internal networkYour company requires positive username attribution of every IP address used by the wireless devices to support a new compliance requirement. You must collect IP to user mapping as soon as possible with the minimal configuration changes to the wireless devices themselves. the wireless devices are from various manufactures. Given the scenario, choose the option for sending IP-to user mapping to the NGFW. A. syslog B. RADIUS C. UID redistribution D. XFF headers ✔✔A. syslog An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command- and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.) A. vulnerability protection profile applied to outbound security policies B. anti-spyware profile applied to outbound security policies C. antivirus profile applied to outbound security policies D. URL filtering profile applied to outbound security policies ✔✔B. anti-spyware profile applied to outbound security polices D. URL filtering profile applied to out bound security Which interface does not require a MAC or IP address? A. Virtual Wire B. Layer3 C. Layer2 D. Loopback ✔✔A. Virtual Wire Order the steps needed to create a new security zone with a Palo Alto Networks firewall. ✔✔Step 1 : Select NetworkStep 2: Select Zones from the list of available items Step 3: Select add Step 4: Specify Zone Name Step 5: Specify Zone type Step 6: Assign interface as needed What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.) A. An implicit dependency does not require the dependent application to be added in the security policy B. An implicit dependency requires the dependent application to be added in the security policy C. An explicit dependency does not require the dependent application to be added in the security policy D. An explicit dependency requires the dependent application to be added in the security policy ✔✔A. An implicit dependency does not require the dependent application to be added in the security policy D. An explicit dependency requires the dependent application to be added in the security policy Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor? A. management B. network processing C. data D. security processing ✔✔A. management A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified byApp-ID as SuperApp_base.On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.Based on the information, how is the SuperApp traffic affected after the 30 days have passed?A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application B. No impact because the apps were automatically downloaded and installed C. No impact because the firewall automatically adds the rules to the App-ID interface D. All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications ✔✔C. No impact because the firewall automatically adds the rules to the App-ID interface How many zones can an interface be assigned with a Palo Alto Networks firewall? A. two B. three C. four D. one ✔✔D. one Which option shows the attributes that are selectable when setting up application filters? A. Category, Subcategory, Technology, and Characteristic B. Category, Subcategory, Technology, Risk, and Characteristic C. Name, Category, Technology, Risk, and Characteristic D. Category, Subcategory, Risk, Standard Ports, and Technology ✔✔B. Category, Subcategory, Technology, Risk, and Characteristic Actions can be set for which two items in a URL filtering security profile? (Choose two.) A. Block List B. Custom URL Categories C. PAN-DB URL Categories D. Allow List ✔✔A. Block List D. Allow List Which two statements are correct about App-ID content updates? (Choose two.) A. Updated application content might change how Security policy rules are enforced. B. After an application content update, new applications must be manually classified prior to use.C. Existing security policy rules are not affected by application content updates. D. After an application content update, new applications are automatically identified and classified. ✔✔C. Existing security policy rules are not affected by application content updates. D. After an application content update, new applications are automatically identified and classified. Which User-ID mapping method should be used for an environment with [Show More]

Last updated: 1 year ago

Preview 1 out of 17 pages

Add to cart

Instant download

document-preview

Buy this document to get the full access instantly

Instant Download Access after purchase

Add to cart

Instant download

Also available in bundle (1)

PCNSA BUNDLE. ALL QUESTIONS AND ANSWERS. DIFERENT VERSIONS OF EXAM QUESTIONS WITH ACCURATE ANSWERS. RATED A DOCS

ALL YOU NEED TO PASS THE PCNSA EXAMS. PCNSA BUNDLE. ALL QUESTIONS AND ANSWERS. DIFERENT VERSIONS OF EXAM QUESTIONS WITH ACCURATE ANSWERS. RATED A DOCS

By bundleHub Solution guider 1 year ago

$25

10  

Reviews( 0 )

$7.00

Add to cart

Instant download

Can't find what you want? Try our AI powered Search

OR

REQUEST DOCUMENT
136
0

Document information


Connected school, study & course


About the document


Uploaded On

Sep 30, 2022

Number of pages

17

Written in

Seller


seller-icon
bundleHub Solution guider

Member since 2 years

314 Documents Sold


Additional information

This document has been written for:

Uploaded

Sep 30, 2022

Downloads

 0

Views

 136

Document Keyword Tags

More From bundleHub Solution guider

View all bundleHub Solution guider's documents »
What is Browsegrades

In Browsegrades, a student can earn by offering help to other student. Students can help other students with materials by upploading their notes and earn money.

We are here to help

We're available through e-mail, Twitter, Facebook, and live chat.
 FAQ
 Questions? Leave a message!

Follow us on
 Twitter

Copyright © Browsegrades · High quality services·