Download Palo Alto Networks Certified Network Security Administrator.examcollection.PCNSA.v3-0.2021-01-11.1e.98q.vcex

Download Exam

File Info

Exam Palo Alto Networks Certified Network Security Administrator
Number PCNSA
File Name Palo Alto Networks Certified Network Security Administrator.examcollection.PCNSA.v3-0.2021-01-11.1e.98q.vcex
Size 3.46 Mb
Posted January 11, 2021
Downloads 17
Download Palo Alto Networks Certified Network Security Administrator.examcollection.PCNSA.v3-0.2021-01-11.1e.98q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%



 
 



Demo Questions

Question 1

Which plane on a Palo Alto Networks Firewall provides configuration, logging, and reporting functions on a separate processor?

  • A: management
  • B: network processing
  • C: data
  • D: security processing

Correct Answer: A




Question 2

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days. 
Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

  • A: All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
  • B: No impact because the apps were automatically downloaded and installed
  • C: No impact because the firewall automatically adds the rules to the App-ID interface
  • D: All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications

Correct Answer: A




Question 3

How many zones can an interface be assigned with a Palo Alto Networks firewall?

  • A: two
  • B: three
  • C: four
  • D: one

Correct Answer: D

Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/network/network-zones/security-zone-overview




Question 4

Which two configuration settings shown are not the default? (Choose two.) 

  

  • A: Enable Security Log
  • B: Server Log Monitor Frequency (sec)
  • C: Enable Session
  • D: Enable Probing

Correct Answer: BC

Reference: https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/user-identification/device-user-identification-user-mapping/enable-server-monitoring




Question 5

Which dataplane layer of the graphic shown provides pattern protection for spyware and vulnerability exploits on a Palo Alto Networks Firewall? 

  

  • A: Signature Matching
  • B: Network Processing
  • C: Security Processing
  • D: Data Interfaces

Correct Answer: A




Question 6

Which option shows the attributes that are selectable when setting up application filters?

  • A: Category, Subcategory, Technology, and Characteristic
  • B: Category, Subcategory, Technology, Risk, and Characteristic
  • C: Name, Category, Technology, Risk, and Characteristic
  • D: Category, Subcategory, Risk, Standard Ports, and Technology

Correct Answer: B

Reference: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/objects/objects-application-filters




Question 7

Actions can be set for which two items in a URL filtering security profile? (Choose two.)

  • A: Block List
  • B: Custom URL Categories
  • C: PAN-DB URL Categories
  • D: Allow List

Correct Answer: BC




Question 8

Which two statements are correct about App-ID content updates? (Choose two.)

  • A: Updated application content may change how security policy rules are enforced
  • B: After an application content update, new applications must be manually classified prior to use
  • C: Existing security policy rules are not affected by application content updates
  • D: After an application content update, new applications are automatically identified and classified

Correct Answer: AD




Question 9

Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?

  • A: Windows session monitoring via a domain controller
  • B: passive server monitoring using the Windows-based agent
  • C: Captive Portal
  • D: passive server monitoring using a PAN-OS integrated User-ID agent

Correct Answer: C




Question 10

An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?

  • A: Create an Application Filter and name it Office Programs, then filter it on the business-systems category, office-programs subcategory
  • B: Create an Application Group and add business-systems to it
  • C: Create an Application Filter and name it Office Programs, then filter it on the business-systems category
  • D: Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office

Correct Answer: A










CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files