Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

PCNSE QUESTIONS AND ANSWER GRADED A+

Rating
-
Sold
-
Pages
9
Grade
A+
Uploaded on
30-01-2024
Written in
2023/2024

2 ways to Reset to Factory default - * from CLI with known password . request system private-data-reset * from CLI without PW reboot and type "maint" during bootup choose Reset to factory default or load another config into running memory DNS and NTP are configured where? - Device Setup Services where do you configure service routes - device setup services service route configuration name of the running config - where do you manage configurations - device setup operations Steps needed prior to firewall being usable - * register with PA * activate licenses * verify update and DNS * manage content updates * install software updates where is Pan-OS software updates - device software where do you define an interface management profile - network network profiles interface mgmt add What are the four major components that enable threat prevetion - * Natively integrated technologies that leverage single pass prevention architecture, support open communication * Automated creation and delivery of protection mechanisms *Extensibility and flexibility * Threat inelligence sharing

Show more Read less
Institution
Course

Content preview

PCNSE QUESTIONS AND ANSWER
GRADED A+

2 ways to Reset to Factory default - ✔✔* from CLI with known password
. request system private-data-reset

* from CLI without PW
reboot and type "maint" during bootup
choose Reset to factory default
or load another config into running memory

DNS and NTP are configured where? - ✔✔Device > Setup > Services

where do you configure service routes - ✔✔device > setup > services > service route
configuration

name of the running config - ✔✔running-config.xml

where do you manage configurations - ✔✔device > setup > operations

Steps needed prior to firewall being usable - ✔✔* register with PA
* activate licenses
* verify update and DNS
* manage content updates
* install software updates

where is Pan-OS software updates - ✔✔device > software

where do you define an interface management profile - ✔✔network > network profiles
> interface mgmt > add

What are the four major components that enable threat prevetion - ✔✔* Natively
integrated technologies that leverage single pass prevention architecture, support open
communication

* Automated creation and delivery of protection mechanisms

*Extensibility and flexibility

* Threat inelligence sharing

, Throughput in a PA 7080 - ✔✔App-ID firewall throughput 200Gps
Threat prevention throughput 100 Gbps

Throughput of a PA7050 - ✔✔App-id throughput 120 Gbps
Threat prevention 60 Gbps

throughput of a PA 5280/5260 - ✔✔App-id thoughput 68 Gbps
threat prevention throughput 30 gbps

throughput of a PA5250 - ✔✔app-id throughput 39 gbps
threat prevention 20 gbps

throughput of a PA5220 - ✔✔App-id 18gbps
threat prevention 9 gbps

Describe HA active/passive deployment - ✔✔recommended, single firewall config
synched between the two firewalls.
Synchronization happens across HA1 connection
Session data is kept on both firewalls via HA2

Describe HA active/active deployment - ✔✔two firewalls attached with 3 cables, HA1,
HA2, HA3. only recommended for load balancing

Identify ways to mitigate resource exhaustion - ✔✔*Denial of Service Policy - ,more
granular for specific resources
* Zone Protection Profiles (ZZP) - coveres AE zone

Why are denial of service protections applied by zone? - ✔✔* DOS protections are
applied very early in the processing before a lot of information is known about the
connection but the ingress interface is already known

* Because DOS protections are only applied when manually turned on to avoid quota
overload (which would make a DOS attack easier)

Which feature never requires a Decryption policy? - ✔✔Network address translation

How can the NGFW inform web browsers that a web server's certificate is from an
unknown certificate authority (CA)? - ✔✔Have two certificate authority certificates in
the firewall. One is used to produce certificates for sites whose original certificate is
trusted, and the other for certificates for sites whose original certificate is untrusted.

what type of identification is disabled by application override - ✔✔App-ID

what are two ways you can control unknown applications - ✔✔* Create a custom
application with a custom signature

Written for

Course

Document information

Uploaded on
January 30, 2024
Number of pages
9
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$12.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
dennisgathiru
5.0
(1)

Get to know the seller

Seller avatar
dennisgathiru City University New York
Follow You need to be logged in order to follow users or courses
Sold
3
Member since
2 year
Number of followers
2
Documents
2234
Last sold
7 months ago

5.0

1 reviews

5
1
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions