Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

Palo Alto Networks: PCNSE Practice Exam Questions And Answers

Beoordeling
-
Verkocht
-
Pagina's
9
Cijfer
A+
Geüpload op
28-10-2024
Geschreven in
2024/2025

What can be used to push network and device configurations from Panorama to firewalls running PAN-OS software? - ANS Templates Which two virtualization platforms officially support the deployment of Palo Alto Networks VM-Series firewalls? - ANS Kernel Virtualization Module (KVM) Microsoft Hyper-V Where can the oversubscription rate be adjusted on platforms that support NAT oversubscription? - ANS In the GUI, under Device - Setup - Session - Session Settings Which action will display the NAT policies that are deployed on the firewall? - ANS From the command line, check the NAT policies loaded on the data plane using the command "show running nat-policy." What is the proper method to determine which active sessions on the firewall matched a security rule named "ftp-out"? - ANS In the CLI, run the command "show session all filter rule ftp-out." Which feature of the Palo Alto Networks firewall was designed to minimize network latency on the data plane? - ANS Single-Pass Parallel Processing Architecture Which statement is true about how Palo Alto Networks firewalls monitor traffic on the network? - ANS Unlike traditional firewalls that use port or protocol to identify applications, the Palo Alto Networks firewalls use the application signature (the App-ID technology) to identify applications. Consider this graphic representation of the Threat Monitor report: What does this report display? - ANS It displays the Top 10 Threats over the last 6 hours The WildFire Cloud or WF500 appliance provide information to which two Palo Alto Networks security services? - ANS Threat Prevention URL Filtering When configuring packet capture on a Palo Alto Networks firewall, what are the valid stage types? - ANS Receive, firewall, transmit, and drop You are analyzing a specific device group from Panorama and notice there are a very large number of "insufficient data" log entries. What does "insufficient data" mean? - ANS The amount of data seen during a session was not enough to identify the application. A customer has a requirement for a hardware firewall that supports at least two virtual systems (vsys). Which platform would be the smallest one to meet the requirement? - ANS PA-3220 A company wants to run their pair of firewalls in a High Availability active/passive mode and will be using HA-Lite. Which capability can be used in this situation? - ANS Configuration Sync Which two features can be used to tag a username so that it is included in a dynamic user group? - ANS XML API Built-in Actions in Log Forwarding Which feature will control how the firewall handles web servers with expired certificates when decrypting SSL? - ANS Decryption Profile An engineer has been tasked with sizing a firewall in an environment that requires decryption. When sizing the NGFW, what are two measurements the engineer should take? - ANS Measure the average transaction size of all traffic Measure the average transaction size of traffic on port 443 A website is presenting an RSA 2048-bit key. By default, what will the size of the key be in the certificate sent by the firewall to the client when doing SSL Decryption? - ANS 2048 Bits A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama. Which configuration is necessary in order to be able to select user groups directly inside Panorama policies? - ANS Configure a master device within the device group

Meer zien Lees minder
Instelling
PALO ALTO PCNSE NGFW
Vak
PALO ALTO PCNSE NGFW

Voorbeeld van de inhoud

PCNSE Updated Exam Questions And
Answers


2 ways to Reset to Factory default - ANS * from CLI with known password
. request system private-data-reset

* from CLI without PW
reboot and type "maint" during bootup
choose Reset to factory default
or load another config into running memory

DNS and NTP are configured where? - ANS Device > Setup > Services

where do you configure service routes - ANS device > setup > services > service route
configuration

name of the running config - ANS running-config.xml

where do you manage configurations - ANS device > setup > operations

Steps needed prior to firewall being usable - ANS * register with PA
* activate licenses
* verify update and DNS
* manage content updates
* install software updates

where is Pan-OS software updates - ANS device > software

where do you define an interface management profile - ANS network > network profiles >
interface mgmt > add

What are the four major components that enable threat prevetion - ANS * Natively
integrated technologies that leverage single pass prevention architecture, support open
communication

* Automated creation and delivery of protection mechanisms

*Extensibility and flexibility

, * Threat inelligence sharing

Throughput in a PA 7080 - ANS App-ID firewall throughput 200Gps
Threat prevention throughput 100 Gbps

Throughput of a PA7050 - ANS App-id throughput 120 Gbps
Threat prevention 60 Gbps

throughput of a PA 5280/5260 - ANS App-id thoughput 68 Gbps
threat prevention throughput 30 gbps

throughput of a PA5250 - ANS app-id throughput 39 gbps
threat prevention 20 gbps

throughput of a PA5220 - ANS App-id 18gbps
threat prevention 9 gbps

Describe HA active/passive deployment - ANS recommended, single firewall config
synched between the two firewalls.
Synchronization happens across HA1 connection
Session data is kept on both firewalls via HA2

Describe HA active/active deployment - ANS two firewalls attached with 3 cables, HA1,
HA2, HA3. only recommended for load balancing

Identify ways to mitigate resource exhaustion - ANS *Denial of Service Policy - ,more
granular for specific resources
* Zone Protection Profiles (ZZP) - coveres AE zone

Why are denial of service protections applied by zone? - ANS * DOS protections are
applied very early in the processing before a lot of information is known about the connection
but the ingress interface is already known

* Because DOS protections are only applied when manually turned on to avoid quota overload
(which would make a DOS attack easier)

Which feature never requires a Decryption policy? - ANS Network address translation

How can the NGFW inform web browsers that a web server's certificate is from an unknown
certificate authority (CA)? - ANS Have two certificate authority certificates in the firewall.
One is used to produce certificates for sites whose original certificate is trusted, and the other
for certificates for sites whose original certificate is untrusted.

Geschreven voor

Instelling
PALO ALTO PCNSE NGFW
Vak
PALO ALTO PCNSE NGFW

Documentinformatie

Geüpload op
28 oktober 2024
Aantal pagina's
9
Geschreven in
2024/2025
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$10.89
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
DocLaura Galen College Of Nursing
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
159
Lid sinds
2 jaar
Aantal volgers
38
Documenten
6400
Laatst verkocht
2 weken geleden

4.2

44 beoordelingen

5
27
4
4
3
10
2
2
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen