PCNSC Exam Questions
75 real PCNSC exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1VPN and High Availability
View the GlobalProtect configuration screen capture. What is the purpose of this configuration?
GlobalProtectinternal gateway detectionreverse DNSsplit tunneling - Question #2Complex Threat Prevention and Zero Trust Implementation
Which feature prevents the submission of corporate login information into website forms?
credential phishing preventionURL filteringphishinguser credentials - Question #3Security Policy and Application Identification
A firewall engineer creates a new App-ID report under Monitor > Reports > Application Reports > New Applications to monitor new applications on the network and better assess any Se...
App-IDcontent updatesapplication reportsnew applications - Question #4Security Policy and Application Identification
An administrator needs to optimize traffic to prefer business-critical applications over non-critical applications. QoS natively integrates with which feature to provide service qu...
QoSApp-IDtraffic prioritizationbandwidth management - Question #5Threat Prevention and WildFire
A Palo Alto Networks NGFW just submitted a file to WildFire for analysis. Assume a 5- minute window for analysis. The firewall is configured to check for verdicts every 5 minutes....
WildFireverdict timingfile analysiscloud analysis - Question #6Core Firewall Concepts and Administration
Which three steps will reduce the CPU utilization on the management plane? (Choose three.)
management planeCPU utilizationperformance tuninglogging optimization - Question #7User-ID, Decryption, and Authentication
If an administrator wants to decrypt SMTP traffic and possesses the saver's certificate, which SSL decryption mode will allow the Palo Alto Networks NGFW to inspect traffic to the...
SSL inbound inspectionSMTP decryptiondecryption modesserver certificate - Question #8User-ID, Decryption, and Authentication
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?
inbound decryptionSSL troubleshootingsecurity policytriage - Question #9Core Firewall Concepts and Administration
Which feature can be configured on VM-Series firewalls?
VM-SeriesGlobalProtectvirtual firewallplatform capabilities - Question #10User-ID, Decryption, and Authentication
Which two benefits come from assigning a Decrypting Profile to a Decryption rule with a" NO Decrypt" action? (Choose two.)
decryption profileno-decrypt actioncertificate validationSSL policy - Question #11VPN and High Availability
In High Availability, which information is transferred via the HA data link?
high availabilityHA data linksession synchronizationHA2 - Question #12User-ID, Decryption, and Authentication
Which PAN-OSֲ® policy must you configure to force a user to provide additional credentials before he is allowed to access an internal application that contains highly-sensitive bus...
authentication policymulti-factor authenticationaccess controlsensitive data - Question #13Core Firewall Concepts and Administration
An administrator has left a firewall to use default port for all management services. Which three function performed by the dataplane? (Choose three.)
dataplanemanagement planeplane separationfirewall architecture - Question #14Monitoring, Logging, and Reporting
An administrator has created an SSL Decryption policy rule that decrypts SSL sessions on any port. Which log entry can the administrator use to verify that sessions are being decry...
decryption logstraffic logsSSL verificationlog analysis - Question #15Core Firewall Concepts and Administration
When is the content inspection performed in the packet flow process?
packet flowcontent inspectionApp-IDsession processing - Question #16VPN and High Availability
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to mu...
GlobalProtect satelliteLSVPNremote site VPNscalable VPN - Question #17Monitoring, Logging, and Reporting
Refer to the exhibit. An administrator cannot see any of the Traffic logs from the Palo Alto Networks NGFW on Panorama. The configuration problem seems to be on the firewall side....
Panoramalog forwardingtraffic logslog configuration - Question #18VPN and High Availability
VPN traffic intended for an administrator's Palo Alto Networks NGfW is being maliciously intercepted and retransmitted by the interceptor. When Creating a VPN tunnel, which protect...
IPsecreplay attack preventionVPN securityprotection profile - Question #19Security Policy and Application Identification
Which event will happen if an administrator uses an Application Override Policy?
application overrideApp-IDLayer 4 processingpolicy processing - Question #20Security Policy and Application Identification
The firewall identifies a popular application as an unknown-tcp. Which two options are available to identify the application? (Choose two.)
custom applicationApp-IDunknown-tcpapplication identification - Question #21Threat Prevention and WildFire
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
WildFirebasic WildFire servicefile typesmalware analysis - Question #22User-ID, Decryption, and Authentication
Which two methods can be configured to validate the revocation status of a certificate? (Choose two)
certificate revocationCRLOCSPPKI - Question #23Advanced Network Design and Integration
Which virtual router feature determines if a specific destination IP address is reachable'?
virtual routerpath monitoringroute reachabilityrouting - Question #24Advanced Network Design and Integration
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router. Which two options would help t...
BGP troubleshootingvirtual routerruntime statspacket capture - Question #25User-ID, Decryption, and Authentication
A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN-OS® software would...
User-IDuser mapping redistributionscalabilitybottleneck - Question #26Security Policy and Application Identification
During the packet flow process, which two processes are performed in application identification? (Choose two.)
App-IDapplication identificationpacket flowapplication override - Question #27Monitoring, Logging, and Reporting
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OSֲ® software, the administrator enables log forwarding from...
Panoramalog forwardingpre-existing logsCLI commands - Question #28User-ID, Decryption, and Authentication
Which administrative authentication method supports authorization by an external service?
RADIUSexternal authorizationadmin authenticationAAA - Question #29Complex Threat Prevention and Zero Trust Implementation
A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks. How can t...
DDoS protectionDoS Protection Profileresource exhaustionsession limits - Question #30VPN and High Availability
An engineer is monitoring an active/active high availability (HA) firewall pair. Which HA firewall state describes the firewall that is currently processing traffic?
active/active HAfirewall stateshigh availabilityactive-primary - Question #31Security Policy and Application Identification
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to...
SSL decryptionsecurity policyservice configurationforward proxy - Question #32User-ID, Decryption, and Authentication
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
SSH proxydecryption policyprerequisitesSSL decryption - Question #33VPN and High Availability
An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled. What must be ve...
HA upgradePAN-OS upgradeApplications and Threatscontent updates - Question #34Enterprise Security Architecture with Palo Alto Networks
Which processing order will be enabled when a panorama administrator selects the setting "Objects defined in ancestors will takes higher precedence?
Panoramaobject precedenceancestor objectspolicy hierarchy - Question #35Core Firewall Concepts and Administration
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of tha...
commit verificationtask manageradministrationcommit progress - Question #36Monitoring, Logging, and Reporting
How would an administrator monitor/capture traffic on the management interface of the Palo Alto Networks NGFW?
management interfacetcpdumptraffic capturetroubleshooting - Question #37Monitoring, Logging, and Reporting
An organization has Palo Alto Networks MGfWs that send logs to remote monitoring and security management platforms. The network team has report has excessive traffic on the corpora...
log forwardingPanoramaWAN traffic optimizationlog consolidation - Question #38Advanced Network Design and Integration
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach How can the firewall be configured automatically disable the PBF rule if the next hop goes down?
policy-based forwardingPBFmonitor profilefailover action - Question #39Threat Prevention and WildFire
Which two methods can be used to verify firewall connectivity to Autofocus? (Choose two. )
AutoFocusconnectivity verificationthreat intelligencelicense management - Question #40Security Policy and Application Identification
An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same firewall. The update contain...
custom applicationApp-ID precedencedynamic updatesapplication signatures - Question #41VPN and High Availability
Which three options are supposed in HA Lite? (Choose three.)
HA Litehigh availabilitysession synchronizationconfiguration synchronization - Question #42User-ID, Decryption, and Authentication
Which three user authentication services can be modified in to provide the Palo Alto Networks NGFW with both username and role names? (Choose three.)
authentication servicesSAMLTACACS+RADIUS - Question #43VPN and High Availability
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs. The administrator assigns priority 100 to the active firewall. Which priority...
HA priorityactive/passive HAfirewall priority - Question #44Threat Prevention and WildFire
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log. What...
DNS sinkholecommand and controlanti-spywaretraffic logs - Question #45Monitoring, Logging, and Reporting
A session in the Traffic log is reporting the application as "incomplete". What does "incomplete" mean?
application identificationTCP handshakeincomplete sessiontraffic logs - Question #46Security Policy and Application Identification
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
DNATNAT policysecurity policy zonesDMZ - Question #47VPN and High Availability
Which version of Global Protect supports split tunneling based on destination domain, client process, and HTTP/HTTPs video streaming application?
GlobalProtectsplit tunnelingPAN-OS versionVPN - Question #48User-ID, Decryption, and Authentication
Which User-ID method should be configured to map IP addresses to usernames for users connected through a terminal server?
User-IDterminal serverport mappingIP-to-username mapping - Question #49VPN and High Availability
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewalls use layer 3 interface to send traffic to a single gateway IP for...
active/active HAfloating IPgratuitous ARPhigh availability - Question #50Enterprise Security Architecture with Palo Alto Networks
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between panorama and the managed firewall and Log Collectors. Ho...
PKIcustom certificatesPanoramamutual authentication