PCNSC Exam Questions
75 real PCNSC exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Advanced Network Design and Integration
Refer to the exhibit. Which will be the egress interface if the traffic's ingress interface is ethernet 1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?
routingvirtual routeregress interfaceroute lookup - Question #52Security Policy and Application Identification
An administrator sees several inbound sessions identified as unknown tcp in the Traffic logs. The administrator determines that these sessions are from external users accessing the...
custom App-IDapplication identificationthreat scanningApp-ID - Question #53Advanced Network Design and Integration
An administrator has enabled OSPF on a virtual router on the NGFW. OSPF is not adding new routes to the virtual router. Which two options enable the administrator to troubleshoot t...
OSPFvirtual routerrouting troubleshootingruntime status - Question #54Monitoring, Logging, and Reporting
Which two options prevents the firewall from capturing traffic passing through it? (Choose two.)
packet capturetraffic offloadPCAP filtertroubleshooting - Question #55User-ID, Decryption, and Authentication
Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)
SSL decryptionuntrusted certificatesno-decrypt policyCRL - Question #56Enterprise Security Architecture with Palo Alto Networks
How does Panorama prompt VMWare NSX to quarantine an infected VM?
PanoramaVMware NSXquarantineHTTP Server Profile - Question #57Threat Prevention and WildFire
Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.)
Panoramadynamic updatessubscriptionsantivirus - Question #58Automation and Orchestration
Which method will dynamically register tags on the Palo Alto Networks NGFW?
dynamic address groupsXML APItag registrationUser-ID agent - Question #59Core Firewall Concepts and Administration
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using Link aggregation. Which two formats are correct for naming aggregate interlaces? (Cho...
link aggregationaggregate interfaceinterface namingLACP - Question #60Core Firewall Concepts and Administration
Which CLI command enables an administrator to view details about the firewall including uptime, PAN-OSֲ® version, and serial number?
CLI commandsshow system infofirewall administrationPAN-OS - Question #61VPN and High Availability
An administrator pushes a new configuration from panorama to a pair of firewalls that are configured as active/passive HA pair. Which NGFW receives the configuration from panorama?
Panorama config pushHA pairactive/passivesynchronization behavior - Question #62VPN and High Availability
What is exchanged through the HA2 link?
HA2 linksession synchronizationhigh availabilityHA data plane - Question #63Security Policy and Application Identification
A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny". Which action will this configuration cause on the matched traffic?
Security policyVulnerability Protection Profiledeny actionprofile interaction - Question #64Threat Prevention and WildFire
Which DoS protection mechanism detects and prevents session exhaustion attacks?
DoS protectionsession exhaustionResource Protectionflood protection - Question #65Core Firewall Concepts and Administration
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the...
DNATNAT rulesDMZdestination NAT - Question #66Threat Prevention and WildFire
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-number or bacon out to eternal command-and-contr...
Anti-SpywareC2 communicationcommand and controlcompromised hosts - Question #67User-ID, Decryption, and Authentication
An administrator has users accessing network resources through Citrix XenApp 7.x. Which User- ID mapping solution will map multiple mat who using Citrix to connect to the network a...
User-IDTerminal Services agentCitrix XenAppuser mapping - Question #68Core Firewall Concepts and Administration
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port which it connects. How would an administrator configure the interface to 1...
CLImanagement portspeed-duplexinterface configuration - Question #69User-ID, Decryption, and Authentication
Which Captive Portal mode must be configured to support MFA authentication?
Captive PortalMFARedirect modeauthentication - Question #70User-ID, Decryption, and Authentication
Which three authentication factors does PAN-OSֲ® software support for MFA? (Choose three.)
MFAauthentication factorsVoice SMS PushPAN-OS - Question #71Core Firewall Concepts and Administration
An administrator logs in to the Palo Alto Networks NGFW and reports and reports that the WebUI is missing the policies tab. Which profile is the cause of the missing policies tab?
Admin Role profileWebUI accessrole-based access controladmin permissions - Question #72Enterprise Security Architecture with Palo Alto Networks
What should an administrator consider when planning to revert Panorama to a pre-PAN-OS 8.1 version?
PanoramaPAN-OS version reverttemplate variablesversion compatibility - Question #73Core Firewall Concepts and Administration
Which option would an administrator choose to define the certificate and protocol that Panorama and its managed devices use for SSL/TLS services?
SSL/TLS Profilecertificate managementPanoramamanaged device communication - Question #74User-ID, Decryption, and Authentication
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
credential phishingDomain Credential Filtercredential theft detectionUser-ID - Question #75Enterprise Security Architecture with Palo Alto Networks
What are two benefits of nested device groups in panorama? (Choose two )
Panoramanested device groupsShared group inheritancepolicy reuse