PCNSE Exam Questions
860 real PCNSE exam questions with expert-verified answers and explanations. Page 17 of 18.
- Question #816Deploy and Configure
When creating a Policy-Based Forwarding (PBF) policy, which two components can be used? (Choose two.)
Policy-Based Forwarding (PBF)Firewall PoliciesTraffic SteeringPalo Alto Configuration - Question #817Deploy and Configure
An administrator configures HA on a customer's Palo Alto Networks firewalls with path monitoring by using the default configuration values. What are the default values for ping int...
High Availability (HA)Path MonitoringDefault SettingsFailover Configuration - Question #818Configuration Troubleshooting
An administrator is troubleshooting intermittent connectivity problems with a user's GlobalProtect connection. Packet captures at the firewall reveal missing UDP packets, suggestin...
GlobalProtectVPN TroubleshootingAgent ConfigurationProtocol Enforcement - Question #819Deploy and Configure
What type of NAT is required to configure transparent proxy?
NATTransparent ProxyDNAT - Question #820Deploy and Configure
What should an engineer consider when setting up the DNS proxy for web proxy?
DNS ProxyWeb ProxyFirewall ConfigurationNetwork Services - Question #821Deploy and Configure
An administrator is creating a new Dynamic User Group to quarantine users for suspicious activity. Which two objects can Dynamic User Groups use as match conditions for group membe...
Dynamic User GroupsUser-IDDynamic TagsLDAP attributes - Question #822Configuration Troubleshooting
A firewall administrator has configured User-ID and deployed GlobalProtect, but there is no User- ID showing in the traffic logs. How can the administrator ensure that User-IDs are...
User-IDGlobalProtectTraffic LogsZone Configuration - Question #823Core Concepts
A decryption policy has been created with an action of "No Decryption." The decryption profile is configured in alignment to best practices. What protections does this policy provi...
Decryption PolicySSL InspectionCertificate ValidationFirewall Security - Question #824Plan
An administrator plans to install the Windows User-ID agent on a domain member system. What is a best practice for choosing where to install the User-ID agent?
User-ID AgentDeployment Best PracticesAgent PlacementLog Collection - Question #825Deploy and Configure
Which statement accurately describes how web proxy is run on a firewall with multiple virtual systems?
Web ProxyVirtual SystemsFeature LimitationsDeployment - Question #826Plan
A company wants to use GlobalProtect as its remote access VPN solution. Which GlobalProtect features require a Gateway license?
GlobalProtectVPNLicensingRemote Access - Question #827Operate
A firewall engineer is investigating high dataplane CPU utilization. To decrease the load on this CPU, what should be reduced?
Dataplane performanceCPU utilizationSSL decryptionPerformance troubleshooting - Question #828Core Concepts
Which protocol is natively supported by GlobalProtect Clientless VPN?
GlobalProtectClientless VPNHTTPSSSL VPN - Question #829Deploy and Configure
An administrator wants to add User-ID information for their Citrix MetaFrame Presentation Server (MPS) users. Which option should the administrator use?
User-IDTerminal Server AgentCitrixUser Mapping - Question #830Configuration Troubleshooting
An administrator is troubleshooting application traffic that has a valid business use case, and observes the following decryption log message: "Received fatal alert UnknownCA from...
SSL DecryptionTroubleshootingCertificate ManagementExclusion Lists - Question #831Operate
After configuring an IPSec tunnel, how should a firewall administrator initiate the IKE phase 1 to see if it will come up?
IPSec VPNIKE Phase 1CLI CommandsVPN Verification - Question #832Configuration Troubleshooting
While troubleshooting an issue, a firewall administrator performs a packet capture with a specific filter. The administrator sees drops for packets with a source IP address of 10.1...
Global CountersPacket DropsTroubleshootingCLI Diagnostics - Question #833Deploy and Configure
An administrator plans to install the Windows-Based User-ID Agent. What type of Active Directory (AD) service account should the administrator use?
User-ID AgentActive DirectoryService AccountsLeast Privilege - Question #834Deploy and Configure
A company uses GlobalProtect for its VPN and wants to allow access to users who have only an endpoint solution installed. Which sequence of configuration steps will allow access on...
GlobalProtectHIP ObjectsEndpoint PostureAntivirus/Anti-Malware - Question #835Operate
An administrator configures a preemptive active-passive high availability (HA) pair of firewalls and configures the HA election settings on firewall-02 with a device priority value...
HAPreemptionDevice PriorityFailover - Question #836Deploy and Configure
An administrator needs to assign a specific DNS server to an existing template variable. Where would the administrator go to edit a template variable at the device level?
Panorama TemplatesTemplate VariablesDevice Specific ConfigurationVariable Management - Question #837Configuration Troubleshooting
Certain services in a customer implementation are not working, including Palo Alto Networks Dynamic version updates. Which CLI command can the firewall administrator use to verify...
Service RoutesManagement PlaneCLI CommandsTroubleshooting - Question #838Operate
What action does a firewall take when a Decryption profile allows unsupported modes and unsupported traffic with TLS 1.2 protocol traverses the firewall?
TLS DecryptionDecryption ProfilesUnsupported ProtocolsFirewall Behavior - Question #839Deploy and Configure
A firewall administrator is configuring an IPSec tunnel between a company's HQ and a remote location. On the HQ firewall, the interface used to terminate the IPSec tunnel has a sta...
IPSec VPNDynamic IPDDNSFQDN - Question #840Configuration Troubleshooting
Review the screenshots. What is the most likely reason for this decryption error log?
SSL DecryptionCertificate Authorities (CA)TLS/SSL HandshakeTroubleshooting - Question #841Configuration Troubleshooting
SSL Forward Proxy decryption is configured, but the firewall uses Untrusted-CA to sign the certificate is not trusted" warning. Without SSL decryption, the web browser shows that t...
SSL DecryptionCertificate ManagementForward ProxyTrusted CAs - Question #842Deploy and Configure
A company has a PA-3220 NGFW at the edge of its network and wants to use active directory groups in its Security policy rules. There are 1500 groups in its active directory. An eng...
User-IDGroup MappingActive Directory IntegrationSecurity Policy - Question #843Operate
Which two scripting file types require direct upload to the Advanced WildFire portal/API for analysis? (Choose two.)
WildFireFile AnalysisScripting FilesManual Upload - Question #844Core Concepts
Which two actions can the administrative role called "vsysadmin" perform? (Choose two)
Administrative RolesVirtual Systems (vsys)Role-Based Access Control (RBAC)Security Policy Management - Question #845Configuration Troubleshooting
Which tool will allow review of the policy creation logic to verify that unwanted traffic is not allowed?
Policy VerificationSecurity PoliciesFirewall ToolsTraffic Filtering - Question #846Deploy and Configure
A customer requires that virtual systems with separate virtual routers can communicate with one another within a Palo Alto Networks firewall. In addition to confirming Security pol...
Virtual Systems (VSys)Inter-VSys RoutingVirtual RoutersZones - Question #848Deploy and Configure
A company CISO updates the business Security policy to identify vulnerable assets and services and deploy protection for quantum-related attacks. As a part of this update, the fire...
Post-Quantum CryptographyIKEv2VPN ConfigurationPAN-OS 11.2 Features - Question #849Deploy and Configure
How can a firewall be set up to automatically block users as soon as they are found to exhibit malicious behavior via a threat log?
Dynamic User GroupsUser-IDAutomated Threat ResponseLog Forwarding - Question #850Deploy and Configure
For company compliance purposes, three new contractors will be working with different device groups in their hierarchy to deploy policies and objects. Which type of role-based acce...
Role-Based Access ControlPanorama AdministrationDevice GroupsAdministrator Roles - Question #851Deploy and Configure
A firewall engineer is migrating port-based rules to application-based rules by using the Policy Optimizer. The engineer needs to ensure that the new application-based rules are fu...
Application-IDPolicy OptimizerSecurity PolicyContainer Applications - Question #852Deploy and Configure
What is the best description of the Cluster Synchronization Timeout (min)?
HAClusteringSynchronizationTimeout - Question #853Operate
An engineer has been given approval to upgrade their environment to the latest version of PAN- OS. The environment consists of both physical and virtual firewalls, a virtual Panora...
PAN-OS UpgradeUpgrade OrderPanoramaLog Collectors - Question #854Operate
A security engineer is informed that the vulnerability protection profile of their on-premises Palo Alto Networks firewall is triggering on a common Threat ID, and which has been d...
Vulnerability ProtectionException HandlingFalse PositivesOperational Efficiency - Question #855Deploy and Configure
Which configuration change will improve network reliability and ensure minimal disruption during tunnel failures?
IPsec VPNTunnel MonitoringFailoverNetwork Reliability - Question #856Deploy and Configure
Which statement explains the difference between using the PAN-OS integrated User-ID agent and the standalone User-ID agent when using Active Directory for user-to-IP mapping?
User-IDStandalone User-ID agentIntegrated User-ID agentResource consumption - Question #857Core Concepts
Which sessions does Packet Buffer Protection apply to when used on ingress zones to protect against single-session DoS attacks?
Packet Buffer ProtectionDoS ProtectionZone ProtectionSession Management - Question #858Deploy and Configure
A customer wants to enhance the protection provided by their Palo Alto Networks NGFW deployment to cover public-facing company-owned domains from misconfigurations that point recor...
Advanced DNS SecurityDNS PolicyAnti-Spyware ProfileLicensing - Question #859Deploy and Configure
An administrator is attempting to create policies for deployment of a device group and template stack. When creating the policies, the zone drop-down list does not include the requ...
PanoramaTemplatesDevice GroupsZonesPolicy Management - Question #861Configuration Troubleshooting
The decision to upgrade PAN-OS has been approved. The engineer begins the process by upgrading the Panorama servers, but gets an error when attempting the install. When performing...
PAN-OS UpgradePanoramaCertificatesTroubleshooting - Question #862Configuration Troubleshooting
Users are intermittently being cut off from local resources whenever they connect to GlobalProtect. After researching, it is determined that this is caused by an incorrect setting...
GlobalProtectSplit TunnelingGateway ConfigurationClient Settings - Question #863Deploy and Configure
Which tool can gather information about the application patterns when defining a signature for a custom application?
Custom App-IDPacket CaptureApplication SignatureWireshark - Question #864Configuration Troubleshooting
How is Perfect Forward Secrecy (PFS) enabled when troubleshooting a VPN Phase 2 mismatch?
VPNIPsecPerfect Forward Secrecy (PFS)IKE Gateway - Question #865Configuration Troubleshooting
How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?
Application overrideApp-ID bypassContent inspection bypassTroubleshooting - Question #866Deploy and Configure
An engineer needs to collect User-ID mappings from the company's existing proxies. What two methods can be used to pull this data from third-party proxies? (Choose two)
User-IDProxy IntegrationSyslogXFF Headers - Question #867Deploy and Configure
A company requires that a specific set of ciphers be used when remotely managing their Palo Alto Networks appliances. Which profile should be configured in order to achieve this?
SSL/TLS Service ProfileRemote ManagementCipher SuitesSecurity Configuration