PCNSE6 Exam Questions
147 real PCNSE6 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1
Which option allows an administrator to segrate Panorama and Syslog traffic, so that the Management Interface is not employed when sending these types of traffic?
- Question #2
To properly configure DOS protection to limit the number of sessions individually from specific source IPs you would configure a DOS Protection rule with the following characterist...
- Question #3
Where can the maximum concurrent SSL VPN Tunnels be set for Vsys2 when provisioning a Palo Alto Networks firewall for multiple virtual systems?
- Question #4
The "Drive-By Download" protection feature, under File Blocking profiles in Content-ID, provides:
- Question #5
What is the name of the debug save file for IPSec VPN tunnels?
- Question #6
You are configuring a File Blocking Profile to be applied to all outbound traffic uploading a specific file type, and there is a specific application that you want to match in the...
- Question #7
When setting up GlobalProtect, what is the job of the GlobalProtect Portal? Select the best answer
- Question #8
via Google Translator?
- Question #9
In order to route traffic between layer 3 interfaces on the PAN firewall you need:
- Question #10
Wildfire may be used for identifying which of the following types of traffic?
- Question #11
Wildfire may be used for identifying which of the following types of traffic?
- Question #12
As a Palo Alto Networks firewall administrator, you have made unwanted changes to the Candidate configuration. These changes may be undone by Device > Setup > Operations > Configur...
- Question #13
A company wants to run their pair of PA-200 firewalls in a High Availability Active/Passive configuration and will be using HA-Lite. Which capability can be used in this situation?
- Question #14
Which of the following must be configured when deploying User-ID to obtain information from an 802.1x authenticator?
- Question #15
To create a custom signature object for an Application Override Policy, which of the following fields are mandatory?
- Question #16
For non-Microsoft clients, what Captive Portal method is supported?
- Question #17
Which of the following objects cannot use User-ID as a match criteria?
- Question #18
An Outbound SSL forward-proxy decryption rule cannot be created using which type of zone?
- Question #19
A Palo Alto Networks firewall has the following interface configuration; Hosts are directly connected on the following interfaces: Ethernet 1/6 -Host IP 192.168.62.2 Ethernet 1/3 -...
- Question #20
Which best describes how Palo Alto Networks firewall rules are applied to a session?
- Question #21
A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy r...
- Question #22
What built-in administrator role allows all rights except for the creation of administrative accounts and virtual systems?
- Question #23
Company employees have been given access to the GlobalProtect Portal at https://portal.company.com: Assume the following: 1. The firewall is configured to resolve DNS names using t...
- Question #24
What will the user experience when attempting to access a blocked hacking website through a translation service such as Google Translate or Bing Translator?
- Question #25
How do you limit the amount of information recorded in the URL Content Filtering Logs?
- Question #26
Which of the following describes the sequence of the Global Protect agent connecting to a Gateway?
- Question #27
When a Palo Alto Networks firewall is forwarding traffic through interfaces configured for L2 mode, security policies can be set to match on multicast IP addresses.
- Question #29
Which of the following are methods HA clusters use to identify network outages?
- Question #30
Which URL Filtering Security Profile action logs the URL Filtering category to the URL Filtering log?
- Question #31
In PANOS 6.0, rule numbers are:
- Question #32
As the Palo Alto Networks administrator, you have enabled Application Block pages. Afterward, some users do not receive web-based feedback for all denied applications. Why would th...
- Question #33
Which of the Dynamic Updates listed below are issued on a daily basis?
- Question #34
When configuring a Decryption Policy, which of the following are available as matching criteria in a policy? (Choose 3)
- Question #35
When Destination Network Address Translation is being performed, the destination in the corresponding Security Policy Rule should use:
- Question #36
When creating a Security Policy to allow Facebook in PAN-OS 5.0, how can you be sure that no other web-browsing traffic is permitted?
- Question #37
A network engineer experienced network reachability problems through the firewall. The routing table on the device is complex. To troubleshoot the problem the engineer ran a Comman...
- Question #38
A user complains that they are no longer able to access a needed work application after you have implemented vulnerability and anti-spyware profiles. The user's application uses a...
- Question #39
Which mode will allow a user to choose how they wish to connect to the GlobalProtect Network as they would like?
- Question #40
A "Continue" action can be configured on the following Security Profiles:
- Question #41
When creating an application filter, which of the following is true?
- Question #42
Which of the following options may be enabled to reduce system overhead when using Content ID?
- Question #43
Traffic going to a public IP address is being translated by your PANW firewall to your web server's private IP. Which IP should the Security Policy use as the "Destination IP" in o...
- Question #44
What option should be configured when using User-ID
- Question #45
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens of thousands of bogus UDP connections per second to a single destinati...
- Question #46
Which fields can be altered in the default Vulnerability Protection Profile?
- Question #47
Which of the following is NOT a valid option for built-in CLI access roles?
- Question #48
What is the default setting for 'Action' in a Decryption Policy's rule?
- Question #49
Which fields can be altered in the default Vulnerability profile?
- Question #50
The following can be configured as a next hop in a Static Route:
- Question #51
Which feature can be configured with an IPv6 address?