PCNSE6 Exam Questions
147 real PCNSE6 exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #106
When a user logs in via Captive Portal, their user information can be checked against:
- Question #107
When using Config Audit, the color yellow indicates which of the following?
- Question #108
A user is reporting that they cannot download a PDF file from the internet. Which action will show whether the downloaded file has been blocked by a Security Profile?
- Question #109
Which one of the options describes the sequence of the GlobalProtect agent connecting to a Gateway?
- Question #110
What is the correct policy to most effectively block Skype?
- Question #111
In an Anti-Virus profile, changing the action to "Block" for IMAP or POP decoders will result in the following:
- Question #112
Can multiple administrator accounts be configured on a single firewall?
- Question #113
Which two steps are required to make Microsoft Active Directory users appear in the firewall's traffic log? Choose 2 answers
- Question #114
It is discovered that WebandNetTrends Unlimited's new web server software produces traffic that the Palo Alto Networks firewall sees as "unknown-tcp" traffic. Which two configurati...
- Question #115
By default, all PA-5060 syslog data is forwarded out the Management interface. What needs to be configured in order to send syslog data out of a different interface?
- Question #116
When configuring Security rules based on FQDN objects, which of the following statements are true?
- Question #117
When allowing an Application in a Security policy on a PAN-OS 5.0 device, would a dependency Application need to also be enabled if the application does not employ HTTP, SSL, MSRPC...
- Question #118
What happens at the point of Threat Prevention license expiration?
- Question #120
A company is in the process of upgrading their existing Palo Alto Networks firewalls from version 6.1.0 to 6.1.1. Which three methods can the firewall administrator use to install...
- Question #121
When employing the BrightCloud URL filtering database in a Palo Alto Networks firewall, the order of evaluation within a profile is:
- Question #122
When troubleshooting Phase 1 of an IPSec VPN tunnel, what location will have the most informative logs?
- Question #123
What is the size limitation of files manually uploaded to WildFire
- Question #124
The "Disable Server Return Inspection" option on a security profile:
- Question #125
A network administrator uses Panorama to push security policies to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrator wish...
- Question #126
A firewall administrator is troubleshooting problems with traffic passing through the Palo Alto Networks firewall. Which method will show the global counters associated with the tr...
- Question #127
What are the benefits gained when the "Enable Passive DNS Monitoring" checkbox is chosen on the firewall? (Select all correct answers.)
- Question #129
What is the maximum usable storage capacity of an M-100 appliance?
- Question #130
In the following display, ethernetl/6 is configured with an interface management profile that allows ping with no restriction on the source address: Given the following security po...
- Question #131
When employing the Brightcloud URL filtering database on the Palo Alto Networks firewalls, the order of checking within a profile is:
- Question #132
Configuring a pair of devices into an Active/Active HA pair provides support for:
- Question #133
Which of the following types of protection are available in DoS policy?
- Question #134
Both SSL decryption and SSH decryption are disabled by default.
- Question #135
What is the default DNS Sinkhole address used by Palo Alto Networks Firewall to cut off communication?
- Question #136
What is a prerequisite for configuring a pair of Palo Alto Networks firewalls in an Active/Passive High Availability (HA) pair?
- Question #137
When an interface is in Tap mode and a policy action is set to block, the interface will send a TCP reset.
- Question #138
Users can be authenticated serially to multiple authentication servers by configuring:
- Question #139
What are two sources of information for determining if the firewall has been successful in communicating with an external User-ID Agent?
- Question #140
Which of the following interfaces types will have a MAC address?
- Question #141
In Active/Active HA environments, redundancy for the HA3 interface can be achieved by
- Question #142
Enabling "Highlight Unsused Rules" in the Security policy window will:
- Question #143
What can cause missing SSL packets when performing a packet capture on data plane interfaces?
- Question #144
Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? Choose 2 answers
- Question #145
A security engineer has been asked by management to optimize how Palo Alto Networks firewall syslog messages are forwarded to a syslog receiver. There are currently 20 PA-5060 s, e...
- Question #146
Which three inspections can be performed with a next-generation firewall but NOT with a legacy firewall? Choose 3 answers
- Question #147
Which two interface types provide support for network address translation (NAT)? Choose 2 answers
- Question #149
Which Public Key Infrastructure component is used to authenticate users for GlobalProtect when the Connect Method is set to "pre-logon"?
- Question #150
A hotel chain is using a system to centrally control a variety of items in guest rooms. The client devices in each guest room communicate to the central controller using TCP and fr...
- Question #151
Select the implicit rules enforced on traffic failing to match any user defined Security Policies:
- Question #152
Which authentication method can provide role-based administrative access to firewalls running PAN-OS?
- Question #153
A firewall is being attacked with a port scan. Which component can prevent this attack?
- Question #154
What are the three Security Policy rule Type classifications supported in PAN-OS 6.1?
- Question #155
The IT department has received complaints about VoIP call jitter when the sales staff is making or receiving calls. QoS is enabled on all firewall interfaces, but there is no QoS p...