PCNSE7 Exam Questions
223 real PCNSE7 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Configure and Deploy
A company.com wants to enable Application Override. Given the following screenshot: Which two statements are true if Source and Destination traffic match the Application Override p...
Application OverrideApp-IDContent-ID bypassUDP port mapping - Question #2
Which three fields can be included in a pcap filter? (Choose three)
- Question #3Operate and Manage
What are three possible verdicts that WildFire can provide for an analyzed sample? (Choose three)
WildFiremalware verdictsthreat analysisgrayware - Question #4
A logging infrastructure may need to handle more than 10,000 logs per second. Which two options support a dedicated log collector function? (Choose two)
- Question #5
What are three valid method of user mapping? (Choose three)
- Question #6Troubleshoot and Optimize
A host attached to ethernet1/3 cannot access the internet. The default gateway is attached to ethernet1/4. After troubleshooting. It is determined that traffic cannot pass from the...
interface modesLayer 2 vs Layer 3routingconnectivity troubleshooting - Question #7Troubleshoot and Optimize
The IT department has received complaints abou VoIP call jitter when the sales staff is making or receiving calls. QoS is enabled on all firewall interfaces, but there is no QoS po...
QoS statisticsreal-time monitoringbandwidthVoIP jitter - Question #8Operate and Manage
A network security engineer is asked to provide a report on bandwidth usage. Which tab in the ACC provides the information needed to create the report?
ACCnetwork activitybandwidth reportingtraffic analysis - Question #9
Which three options does the WF-500 appliance support for local analysis? (Choose three)
- Question #10
Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application...
- Question #11Troubleshoot and Optimize
After pushing a security policy from Panorama to a PA-3020 firewall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic l...
Panoramalog forwarding profiletraffic logspolicy logging - Question #12Configure and Deploy
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermo...
Anti-SpywareDNS sinkholebotnet detectionC2 identification - Question #13Configure and Deploy
Which two statements are correct for the out-of-box configuration for Palo Alto Networks NGFWs? (Choose two)
default configurationmanagement interfacevirtual wireout-of-box defaults - Question #14
A network security engineer is asked to perform a Return Merchandise Authorization (RMA) on a firewall Which part of files needs to be imported back into the replacement firewall t...
- Question #15Troubleshoot and Optimize
A network engineer has revived a report of problems reaching 98.139.183.24 through vr1 on the firewall. The routing table on this firewall is extensive and complex. Which CLI comma...
CLIFIB lookupvirtual routerrouting troubleshooting - Question #16Configure and Deploy
Which two mechanisms help prevent a spilt brain scenario an Active/Passive High Availability (HA) pair? (Choose two)
High Availabilitysplit brainHA1 backupActive/Passive HA - Question #17Configure and Deploy
What are three valid actions in a File Blocking Profile? (Choose three)
File Blocking Profilesecurity profilesfile transfer actions - Question #18Troubleshoot and Optimize
An Administrator is configuring an IPSec VPN toa Cisco ASA at the administrator's home and experiencing issues completing the connection. The following is th output from the comman...
IPSec VPNProxy IDIKE negotiationVPN troubleshooting - Question #19Configure and Deploy
Which interface configuration will accept specific VLAN IDs?
subinterfaceVLAN tagginginterface configurationLayer 3 - Question #20Configure and Deploy
Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)
PAN-DB URL filteringDNS-based C2 signaturesmalicious domain databasethreat prevention - Question #21Configure and Deploy
Which two methods can be used to mitigate resource exhaustion of an application server? (Choose two)
DoS Protection ProfileZone Protection Profileresource exhaustionapplication server protection - Question #22
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192....
- Question #23
A VPN connection is set up between Site-A and Site-B, but no traffic is passing in the system log of Site-A, there is an event logged as like-nego-p1-fail-psk. What action will bri...
- Question #24Troubleshoot and Optimize
A firewall administrator is troubleshooting problems with traffic passing through the Palo Alto Networks firewall. Which method shows the global counters associated with the traffi...
CLIglobal counterspacket filtertraffic debugging - Question #25Troubleshoot and Optimize
A network security engineer has been asked to analyze Wildfire activity. However, the Wildfire Submissions item is not visible form the Monitor tab. What could cause this condition...
WildFiresubscription licensingMonitor tabWildFire submissions - Question #26Plan and Implement
Which Palo Alto Networks VM-Series firewall is supported for VMware NSX?
VM-SeriesVMware NSXVM-1000-HVvirtualization - Question #27Configure and Deploy
A client is deploying a pair of PA-5000 series firewalls using High Availability (HA) in Active/Passive mode. Which statement is true about this deployment?
High AvailabilityActive/PassivePA-5000HA management port backup - Question #28Configure and Deploy
What must be used in Security Policy Rule that contain addresses where NAT policy applies?
NAT policySecurity PolicyPre-NAT addressesPost-NAT zones - Question #29
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following securi...
- Question #30Configure and Deploy
How are IPV6 DNS queries configured to user interface ethernet1/3?
IPv6 DNSservice route configurationinterface managementDevice setup - Question #31Troubleshoot and Optimize
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination...
DoS protectionUDP floodNTP amplificationclassified DoS policy - Question #32Configure and Deploy
Which Security Policy Rule configuration option disables antivirus and anti-spyware scanning of server-to-client flows only?
server response inspectionsecurity policy optionsantivirus scanningtraffic inspection - Question #33Plan and Implement
Which three options are available when creating a security profile? (Choose three)
security profilesfile blockingURL filteringantivirus - Question #34Configure and Deploy
Given the following table. Which configuration change on the firewall would cause it to use 10.66.24.88 as the next hop for the 192.168.93.0/30 network?
administrative distanceRIPOSPFrouting protocol preference - Question #35
A company hosts a publically accessible web server behind a Palo Alto Networks next generation firewall with the following configuration information. - Users outside the company ar...
- Question #36Configure and Deploy
Which two interface types can be used when configuring GlobalProtect Portal?(Choose two)
GlobalProtect portalinterface typesloopback interfaceLayer 3 interface - Question #37
What can missing SSL packets when performing a packet capture on dataplane interfaces?
- Question #38Operate and Manage
A network Administrator needs to view the default action for a specific spyware signature. The administrator follows the tabs and menus through Objects> Security Profiles> Anti- Sp...
anti-spyware profilesignature exceptionsdefault actionssecurity profiles - Question #39Operate and Manage
How does Panorama handle incoming logs when it reaches the maximum storage capacity?
Panoramalog storagelog managementstorage capacity - Question #40Plan and Implement
Which three function are found on the dataplane of a PA-5050? (Choose three)
PA-5050 architecturedataplane functionsmanagement planehardware platform - Question #41Configure and Deploy
How is the Forward Untrust Certificate used?
SSL inspectionforward untrust certificateSSL decryptioncertificate management - Question #42Troubleshoot and Optimize
A firewall administrator has completed most of the steps required to provision a standalone Palo Alto Networks Next-Generation Firewall. As a final step, the administrator wants to...
CLI commandssecurity policy matchpolicy testingtest commands - Question #43
The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is c...
- Question #44
A company has a pair of Palo Alto Networks firewalls configured as an Acitve/Passive High Availability (HA) pair. What allows the firewall administrator to determine the last date...
- Question #45Configure and Deploy
A network administrator uses Panorama to push security polices to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrators at t...
Panoramapre-rulespost-rulespolicy override - Question #46
Which client software can be used to connect remote Linux client into a Palo Alto Networks Infrastructure without sacrificing the ability to scan traffic and protect against threat...
- Question #47
Only two Trust to Untrust allow rules have been created in the Security policy - Rule1 allows google-base - Rule2 allows youtube-base The youtube-base App-ID depends on google-base...
- Question #48Configure and Deploy
The GlobalProtect Portal interface and IP address have been configured. Which other value needs to be defined to complete the network settings configuration of GlobalPortect Portal...
GlobalProtect portalserver certificatenetwork settingsportal configuration - Question #49Troubleshoot and Optimize
Which command can be used to validate a Captive Portal policy?
Captive PortalCLI test commandspolicy matchuser identification - Question #50
A company is upgrading its existing Palo Alto Networks firewall from version 7.0.1 to 7.0.4. Which three methods can the firewall administrator use to install PAN-OS 7.0.4 across t...