PCNSE7 Exam Questions
223 real PCNSE7 exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #153
An administrator has users accessing network resources through Citrix XenApp 7 x. Which User- ID mapping solution will map multiple users who are using Citrix to connect to the net...
- Question #154
An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW. The update contains an...
- Question #155
How can a candidate or running configuration be copied to a host external from Panorama?
- Question #156
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to mu...
- Question #157
A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN-OS?software would h...
- Question #158
Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by t...
- Question #159
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
- Question #160
Which Security policy rule will allow an admin to block facebook chat but allow Facebook in general?
- Question #161
Which feature prevents the submission of corporate login information into website forms?
- Question #162
Which three steps will reduce the CPU utilization on the management plane? (Choose three.)
- Question #163
Which two virtualization platforms officially support the deployment of Palo Alto Networks VM- Series firewalls? (Choose two.)
- Question #164
To connect the Palo Alto Networks firewall to AutoFocus, which setting must be enabled?
- Question #165
Which event will happen if an administrator uses an Application Override Policy?
- Question #166
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the...
- Question #167
Which three options are supported in HA Lite? (Choose three.)
- Question #168
A session in the Traffic log is reporting the application as "incomplete." What does "incomplete" mean?
- Question #169
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS?software, the administrator enables log forwarding from t...
- Question #170
An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panora...
- Question #171
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
- Question #172
Which three firewall states are valid? (Choose three.)
- Question #173
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?
- Question #174
Which Palo Alto Networks VM-Series firewall is valid?
- Question #175
An administrator needs to implement an NGFW between their DMZ and Core network. EIGRP Routing between the two environments is required. Which interface type would support this busi...
- Question #176
A network security engineer for a large company has just installed a PA-5060 Firewall to isolate the company's PCI environment from its production network. The company's engineers...
- Question #177
After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly...
- Question #178
and service within the Traffic log?
- Question #179
If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is...
- Question #180
A web server is hosted in the DMZ, and the server is configured to listen for incoming connections only on TCP port 8080. A Security policy rule allowing access from the Trust zone...
- Question #181
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the...
- Question #182
During the packet flow process, which two processes are performed in application identification? (Choose two.)
- Question #183
An administrator logs in to the Palo Alto Networks NGFW and reports that the WebUI is missing the Policies tab. Which profile is the cause of the missing Policies tab?
- Question #184
When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?
- Question #185
The certificate information displayed in the following image is for which type of certificate?
- Question #186
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs. The administrator assigns priority 100 to the active firewall. Which priority...
- Question #187
Which option is part of the content inspection process?
- Question #188
Which three types of software will receive a Grayware verdict from WildFire? (Choose Three)
- Question #189
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port which it connects. How would an administrator configure the interface to 1...
- Question #190
In a virtual router, which object contains all potential routes?
- Question #191
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, wher...
- Question #192
A customer has an application that is being identified as unknown-top for one of their custom PostgreSQL database connections. Which two configuration options can be used to correc...
- Question #193
Server Message Block (SMB), a common file-sharing application, is slow when passing through a Palo Alto Networks firewall. The Network Security Administrator created an application...
- Question #194
An administrator has enabled OSPF on a virtual router on the NGFW. OSPF is not adding new routes to the virtual router. Which two options enable the administrator to troubleshoot t...
- Question #195
Which tool provides an administrator the ability to see trends in traffic over periods of time, such as threats detected in the last 30 days?
- Question #196
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router. Which two options would help t...
- Question #197
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach How can the firewall be configured automatically disable the PBF rule if the next hop goes down?
- Question #198
Which feature must you configure to prevent users form accidentally submitting their corporate credentials to a phishing website?
- Question #199
A Palo Alto Networks NGFW just submitted a file to WildFire for analysis. Assume a 5- minute window for analysis. The firewall is configured to check for verdicts every 5 minutes....
- Question #200
What are two benefits of nested device groups in Panorama? (Choose two.)
- Question #201
PAN-OS 7.0 introduced an automated correlation engine that analyzes log patterns and generates correlation events visible in the new Application Command Center (ACC). Which license...
- Question #202
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN-OS?software. The firewall has internet connectivity through an Ethernet interface, bu...