Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

PCNSC Palo Alto Networks Certified Network Security Consultant Questions and Answers

Questions 4

If an administrator wants to decrypt SMTP traffic and possesses the saver’s certificate, which SSL decryption mode will allowthe Palo Alto Networks NGFW to inspect traffic to the server?

Options:

A.

TLS Bidirectional Inspection

B.

SSL Inbound Inspection

C.

SSH Forward now proxy

D.

SMTP inbound Decryption

Buy Now
Questions 5

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying tophone-number or bacon out to eternal command-and-control (C2) servers.

Which Security Profile type will prevent these behaviors?

Options:

A.

Vulnerability Protection

B.

Antivirus

C.

Wildfire

D.

Anti-Spyware

Buy Now
Questions 6

A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny".

Which action will this configuration cause on the matched traffic?

Options:

A.

The configuration is invalid it will cause the firewall to Skip thisSecurity policy rule A warning will be displayed during a command.

B.

The configuration is valid It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to "Deny"

The configuration will allow the matched session unless a vulnerability signature is detected. The "Deny" action will supersede the per. defined, severity defined actions defined in the associated Vulnerability Protection Profile.

C.

The configuration is invalid. The Profile Settings section will be- grayed out when the action is set to "Deny"

Buy Now
Questions 7

Which two methods can be used to verify firewall connectivity to Autofocus? (Choose two. )

Options:

A.

Check the WebUl Dashboard Autofocus widget

B.

Check for WildFire forwarding logs.

C.

Verify AutoFocus is enabled below Device Management tab

D.

Verify AutoFocus status using the CLI "test"command.

E.

Check the license

Buy Now
Questions 8

Which three options are supposed in HA Lite? (Choose three.)

Options:

A.

Configuration synchronization

B.

Virtual link

C.

active/passive deployment

D.

session synchronization

E.

synchronization of IPsec security associations

Buy Now
Questions 9

Which feature prevents the submission of login information into website froms?

Options:

A.

credential phishing prevention

B.

file blocking

C.

User-ID

D.

data filtering

Buy Now
Questions 10

An administrator is using Panorama and multiple Palo Alto NetworksNGFWs. After upgrading all devices to the latest PAN-OS® software, the administrator enables logs forwarding from the firewalls to panorama Pre-existing logs from the firewall are not appearing in Panorama.

Which action would enables the firewalls to sendtheir preexisting logs to Panorama?

Options:

A.

A CLI command will forward the pre-existing logs to Panorama.

B.

Use the import option to pull logs panorama.

C.

Use the ACC to consolidate pre-existing logs.

D.

The- log database will need to be exported from thefirewall and manually imported into Panorama.

Buy Now
Questions 11

A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN -OS® software would help in this case?

Options:

A.

content inspection

B.

application override

C.

Virtual Wire mode

D.

redistribution of user mappings

Buy Now
Exam Code: PCNSC
Exam Name: Palo Alto Networks Certified Network Security Consultant
Last Update: May 4, 2024
Questions: 75
PCNSC pdf

PCNSC PDF

$28  $80
PCNSC Engine

PCNSC Testing Engine

$33.25  $95
PCNSC PDF + Engine

PCNSC PDF + Testing Engine

$45.5  $130