Up To Date Palo Alto Networks Certified Security Engineer (PCNSE)PAN-OS 8.0 PCNSE Test

Your success in Paloalto-Networks PCNSE is our sole target and we develop all our PCNSE braindumps in a way that facilitates the attainment of this target. Not only is our PCNSE study material the best you can find, it is also the most detailed and the most updated. PCNSE Practice Exams for Paloalto-Networks PCNSE are written to the highest standards of technical accuracy.

Free demo questions for Paloalto-Networks PCNSE Exam Dumps Below:

Page: 1 / 21
Total 255 questions Full Exam Access
Question 1
Which logs enable a firewall administrator to determine whether a session was decrypted?
My answer: -
Reference answer: B
Reference analysis:

None

Question 2
YouTube videos are consuming too much bandwidth on the network, causing delays in mission- critical traffic. The administrator wants to throttle YouTube traffic. The following interfaces and zones are in use on the firewall:
* ethernet1/1, Zone: Untrust (Internet-facing)
* ethernet1/2, Zone: Trust (client-facing)
A QoS profile has been created, and QoS has been enabled on both interfaces. A QoS rule exists to put the YouTube application into QoS class 6. Interface Ethernet1/1 has a QoS profile called Outbound, and interface Ethernet1/2 has a QoS profile called Inbound.
Which setting for class 6 with throttle YouTube traffic?
My answer: -
Reference answer: D
Reference analysis:

None

Question 3
Which Panorama feature allows for logs generated by Panorama to be forwarded to an external Security Information and Event Management(SIEM) system?
My answer: -
Reference answer: A
Reference analysis:

https://www.paloaltonetworks.com/documentation/61/panorama/panorama_admiHYPERLINK "https://www.paloaltonetworks.com/documentation/61/panorama/panorama_adminguide/manag e-log-collection/enable-log-forwarding-from-panorama-to-external-destinations"nguidHYPERLINK "https://www.paloaltonetworks.com/documentation/61/panorama/panorama_adminguide/manag e-log-collection/enable-log-forwarding-from-panorama-to-external-destinations"e/manage-log- collection/enable-log-forwarding-from-panorama-to-external-destinaHYPERLINK "https://www.paloaltonetworks.com/documentation/61/panorama/panorama_adminguide/manag e-log-collection/enable-log-forwarding-from-panorama-to-external-destinations"tions

Question 4
How are IPV6 DNS queries configured to user interface ethernet1/3?
My answer: -
Reference answer: D
Reference analysis:

None

Question 5
Which Captive Portal mode must be configured to support MFA authentication?
My answer: -
Reference answer: B
Reference analysis:

Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/authentication/configure-multi-factor-authentication

Question 6
Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)
My answer: -
Reference answer: AD
Reference analysis:

None

Question 7
An administrator is defining protection settings on the Palo Alto Networks NGFW to guard against resource exhaustion. When platform utilization is considered, which steps must the administrator take to configure and apply packet buffer protection?
My answer: -
Reference answer: A
Reference analysis:

None

Question 8
An administrator needs to optimize traffic to prefer business-critical applications over non-critical applications. QoS natively integrates with which feature to provide service quality?
My answer: -
Reference answer: D
Reference analysis:

Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/quality-of-service/qos-for-applications-and-users

Question 9
Which two methods can be configured to validate the revocation status of a certificate? (Choose two.)
My answer: -
Reference answer: AC
Reference analysis:

None

Question 10
Which three log-forwarding destinations require a server profile to be configured? (Choose three)
My answer: -
Reference answer: ABF
Reference analysis:

None

Question 11
Which administrative authentication method supports authorization by an external service?
My answer: -
Reference answer: C
Reference analysis:

None

Question 12
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)
My answer: -
Reference answer: CD
Reference analysis:

None

Question 13
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using link aggregation. Which two formats are correct for naming aggregate interfaces? (Choose two.)
My answer: -
Reference answer: AC
Reference analysis:

None

Question 14
A company has a web server behind a Palo Alto Networks next-generation firewall that it wants to make accessible to the public at 1.1.1.1. The company has decided to configure a destination NAT Policy rule.
Given the following zone information:
• DMZ zone: DMZ-L3
• Public zone: Untrust-L3
• Guest zone: Guest-L3
• Web server zone: Trust-L3
• Public IP address (Untrust-L3): 1.1.1.1
• Private IP address (Trust-L3): 192.168.1.50
What should be configured as the destination zone on the Original Packet tab of NAT Policy rule?
My answer: -
Reference answer: A
Reference analysis:

None

Question 15
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.
Which configuration will enable this HA scenario?
My answer: -
Reference answer: A
Reference analysis:

None

Question 16
Which virtual router feature determines if a specific destination IP address is reachable?
My answer: -
Reference answer: C
Reference analysis:

Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/pbf

Question 17
How does an administrator schedule an Applications and Threats dynamic update while delaying installation of the update for a certain amount of time?
My answer: -
Reference answer: A
Reference analysis:

None

Question 18
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermore, SSL is used to tunnel malicious traffic to command-and-control servers on the internet and SSL Forward Proxy Decryption is not enabled.
Which component once enabled on a perirneter firewall will allow the identification of existing infected hosts in an environment?
My answer: -
Reference answer: A
Reference analysis:

None

Question 19
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination IP address and post.
Which option when enabled with the correction threshold would mitigate this attack without dropping legitirnate traffic to other hosts insides the network?
My answer: -
Reference answer: D
Reference analysis:

None

Question 20
A client is deploying a pair of PA-5000 series firewalls using High Availability (HA) in Active/Passive mode. Which statement is true about this deployment?
My answer: -
Reference answer: D
Reference analysis:

None

Question 21
Which URL Filtering Security Profile action togs the URL Filtering category to the URL Filtering log?
My answer: -
Reference answer: B
Reference analysis:

None

Question 22
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's
firewall.
PCNSE dumps exhibit
Which interface configuration will accept specific VLAN IDs?
Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)
My answer: -
Reference answer: BD
Reference analysis:

None

Question 23
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
My answer: -
Reference answer: ADF
Reference analysis:

None

Question 24
The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?
My answer: -
Reference answer: A
Reference analysis:

None

Question 25
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?
My answer: -
Reference answer: A
Reference analysis:

None

Page: 1 / 21
Total 255 questions Full Exam Access