Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Paloalto Networks PCNSC - Palo Alto Networks Certified Network Security Consultant

Page: 1 / 2
Total 60 questions

Your customer has asked you to set up tunnel monitoring on an IPsec VPN tunnel between two offices What three steps are needed to set up tunnel monitoring? (Choose three)

A.

Create a monitoring profile

B.

Add an IP address to each tunnel interface

C.

Restart each IPsec tunnel

D.

Restart each IKE gateway

E.

Enable tunnel monitoring on each IPsec tunnel

TAC has requested a PCAP on your Panorama lo see why the DNS app is having intermittent issues resolving FODN What is the appropriate CLI command1*

A.

tcp dump snaplen 53 filter "tcp 53"

B.

tcpdump snaplen 0 filter "port 53"

C.

tcp dump snap-en 0 filter "app dns"

D.

tcpdump snaplen 53 filter "port 53"

What happens when a packet from an existing session is received by a firewall that

A.

The firewall requests the sender to resend the packet

B.

The firewall drops the packet to prevent any L3 loops

C.

The firewall forwards the packet lo the peer firewall over the HA3 link

D.

The firewall lakes ownership of the session from the peer firewall

A customer has deployed a GlobalProtect portal and gateway as its remote-access VPN solution for its fleet of Windows 10 laptops

The customer wants to use Host information Profile (HIP) data collected at the GlobalProtect gateway throughout its enterprise as an additional means of policy enforcement

What additional licensing must the customer purchase?

A.

DNS Security on the perimeter firewall

B.

GlobalProtect license for each firewall that will use HIP data to enforce policy

C.

WildFire license

D.

GlobalProtect license for the gateway firewall

What is the purpose of the WildFire Analysis Profile in a security policy?

A.

To specify which files are sent to WildFire for analysis

B.

To configure the WildFire subscription settings

C.

To enable WildFire to analyze all network traffic

D.

To define the action to be taken on files analyzed by WildFire

Instead of disabling App-IDs regularly, a security policy rule is going to be configured to temporarily allow new App-IDs. In which two circumstances is it valid to disable App-IDs as part of content update-?

(Choose two)

A.

when planning to enable the App-IDs immediately

B.

when you want to immediately benefit from the latest threat prevention

C.

when disabling facebook-base to disable all other Facebook App-IDs

D.

when an organization operates a mission-critical network and has zero tolerance for downtime

In a multi-tenant environment, what feature allows you to assign different administrators to different tenants?

A.

Admin Roles

B.

Device Groups

C.

Access Domains

D.

Virtual Systems

Which command would you use to view the current sessions on a Palo Alto firewall?

A.

show session all

B.

show session info

C.

show session list

D.

show session current

Which CLI command should you use to verify whether all SFP SFP*, or QSFP modules are installed in a firewall?

A.

show system info

B.

show interface detail

C.

show system state filter sys.s'-p'-phy

D.

show system state filter sys.p*.phy

How can you ensure that a Palo Alto Networks firewall does not block traffic during a software update?

A.

Enable the Suspend Traffic During Upgrade option

B.

Schedule the upgrade during a maintenance window

C.

Configure session synchronization

D.

Use the High Availability feature