Pass Authentic Palo Alto Networks PCNSA with Free Practice Tests and Exam Dumps [Q155-Q171]

Share

Pass Authentic Palo Alto Networks PCNSA with Free Practice Tests and Exam Dumps

New PCNSA  Exam Questions Real Palo Alto Networks Dumps

NEW QUESTION # 155
Given the screenshot what two types of route is the administrator configuring? (Choose two )

  • A. BGP
  • B. default route
  • C. OSPF
  • D. static route

Answer: B


NEW QUESTION # 156
An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address. What is the most appropriate NAT policy to achieve this?

  • A. Dynamic IP and Port
  • B. Static IP
  • C. Destination
  • D. Dynamic IP

Answer: A


NEW QUESTION # 157
What is the minimum timeframe that can be set on the firewall to check for new WildFire signatures?

  • A. every 30 minutes
  • B. once every 24 hours
  • C. every 1 minute
  • D. every 5 minutes

Answer: D

Explanation:
Explanation
Firewalls with an active WildFire license can retrieve the latest WildFire signatures every five minutes. If you do not have a WildFire subscription, signatures are made available within 24-48 hours as part of the antivirus update for firewalls with an active Threat Prevention license.
https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-concepts/wildfire-sign


NEW QUESTION # 158
An administrator wants to prevent access to media content websites that are risky. Which two URL categories should be combined in a custom URL category to accomplish this goal? (Choose two.)

  • A. high-risk
  • B. known-risk
  • C. recreation-and-hobbies
  • D. streaming-media

Answer: A,D

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/content-inspection- features/url-filtering-multi-category.html
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/content-inspection- features/url-filtering-security-categories.html


NEW QUESTION # 159
Based on the screenshot what is the purpose of the group in User labelled ''it"?

  • A. Allows "any" users to access servers in the DMZ zone
  • B. Allows users to access IT applications on all ports
  • C. Allows users in group "it" to access IT applications
  • D. Allows users in group "DMZ" lo access IT applications

Answer: C


NEW QUESTION # 160
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?

  • A. Policies> Security> Rule Usage> Port-based Rules
  • B. Policies> Security> Rule Usage> Unused Apps
  • C. Policies> Security> Rule Usage> Port only specified
  • D. Policies> Security> Rule Usage> No App Specified

Answer: D

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/security-policy-rule- optimization/migrate-port-based-to-app-id-based-security-policy-rules


NEW QUESTION # 161
Match the Palo Alto Networks Security Operating Platform architecture to its description.

Answer:

Explanation:


NEW QUESTION # 162
What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.)

  • A. An explicit dependency requires the dependent application to be added in the security policy
  • B. An explicit dependency does not require the dependent application to be added in the security policy
  • C. An implicit dependency does not require the dependent application to be added in the security policy
  • D. An implicit dependency requires the dependent application to be added in the security policy

Answer: A,C


NEW QUESTION # 163
Which administrator type utilizes predefined roles for a local administrator account?

  • A. Dynamic
  • B. Device administrator
  • C. Role-based
  • D. Superuser

Answer: A

Explanation:
References:


NEW QUESTION # 164
Match the cyber-attack lifecycle stage to its correct description.

Answer:

Explanation:


NEW QUESTION # 165
Which type of address object is "10 5 1 1/0 127 248 2"?

  • A. IP netmask
  • B. IP subnet
  • C. IP wildcard mask
  • D. IP range

Answer: C


NEW QUESTION # 166
Which interface type requires no routing or switching but applies Security or NAT policy rules before passing allowed traffic?

  • A. Layer 2
  • B. Tap
  • C. Virtual Wire
  • D. Layer 3

Answer: D


NEW QUESTION # 167
Match each feature to the DoS Protection Policy or the DoS Protection Profile.

Answer:

Explanation:


NEW QUESTION # 168
Access to which feature requires the PAN-OS Filtering license?

  • A. DNS Security
  • B. Custom URL categories
  • C. PAN-DB database
  • D. URL external dynamic lists

Answer: C


NEW QUESTION # 169
Which action results in the firewall blocking network traffic with out notifying the sender?

  • A. Drop
  • B. Reset Server
  • C. Reset Client
  • D. Deny

Answer: D


NEW QUESTION # 170
The PowerBall Lottery has reached an unusually high value this week. Your company has decided to raise morale by allowing employees to access the PowerBall Lottery website (www.powerball.com) for just this week. However, the company does not want employees to access any other websites also listed in the URL filtering "gambling" category.
Which method allows the employees to access the PowerBall Lottery website but without unblocking access to the "gambling" URL category?

  • A. Create a custom URL category, add *.powerball.com to it and allow it in the Security Profile.
  • B. Manually remove powerball.com from the gambling URL category.
  • C. Add just the URL www.powerball.com to a Security policy allow rule.
  • D. Add *.powerball.com to the URL Filtering allow list.

Answer: A,D


NEW QUESTION # 171
......

PCNSA Exam Info and Free Practice Test Professional Quiz Study Materials: https://torrentpdf.practicedump.com/PCNSA-exam-questions.html