Pass Authentic Palo Alto Networks PCNSA with Free Practice Tests and Exam Dumps
New PCNSA Exam Questions Real Palo Alto Networks Dumps
NEW QUESTION # 155
Given the screenshot what two types of route is the administrator configuring? (Choose two )
- A. BGP
- B. default route
- C. OSPF
- D. static route
Answer: B
NEW QUESTION # 156
An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address. What is the most appropriate NAT policy to achieve this?
- A. Dynamic IP and Port
- B. Static IP
- C. Destination
- D. Dynamic IP
Answer: A
NEW QUESTION # 157
What is the minimum timeframe that can be set on the firewall to check for new WildFire signatures?
- A. every 30 minutes
- B. once every 24 hours
- C. every 1 minute
- D. every 5 minutes
Answer: D
Explanation:
Explanation
Firewalls with an active WildFire license can retrieve the latest WildFire signatures every five minutes. If you do not have a WildFire subscription, signatures are made available within 24-48 hours as part of the antivirus update for firewalls with an active Threat Prevention license.
https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-concepts/wildfire-sign
NEW QUESTION # 158
An administrator wants to prevent access to media content websites that are risky. Which two URL categories should be combined in a custom URL category to accomplish this goal? (Choose two.)
- A. high-risk
- B. known-risk
- C. recreation-and-hobbies
- D. streaming-media
Answer: A,D
Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/content-inspection- features/url-filtering-multi-category.html
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/content-inspection- features/url-filtering-security-categories.html
NEW QUESTION # 159
Based on the screenshot what is the purpose of the group in User labelled ''it"?
- A. Allows "any" users to access servers in the DMZ zone
- B. Allows users to access IT applications on all ports
- C. Allows users in group "it" to access IT applications
- D. Allows users in group "DMZ" lo access IT applications
Answer: C
NEW QUESTION # 160
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?
- A. Policies> Security> Rule Usage> Port-based Rules
- B. Policies> Security> Rule Usage> Unused Apps
- C. Policies> Security> Rule Usage> Port only specified
- D. Policies> Security> Rule Usage> No App Specified
Answer: D
Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/security-policy-rule- optimization/migrate-port-based-to-app-id-based-security-policy-rules
NEW QUESTION # 161
Match the Palo Alto Networks Security Operating Platform architecture to its description.
Answer:
Explanation:
NEW QUESTION # 162
What are two differences between an implicit dependency and an explicit dependency in App-ID? (Choose two.)
- A. An explicit dependency requires the dependent application to be added in the security policy
- B. An explicit dependency does not require the dependent application to be added in the security policy
- C. An implicit dependency does not require the dependent application to be added in the security policy
- D. An implicit dependency requires the dependent application to be added in the security policy
Answer: A,C
NEW QUESTION # 163
Which administrator type utilizes predefined roles for a local administrator account?
- A. Dynamic
- B. Device administrator
- C. Role-based
- D. Superuser
Answer: A
Explanation:
References:
NEW QUESTION # 164
Match the cyber-attack lifecycle stage to its correct description.
Answer:
Explanation:
NEW QUESTION # 165
Which type of address object is "10 5 1 1/0 127 248 2"?
- A. IP netmask
- B. IP subnet
- C. IP wildcard mask
- D. IP range
Answer: C
NEW QUESTION # 166
Which interface type requires no routing or switching but applies Security or NAT policy rules before passing allowed traffic?
- A. Layer 2
- B. Tap
- C. Virtual Wire
- D. Layer 3
Answer: D
NEW QUESTION # 167
Match each feature to the DoS Protection Policy or the DoS Protection Profile.
Answer:
Explanation:
NEW QUESTION # 168
Access to which feature requires the PAN-OS Filtering license?
- A. DNS Security
- B. Custom URL categories
- C. PAN-DB database
- D. URL external dynamic lists
Answer: C
NEW QUESTION # 169
Which action results in the firewall blocking network traffic with out notifying the sender?
- A. Drop
- B. Reset Server
- C. Reset Client
- D. Deny
Answer: D
NEW QUESTION # 170
The PowerBall Lottery has reached an unusually high value this week. Your company has decided to raise morale by allowing employees to access the PowerBall Lottery website (www.powerball.com) for just this week. However, the company does not want employees to access any other websites also listed in the URL filtering "gambling" category.
Which method allows the employees to access the PowerBall Lottery website but without unblocking access to the "gambling" URL category?
- A. Create a custom URL category, add *.powerball.com to it and allow it in the Security Profile.
- B. Manually remove powerball.com from the gambling URL category.
- C. Add just the URL www.powerball.com to a Security policy allow rule.
- D. Add *.powerball.com to the URL Filtering allow list.
Answer: A,D
NEW QUESTION # 171
......
PCNSA Exam Info and Free Practice Test Professional Quiz Study Materials: https://torrentpdf.practicedump.com/PCNSA-exam-questions.html