Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Paloalto Networks Palo Alto Networks Certified Network Security Consultant PCNSC Questions and answers with ValidTests

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which firewall interface type allows you to non-disruptively monitor traffic coming from a port operating in promiscuous mode?

Options:

A.

V-Wire

B.

Layer 3

C.

Layer

D.

TAP

Expert Solution
Questions # 2:

When creating a custom application signature, which field allows you to specify the layer 7 protocol details to match?

Options:

A.

Application ID

B.

Signature ID

C.

Pattern Match

D.

Protocol Decoder

Expert Solution
Questions # 3:

Which of the following Palo Alto Networks features can help reduce the attack surface by limiting the number of applications allowed through the firewall?

Options:

A.

URL Filtering

B.

App-ID

C.

User-ID

D.

Content-ID

Expert Solution
Questions # 4:

Instead of disabling App-IDs regularly, a security policy rule is going to be configured to temporarily allow new App-IDs. In which two circumstances is it valid to disable App-IDs as part of content update-?

(Choose two)

Options:

A.

when planning to enable the App-IDs immediately

B.

when you want to immediately benefit from the latest threat prevention

C.

when disabling facebook-base to disable all other Facebook App-IDs

D.

when an organization operates a mission-critical network and has zero tolerance for downtime

Expert Solution
Questions # 5:

Which three steps must an administrator perform to load only address objects from a PAN-OS saved configuration file into a VM-3C0 firewall that is in production? (Choose three)

Options:

A.

use the device configuration import in Panorama

B.

Import named configuration snapshot through the web interface

C.

load the config in the web interface and commit

D.

enter the configuration mode from the CLI

E.

use load config partial command

Expert Solution
Questions # 6:

SSL Forward Proxy decryption is enabled on (he firewall When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates

Which two options will satisfy this requirement? (Choose two.)

Options:

A.

create a Decryption Profile with the Block sessions with expired certificates option enabled

B.

create a self-signed Forward Untrust enabled certificate

C.

create a PKI signed Forward Unlrust enabled certificate

D.

remove the Forward Untrust option from the Forward Trust certificate

Expert Solution
Questions # 7:

What is the default port used by the Terminal Services agent to communicate with a firewall?

Options:

A.

5007

B.

5009

C.

443

D.

636

Expert Solution
Questions # 8:

Which touting configuration should you recommend lo a customer who wishes lo actively use multiple pathways to the same destination?

Options:

A.

OSPF

B.

ECMP

C.

BGP

D.

RlPv2

Expert Solution
Questions # 9:

Which interface deployments support the Aggregate Ethernet Active configuration? (Choose three.)

Options:

A.

LACP in TAP

B.

LACP in Layer 3

C.

LACP in Layer 2

D.

LACP in Virtual Wire

E.

LLDP in Layer 3

Expert Solution
Questions # 10:

Which log type would you consult to diagnose why a specific URL is being blocked?

Options:

A.

Threat log

B.

URL Filtering log

C.

Traffic log

D.

Data Filtering log

Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions