wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Mock P C N S A Exam4

Total questions: 60

Worksheet time: 33mins

Name
Class
Date
1.

Your company is highly concerned with their intellectual property being accessed by unauthorized resources. There is a mature process to store and include metadata tags for all confidential documents.

Which Security profile can further ensure that these documents do not exit the corporate network?

a)

File Blocking

b)

Data Filtering

c)

Anti-Spyware

d)

URL Filtering

2.

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.

Which Security policy rule will allow traffic to flow to the web server?

a)

Untrust (any) to DMZ (10.1.1.100), web browsing - Allow

b)

Untrust (any) to Untrust (1.1.1.100), web browsing - Allow

c)

Untrust (any) to Untrust (10.1.1.100), web browsing - Allow

d)

Untrust (any) to DMZ (1.1.1.100), web browsing - Allow

3.

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP

Addresses list?

a)

destination address

b)

source address

c)

destination zone

d)

source zone

4.

Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content whose services are frequently used by attackers to distribute illegal or unethical material?

a)

Palo Alto Networks C&G IP Addresses

b)

Palo Alto Networks High Risk IP Addresses

c)

Palo Alto Networks Known Malicious IP Addresses

d)

Palo Alto Networks Bulletproof IP Addresses

5.

An administrator is reviewing the Security policy rules shown in the screenshot below.

Which statement is correct about the information displayed?

a)

Highlight Unused Rules is checked.

b)

There are seven Security policy rules on this firewall.

c)

The view Rulebase as Groups is checked.

d)

Eleven rules use the “Infrastructure” tag.

6.

In order to fulfill the corporate requirement to backup the configuration of Panorama and the Panorama-managed firewalls securely, which protocol should you select when adding a new scheduled config export?

a)

HTTPS

b)

SMB v3

c)

SCP

d)

FTP

7.

What must be considered with regards to content updates deployed from Panorama?

a)

Content update schedulers need to be configured separately per device group.

b)

Panorama can only install up to five content versions of the same type for potential rollback scenarios.

c)

A PAN-OS upgrade resets all scheduler configurations for content updates.

d)

Panorama can only download one content update at a time for content updates of the same type.

8.

Where in Panorama would Zone Protection profiles be configured?

a)

Templates

b)

Device Groups

c)

Shared

d)

Panorama tab

9.

What is a valid Security Zone type in PAN-OS?

a)

Management

b)

Logical

c)

Transparent

d)

Tap

10.

What are the requirements for using Palo Alto Networks EDL Hosting Service?

a)

an additional paid subscription

b)

any supported Palo Alto Networks firewall or Prisma Access firewall

c)

a firewall device running with a minimum version of PAN-OS 10.1

d)

an additional subscription free of charge

11.

Which action can be set in a URL Filtering Security profile to provide users temporary access to all websites in a given category using a provided password?

a)

continue

b)

override

c)

hold

d)

exclude

12.

An administrator is trying to implement an exception to an external dynamic list manually. Some entries are shown underlined in red.

What would cause this error?

a)

Entries contain symbols.

b)

Entries are wildcards.

c)

Entries contain regular expressions.

d)

Entries are duplicated.

13.

Which path in PAN-OS 10.2 is used to schedule a content update to managed devices using Panorama?

a)

Panorama > Device Deployment > Dynamic Updates > Schedules > Add

b)

Panorama > Device Deployment > Content Updates > Schedules > Add

c)

Panorama > Dynamic Updates > Device Deployment > Schedules > Add

d)

Panorama > Content Updates > Device Deployment > Schedules > Add

14.

In which threat profile object would you configure the DNS Security service?

a)

Antivirus

b)

Anti-Spyware

c)

WildFire

d)

URL Filtering

15.

What can be achieved by disabling the Share Unused Address and Service Objects with Devices setting on Panorama?

a)

Increase the per-firewall capacity for address and service objects

b)

Reduce the configuration and session synchronization time between HA pairs

c)

Increase the backup capacity for configuration backups per firewall

d)

Reduce the number of objects pushed to a firewall

16.

Which solution is a viable option to capture user identification when Active Directory is not in use?

a)

Cloud identity Engine

b)

Directory Sync Service

c)

group mapping

d)

Authentication Portal

17.

Which action would an administrator take to ensure that a service object will be available only to the selected device group?

a)

ensure that disable override is selected

b)

uncheck the shared option

c)

ensure that disable override is cleared

d)

create the service object in the specific template

18.

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic.

a)

Untrust (Any) to DMZ (1.1.1.100), ssh - Allow

b)

Untrust (Any) to Untrust (10.1.1.1), web-browsing - Allow

c)

Untrust (Any) to Untrust (10.1.1.1), ssh - Allow

d)

Untrust (Any) to DMZ (10.1.1.100, 10.1.1.101), ssh, web-browsing - Allow

e)

Untrust (Any) to DMZ (1.1.1.100), web-browsing - Allow

19.

Access to which feature requires a URL Filtering license?

a)

PAN-DB database

b)

External dynamic lists

c)

DNS Security

d)

Custom URL categories

20.

During the App-ID update process, what should you click on to confirm whether an existing policy rule is affected by an App-ID update?

a)

check now

b)

review policies

c)

test policy match

d)

download

21.

An administrator is creating a NAT policy.

Which combination of address and zone are used as match conditions? (Choose two.)

a)

Pre-NAT address

b)

Pre-NAT zone

c)

Post-NAT address

d)

Post-NAT zone

22.

An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets.

What are two security policy actions the administrator can select? (Choose two.)

a)

Reset server

b)

Deny

c)

Drop

d)

Reset both

23.

What are the two default behaviors for the intrazone-default policy? (Choose two.)

a)

Allow

b)

Log at Session End

c)

Deny

d)

Logging disabled

24.

When creating an Admin Role profile, if no changes are made, which two administrative methods will you have full access to? (Choose two.)

a)

web UI

b)

XML API

c)

command line

d)

RESTAPI

25.

According to best practices, how frequently should WildFire updates he made to perimeter firewalls?

a)

every 10 minutes

b)

every minute

c)

every 5 minutes

d)

in real time

26.

An administrator wants to prevent hacking attacks through DNS queries to malicious domains.

Which two DNS policy actions can the administrator choose in the Anti-Spyware Security Profile? (Choose two.)

a)

deny

b)

block

c)

sinkhole

d)

override

27.

What are three valid information sources that can be used when tagging users to dynamic user groups? (Choose three.)

a)

firewall logs

b)

custom API scripts

c)

Security Information and Event Management Systems (SIEMS), such as Splunk

d)

biometric scanning results from iOS devices

e)

DNS Security service

28.

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic.

Which security policy action causes this?

a)

Drop

b)

Drop, send ICMP Unreachable

c)

Reset both

d)

Reset server

29.

An administrator would like to protect against inbound threats such as buffer overflows and illegal code execution.

Which Security profile should be used?

a)

Vulnerability protection

b)

Anti-spyware

c)

URL filtering

d)

Antivirus

30.

Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications.

Which policy achieves the desired results?

a)

b)

c)

d)

31.

What can be achieved by selecting a policy target prior to pushing policy rules from Panorama?

a)

You can specify the location as pre- or post-rules to push policy rules

b)

You can specify the firewalls in a device group to which to push policy rules

c)

Doing so provides audit information prior to making changes for selected policy rules

d)

Doing so limits the templates that receive the policy rules

32.

Which list of actions properly defines the order of steps needed to add a local database user account and create a new group to which this user will be assigned?

a)

1. Navigate to Device > Local User Database > Users and click Add.

2. Enter a Name for the user.

3. Enter and Confirm a Password or Hash.

4. Enable the account and click OK.

5. Navigate to Device > Local User Database > User Groups and click Add.

6. Enter a Name for the group.

7. Add the user to the group and click OK.

b)

1. Navigate to Device > Authentication Profile > Users and click Add.

2. Enter a Name for the user.

3. Enter and Confirm a Password or Hash.

4. Enable the account and click OK.

5. Navigate to Device > Local User Database > User Groups and click Add.

6. Enter a Name for the group.

7. Add the user to the group and click OK.

c)

1. Navigate to Device > Users and click Add.

2. Enter a Name for the user.

3. Enter and Confirm a Password or Hash.

4. Enable the account and click OK.

5. Navigate to Device > User Groups and click Add.

6. Enter a Name for the group.

7. Add the user to the group and click OK.

d)

1. Navigate to Device > Admins and click Add.

2. Enter a Name for the user.

3. Enter and Confirm a Password or Hash.

4. Enable the account and click OK.

5. Navigate to Device > User Groups and click Add.

6. Enter a Name for the group.

7. Add the user to the group and click OK.

33.

An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address.

What is the most appropriate NAT policy to achieve this?

a)

Static IP

b)

Destination

c)

Dynamic IP and Port

d)

Dynamic IP

34.

Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis, Unit 42 research, and data gathered from telemetry?

a)

Palo Alto Networks High-Risk IP Addresses

b)

Palo Alto Networks Known Malicious IP Addresses

c)

Palo Alto Networks C&C IP Addresses

d)

Palo Alto Networks Bulletproof IP Addresses

35.

You notice that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would you need to monitor and block to mitigate the malicious activity?

a)

branch office traffic

b)

north-south traffic

c)

perimeter traffic

d)

east-west traffic

36.

View the diagram. What is the most restrictive, yet fully functional rule, to allow general Internet and SSH traffic into both the DMZ and Untrust/Internet zones from each of the IOT/Guest and Trust Zones?

a)

b)

c)

d)

37.

An administrator needs to add capability to perform real time signature lookups to block or sinkhole all known malware domains.

Which type of single, unified engine will get this result?

a)

Content ID

b)

App-ID

c)

Security Processing Engine

d)

User-ID

38.

Given the screenshot, what are two correct statements about the logged traffic? (Choose two.)

a)

The web session was unsuccessfully decrypted.

b)

The traffic was denied by security profile.

c)

The traffic was denied by URL filtering.

d)

The web session was decrypted.

39.

Which two rule types allow the administrator to modify the destination zone? (Choose two.)

a)

interzone

b)

shadowed

c)

intrazone

d)

universal

40.

An administrator needs to create a Security policy rule that matches DNS traffic within the LAN zone, and also needs to match DNS traffic within the DMZ zone.

The administrator does not want to allow traffic between the DMZ and LAN zones.

Which Security policy rule type should they use?

a)

interzone

b)

intrazone

c)

default

d)

universal

41.

An address object of type IP Wildcard Mask can be referenced in which part of the configuration?

a)

Security policy rule

b)

ACC global fitter

c)

NAT address pool

d)

external dynamic list

42.

You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact command-and-control server.

Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection?

a)

Anti-Spyware Profile

b)

Data Filtering Profile

c)

Vulnerability Protection Profile

d)

URL-Filtering Profile

43.

An administrator would like to determine the default deny action for the application dns-over-https.

Which action would yield the information?

a)

View the application details in beacon.paloaltonetworks.com

b)

Check the action for the Security policy matching that traffic

c)

Check the action for the decoder in the antivirus profile

d)

View the application details in Objects > Applications

44.

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP

Addresses list?

a)

destination address

b)

source address

c)

destination zone

d)

source zone

45.

Which statement best describes a common use of Policy Optimizer?

a)

Policy Optimizer can be used on a schedule to automatically create a disabled Layer 7 App ID Security policy for every Layer 4 policy that exist. Admins can then manually enable policies they want to keep and delete ones they want to remove.

b)

Policy Optimizer can display which Security policies have not been used in the last 90 days.

c)

Policy Optimizer on aVM-50 firewall can display which Layer 7 App-ID Security policies have unused applications.

d)

Policy Optimizer can add or change a Log Forwarding profile for each Security policy selected.

46.

Selecting the option to revert firewall changes will replace what settings?

a)

the candidate configuration with settings from the running configuration

b)

dynamic update scheduler settings

c)

the running configuration with settings from the candidate configuration

d)

the device state with settings from another configuration

47.

Prior to a maintenance-window activity, the administrator would like to make a backup of only the running configuration to an external location.

What command in Device > Setup > Operations would provide the most operationally efficient way to achieve this outcome?

a)

export named configuration snapshot

b)

save named configuration snapshot

c)

export device state

d)

save candidate config

48.

An administrator would like to silently drop traffic from the internet to an ftp server.

Which Security policy action should the administrator select?

a)

Drop

b)

Deny

c)

Block

d)

Reset-server

49.

An administrator is investigating a log entry for a session that is allowed and has the end reason of aged-out.

Which two fields could help in determining if this is normal? (Choose two.)

a)

IP Protocol

b)

Packets sent/received

c)

Decrypted

d)

Action

50.

An administrator is updating Security policy to align with best practices.

Which Policy Optimizer feature is shown in the screenshot below?

a)

Rules without App Controls

b)

New App Viewer

c)

Rule Usage – Unused

d)

Unused Apps

51.

An administrator is creating a Security policy rule and sees that the destination zone is grayed out.

While creating the rule, which option was selected to cause this?

a)

Interzone

b)

Source zone

c)

Universal (default)

d)

Intrazone

52.

A network administrator created an intrazone Security policy rule on the firewall. The source zones were set to IT. Finance, and HR.

Which two types of traffic will the rule apply to? (Choose two)

a)

traffic between zone IT and zone Finance

b)

traffic between zone Finance and zone HR

c)

traffic within zone IT

d)

traffic within zone HR

53.

What is a prerequisite before enabling an administrative account which relies on a local firewall user database?

a)

Configure an authentication profile.

b)

Configure an authentication sequence.

c)

Isolate the management interface on a dedicated management VLAN.

d)

Configure an authentication policy.

54.

An administrator is trying to enforce policy on some (but not all) of the entries in an external dynamic list.

What is the maximum number of entries that they can be excluded?

a)

50

b)

100

c)

200

d)

1,000

55.

How many levels can there be in a device-group hierarchy, below the shared level?

a)

2

b)

3

c)

4

d)

5

56.

An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. The interzone-default was never changed from its default configuration.

Why doesn't the administrator see the traffic?

a)

Logging on the interzone-default policy is disabled by default.

b)

Traffic is being denied on the interzone-default policy.

c)

Logging on the interzone-default policy is disabled.

d)

The Log Forwarding profile is not configured on the policy.

57.

An administrator manages a network with 300 addresses that require translation. The administrator configured NAT with an address pool of 240 addresses and found that connections from addresses that needed new translations were being dropped.

Which type of NAT was configured?

a)

Dynamic IP

b)

Static IP

c)

Dynamic IP and Port

d)

Destination NAT

58.

Why should a company have a File Blocking profile that is attached to a Security policy?

a)

To block uploading and downloading of any type of files

b)

To block uploading and downloading of specific types of files

c)

To detonate files in a sandbox environment

d)

To analyze file types

59.

After making multiple changes to the candidate configuration of a firewall, the administrator would like to start over with a candidate configuration that matches the running configuration.

Which command in Device > Setup > Operations would provide the most operationally efficient way to accomplish this?

a)

Revert to running configuration

b)

Load named configuration snapshot

c)

Revert to last saved configuration

d)

Import named config snapshot

60.

If using group mapping with Active Directory Universal Groups, what must you do when configuring the User ID?

a)

Configure a Primary Employee ID number for user-based Security policies.

b)

Create a RADIUS Server profile to connect to the domain controllers using LDAPS on port 636 or 389.

c)

Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL.

d)

Configure a frequency schedule to clear group mapping cache.