Font size
WorksheetsMock P C N S A Exam4
Total questions: 60
Worksheet time: 33mins
Your company is highly concerned with their intellectual property being accessed by unauthorized resources. There is a mature process to store and include metadata tags for all confidential documents.
Which Security profile can further ensure that these documents do not exit the corporate network?
File Blocking
Data Filtering
Anti-Spyware
URL Filtering
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.
Which Security policy rule will allow traffic to flow to the web server?
Untrust (any) to DMZ (10.1.1.100), web browsing - Allow
Untrust (any) to Untrust (1.1.1.100), web browsing - Allow
Untrust (any) to Untrust (10.1.1.100), web browsing - Allow
Untrust (any) to DMZ (1.1.1.100), web browsing - Allow
Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP
Addresses list?
destination address
source address
destination zone
source zone
Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content whose services are frequently used by attackers to distribute illegal or unethical material?
Palo Alto Networks C&G IP Addresses
Palo Alto Networks High Risk IP Addresses
Palo Alto Networks Known Malicious IP Addresses
Palo Alto Networks Bulletproof IP Addresses
An administrator is reviewing the Security policy rules shown in the screenshot below.
Which statement is correct about the information displayed?
Highlight Unused Rules is checked.
There are seven Security policy rules on this firewall.
The view Rulebase as Groups is checked.
Eleven rules use the “Infrastructure” tag.
In order to fulfill the corporate requirement to backup the configuration of Panorama and the Panorama-managed firewalls securely, which protocol should you select when adding a new scheduled config export?
HTTPS
SMB v3
SCP
FTP
What must be considered with regards to content updates deployed from Panorama?
Content update schedulers need to be configured separately per device group.
Panorama can only install up to five content versions of the same type for potential rollback scenarios.
A PAN-OS upgrade resets all scheduler configurations for content updates.
Panorama can only download one content update at a time for content updates of the same type.
Where in Panorama would Zone Protection profiles be configured?
Templates
Device Groups
Shared
Panorama tab
What is a valid Security Zone type in PAN-OS?
Management
Logical
Transparent
Tap
What are the requirements for using Palo Alto Networks EDL Hosting Service?
an additional paid subscription
any supported Palo Alto Networks firewall or Prisma Access firewall
a firewall device running with a minimum version of PAN-OS 10.1
an additional subscription free of charge
Which action can be set in a URL Filtering Security profile to provide users temporary access to all websites in a given category using a provided password?
continue
override
hold
exclude
An administrator is trying to implement an exception to an external dynamic list manually. Some entries are shown underlined in red.
What would cause this error?
Entries contain symbols.
Entries are wildcards.
Entries contain regular expressions.
Entries are duplicated.
Which path in PAN-OS 10.2 is used to schedule a content update to managed devices using Panorama?
Panorama > Device Deployment > Dynamic Updates > Schedules > Add
Panorama > Device Deployment > Content Updates > Schedules > Add
Panorama > Dynamic Updates > Device Deployment > Schedules > Add
Panorama > Content Updates > Device Deployment > Schedules > Add
In which threat profile object would you configure the DNS Security service?
Antivirus
Anti-Spyware
WildFire
URL Filtering
What can be achieved by disabling the Share Unused Address and Service Objects with Devices setting on Panorama?
Increase the per-firewall capacity for address and service objects
Reduce the configuration and session synchronization time between HA pairs
Increase the backup capacity for configuration backups per firewall
Reduce the number of objects pushed to a firewall
Which solution is a viable option to capture user identification when Active Directory is not in use?
Cloud identity Engine
Directory Sync Service
group mapping
Authentication Portal
Which action would an administrator take to ensure that a service object will be available only to the selected device group?
ensure that disable override is selected
uncheck the shared option
ensure that disable override is cleared
create the service object in the specific template
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic.
Untrust (Any) to DMZ (1.1.1.100), ssh - Allow
Untrust (Any) to Untrust (10.1.1.1), web-browsing - Allow
Untrust (Any) to Untrust (10.1.1.1), ssh - Allow
Untrust (Any) to DMZ (10.1.1.100, 10.1.1.101), ssh, web-browsing - Allow
Untrust (Any) to DMZ (1.1.1.100), web-browsing - Allow
Access to which feature requires a URL Filtering license?
PAN-DB database
External dynamic lists
DNS Security
Custom URL categories
During the App-ID update process, what should you click on to confirm whether an existing policy rule is affected by an App-ID update?
check now
review policies
test policy match
download
An administrator is creating a NAT policy.
Which combination of address and zone are used as match conditions? (Choose two.)
Pre-NAT address
Pre-NAT zone
Post-NAT address
Post-NAT zone
An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets.
What are two security policy actions the administrator can select? (Choose two.)
Reset server
Deny
Drop
Reset both
What are the two default behaviors for the intrazone-default policy? (Choose two.)
Allow
Log at Session End
Deny
Logging disabled
When creating an Admin Role profile, if no changes are made, which two administrative methods will you have full access to? (Choose two.)
web UI
XML API
command line
RESTAPI
According to best practices, how frequently should WildFire updates he made to perimeter firewalls?
every 10 minutes
every minute
every 5 minutes
in real time
An administrator wants to prevent hacking attacks through DNS queries to malicious domains.
Which two DNS policy actions can the administrator choose in the Anti-Spyware Security Profile? (Choose two.)
deny
block
sinkhole
override
What are three valid information sources that can be used when tagging users to dynamic user groups? (Choose three.)
firewall logs
custom API scripts
Security Information and Event Management Systems (SIEMS), such as Splunk
biometric scanning results from iOS devices
DNS Security service
An administrator would like to override the default deny action for a given application, and instead would like to block the traffic.
Which security policy action causes this?
Drop
Drop, send ICMP Unreachable
Reset both
Reset server
An administrator would like to protect against inbound threats such as buffer overflows and illegal code execution.
Which Security profile should be used?
Vulnerability protection
Anti-spyware
URL filtering
Antivirus
Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications.
Which policy achieves the desired results?
What can be achieved by selecting a policy target prior to pushing policy rules from Panorama?
You can specify the location as pre- or post-rules to push policy rules
You can specify the firewalls in a device group to which to push policy rules
Doing so provides audit information prior to making changes for selected policy rules
Doing so limits the templates that receive the policy rules
Which list of actions properly defines the order of steps needed to add a local database user account and create a new group to which this user will be assigned?
1. Navigate to Device > Local User Database > Users and click Add.
2. Enter a Name for the user.
3. Enter and Confirm a Password or Hash.
4. Enable the account and click OK.
5. Navigate to Device > Local User Database > User Groups and click Add.
6. Enter a Name for the group.
7. Add the user to the group and click OK.
1. Navigate to Device > Authentication Profile > Users and click Add.
2. Enter a Name for the user.
3. Enter and Confirm a Password or Hash.
4. Enable the account and click OK.
5. Navigate to Device > Local User Database > User Groups and click Add.
6. Enter a Name for the group.
7. Add the user to the group and click OK.
1. Navigate to Device > Users and click Add.
2. Enter a Name for the user.
3. Enter and Confirm a Password or Hash.
4. Enable the account and click OK.
5. Navigate to Device > User Groups and click Add.
6. Enter a Name for the group.
7. Add the user to the group and click OK.
1. Navigate to Device > Admins and click Add.
2. Enter a Name for the user.
3. Enter and Confirm a Password or Hash.
4. Enable the account and click OK.
5. Navigate to Device > User Groups and click Add.
6. Enter a Name for the group.
7. Add the user to the group and click OK.
An administrator wants to create a NAT policy to allow multiple source IP addresses to be translated to the same public IP address.
What is the most appropriate NAT policy to achieve this?
Static IP
Destination
Dynamic IP and Port
Dynamic IP
Which built-in IP address EDL would be useful for preventing traffic from IP addresses that are verified as unsafe based on WildFire analysis, Unit 42 research, and data gathered from telemetry?
Palo Alto Networks High-Risk IP Addresses
Palo Alto Networks Known Malicious IP Addresses
Palo Alto Networks C&C IP Addresses
Palo Alto Networks Bulletproof IP Addresses
You notice that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would you need to monitor and block to mitigate the malicious activity?
branch office traffic
north-south traffic
perimeter traffic
east-west traffic
View the diagram. What is the most restrictive, yet fully functional rule, to allow general Internet and SSH traffic into both the DMZ and Untrust/Internet zones from each of the IOT/Guest and Trust Zones?
An administrator needs to add capability to perform real time signature lookups to block or sinkhole all known malware domains.
Which type of single, unified engine will get this result?
Content ID
App-ID
Security Processing Engine
User-ID
Given the screenshot, what are two correct statements about the logged traffic? (Choose two.)
The web session was unsuccessfully decrypted.
The traffic was denied by security profile.
The traffic was denied by URL filtering.
The web session was decrypted.
Which two rule types allow the administrator to modify the destination zone? (Choose two.)
interzone
shadowed
intrazone
universal
An administrator needs to create a Security policy rule that matches DNS traffic within the LAN zone, and also needs to match DNS traffic within the DMZ zone.
The administrator does not want to allow traffic between the DMZ and LAN zones.
Which Security policy rule type should they use?
interzone
intrazone
default
universal
An address object of type IP Wildcard Mask can be referenced in which part of the configuration?
Security policy rule
ACC global fitter
NAT address pool
external dynamic list
You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact command-and-control server.
Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection?
Anti-Spyware Profile
Data Filtering Profile
Vulnerability Protection Profile
URL-Filtering Profile
An administrator would like to determine the default deny action for the application dns-over-https.
Which action would yield the information?
View the application details in beacon.paloaltonetworks.com
Check the action for the Security policy matching that traffic
Check the action for the decoder in the antivirus profile
View the application details in Objects > Applications
Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP
Addresses list?
destination address
source address
destination zone
source zone
Which statement best describes a common use of Policy Optimizer?
Policy Optimizer can be used on a schedule to automatically create a disabled Layer 7 App ID Security policy for every Layer 4 policy that exist. Admins can then manually enable policies they want to keep and delete ones they want to remove.
Policy Optimizer can display which Security policies have not been used in the last 90 days.
Policy Optimizer on aVM-50 firewall can display which Layer 7 App-ID Security policies have unused applications.
Policy Optimizer can add or change a Log Forwarding profile for each Security policy selected.
Selecting the option to revert firewall changes will replace what settings?
the candidate configuration with settings from the running configuration
dynamic update scheduler settings
the running configuration with settings from the candidate configuration
the device state with settings from another configuration
Prior to a maintenance-window activity, the administrator would like to make a backup of only the running configuration to an external location.
What command in Device > Setup > Operations would provide the most operationally efficient way to achieve this outcome?
export named configuration snapshot
save named configuration snapshot
export device state
save candidate config
An administrator would like to silently drop traffic from the internet to an ftp server.
Which Security policy action should the administrator select?
Drop
Deny
Block
Reset-server
An administrator is investigating a log entry for a session that is allowed and has the end reason of aged-out.
Which two fields could help in determining if this is normal? (Choose two.)
IP Protocol
Packets sent/received
Decrypted
Action
An administrator is updating Security policy to align with best practices.
Which Policy Optimizer feature is shown in the screenshot below?
Rules without App Controls
New App Viewer
Rule Usage – Unused
Unused Apps
An administrator is creating a Security policy rule and sees that the destination zone is grayed out.
While creating the rule, which option was selected to cause this?
Interzone
Source zone
Universal (default)
Intrazone
A network administrator created an intrazone Security policy rule on the firewall. The source zones were set to IT. Finance, and HR.
Which two types of traffic will the rule apply to? (Choose two)
traffic between zone IT and zone Finance
traffic between zone Finance and zone HR
traffic within zone IT
traffic within zone HR
What is a prerequisite before enabling an administrative account which relies on a local firewall user database?
Configure an authentication profile.
Configure an authentication sequence.
Isolate the management interface on a dedicated management VLAN.
Configure an authentication policy.
An administrator is trying to enforce policy on some (but not all) of the entries in an external dynamic list.
What is the maximum number of entries that they can be excluded?
50
100
200
1,000
How many levels can there be in a device-group hierarchy, below the shared level?
2
3
4
5
An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. The interzone-default was never changed from its default configuration.
Why doesn't the administrator see the traffic?
Logging on the interzone-default policy is disabled by default.
Traffic is being denied on the interzone-default policy.
Logging on the interzone-default policy is disabled.
The Log Forwarding profile is not configured on the policy.
An administrator manages a network with 300 addresses that require translation. The administrator configured NAT with an address pool of 240 addresses and found that connections from addresses that needed new translations were being dropped.
Which type of NAT was configured?
Dynamic IP
Static IP
Dynamic IP and Port
Destination NAT
Why should a company have a File Blocking profile that is attached to a Security policy?
To block uploading and downloading of any type of files
To block uploading and downloading of specific types of files
To detonate files in a sandbox environment
To analyze file types
After making multiple changes to the candidate configuration of a firewall, the administrator would like to start over with a candidate configuration that matches the running configuration.
Which command in Device > Setup > Operations would provide the most operationally efficient way to accomplish this?
Revert to running configuration
Load named configuration snapshot
Revert to last saved configuration
Import named config snapshot
If using group mapping with Active Directory Universal Groups, what must you do when configuring the User ID?
Configure a Primary Employee ID number for user-based Security policies.
Create a RADIUS Server profile to connect to the domain controllers using LDAPS on port 636 or 389.
Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL.
Configure a frequency schedule to clear group mapping cache.
