Font size
WorksheetsMock P C N S E Exam 5
Total questions: 75
Worksheet time: 3hrs 30mins
An administrator connects four new remote offices to the corporate data center. The administrator decides to use the Large Scale VPN (LSVPN) feature on the Palo Alto Networks next-generation firewall.
What should the administrator configure in order to connect the sites?
Generic Routing Encapsulation (GRE) Tunnels
GlobalProtect Satellite
SD-WAN
IKE Gateways
A customer wants to set up a site-to-site VPN using tunnel interfaces.
What format is the correct naming convention for tunnel interfaces?
tun.1025
tunnel.50
vpn.1024
gre1/2
An engineer notices that the tunnel monitoring has been failing for a day and the VPN should have failed over to a backup path.
What part of the network profile configuration should the engineer verify?
Destination IP
Threshold
Action
Interval
Which three multi-factor authentication methods can be used to authenticate access to the firewall? (Choose three.)
One-time password
User certificate
SMS
Voice
Fingerprint
Which two profiles should be configured when sharing tags from threat logs with a remote User-ID agent? (Choose two.)
LDAP
Log Ingestion
HTTP
Log Forwarding
What is the PAN-OS NPTv6 feature based on RFC 6296 used for?
Application port number translation
IPv6-to-IPv6 network prefix translation
Stateful translation to provide better security
IPv6-to-IPv6 host portion translation
An administrator has been tasked with deploying SSL Forward Proxy.
Which two types of certificates are used to decrypt the traffic? (Choose two.)
Device certificate
Subordinate CA from the administrator’s own PKI infrastructure
Self-signed root CA
External CA certificate
An engineer is deploying multiple firewalls with common configuration in Panorama.
What are two benefits of using nested device groups? (Choose two.)
Inherit all Security policy rules and objects
Inherit settings from the Shared group
Inherit IPSec crypto profiles
Inherit parent Security policy rules and objects
A network security administrator wants to inspect HTTPS traffic from users as it egresses through a firewall to the Internet/Untrust zone from trusted network zones. The security admin wishes to ensure that if users are presented with invalid or untrusted security certificates, the user will see an untrusted certificate warning.
What is the best choice for an SSL Forward Untrust certificate?
A self-signed certificate generated on the firewall
A web server certificate signed by the organization’s PKI
A web server certificate signed by an external Certificate Authority
A subordinate Certificate Authority certificate signed by the organization’s PKI
After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall. After troubleshooting, the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports.
What can the engineer do to solve the VoIP traffic issue?
Disable ALG under H.323 application
Increase the TCP timeout under H.323 application
Increase the TCP timeout under SIP application
Disable ALG under SIP application
After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?
Ensure Force Template Values is checked when pushing configuration.
Push the Template first, then push Device Group to the newly managed firewall.
Push the Device Group first, then push Template to the newly managed firewall.
Perform the Export or push Device Config Bundle to the newly managed firewall.
Which new PAN-OS 11.0 feature supports IPv6 traffic?
OSPF
IKEv1
DHCP Server
DHCPv6 Client with Prefix Delegation
If a URL is in multiple custom URL categories with different actions, which action will take priority?
Block
Allow
Alert
Override
An engineer is reviewing the following high availability (HA) settings to understand a recent HA failover event.
Which timer determines the frequency between packets sent to verify that the HA functionality on the other HA firewall is operational?
Hello Interval
Monitor Fail Hold Up Time
Heartbeat Interval
Promotion Hold Time
Which three items must be configured to implement application override? (Choose three.)
Application filter
Application override policy rule
Custom app
Decryption policy rule
Security policy rule
Which three items must be configured to implement application override? (Choose three.)
Application filter
Application override policy rule
Custom app
Decryption policy rule
Security policy rule
An engineer is configuring a firewall with three interfaces:
• MGT connects to a switch with internet access.
• Ethernet1/1 connects to an edge router.
• Ethernet1/2 connects to a virtualization network.
The engineer needs to configure dynamic updates to use a dataplane interface for internet traffic.
What should be configured in Setup > Services > Service Route Configuration to allow this traffic?
Set DNS and Palo Alto Networks Services to use the MGT source interface.
Set DNS and Palo Alto Networks Services to use the ethernet1/1 source interface.
Set DNS and Palo Alto Networks Services to use the ethernet1/2 source interface.
Set DDNS and Palo Alto Networks Services to use the MGT source interface.
An organization conducts research on the benefits of leveraging the Web Proxy feature of PAN-OS 11.0.
What are two benefits of using an explicit proxy method versus a transparent proxy method? (Choose two.)
No client configuration is required for explicit proxy, which simplifies the deployment complexity.
Explicit proxy supports interception of traffic using non-standard HTTPS ports.
It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request.
Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy.
Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the local firewall? (Choose three.)
TACACS+
Kerberos
SAML
RADIUS
LDAP
With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?
insufficient-data
incomplete
not-applicable
unknown-tcp
To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?
Clone the security policy and add it to the other device groups.
Add the policy to the target device group and apply a master device to the device group.
Reference the targeted device’s templates in the target device group.
Add the policy in the shared device group as a pre-rule.
Based on the graphic, which statement accurately describes the output shown in the Server Monitoring panel?
The User-ID agent is connected to a domain controller labeled lab-client.
The host lab-client has been found by the User-ID agent.
The host lab-client has been found by a domain controller.
The User-ID agent is connected to the firewall labeled lab-client.
What can be used as an Action when creating a Policy-Based Forwarding (PBF) policy?
Deny
Allow
Discard
Next VR
An engineer manages a high availability network and requires fast failover of the routing protocols. The engineer decides to implement BFD.
Which three dynamic routing protocols support BFD? (Choose three.)
OSPF
IGRP
OSPFv3 virtual link
BGP
RIP
A company has recently migrated their branch office’s PA-220s to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices. All device group and template configuration is managed solely within Panorama.
They notice that commit times have drastically increased for the PA-220s after the migration.
What can they do to reduce commit times?
Disable “Share Unused Address and Service Objects with Devices” in Panorama Settings.
Perform a device group push using the “merge with device candidate config” option.
Update the apps and threat version using device-deployment.
Use “export or push device config bundle” to ensure that the firewall is integrated with the Panorama config.
An administrator is troubleshooting why video traffic is not being properly classified.
If this traffic does not match any QoS classes, what default class is assigned?
1
2
3
4
An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.
What is one way the administrator can meet this requirement?
Reload the running configuration and perform a Firewall local commit.
Perform a commit force from the CLI of the firewall.
Perform a template commit push from Panorama using the “Force Template Values” option.
Perform a device-group commit push from Panorama using the “Include Device and Network Templates” option.
Where can a service route be configured for a specific destination IP?
Use Network > Virtual Routers, select the Virtual Router > Static Routes > IPv4
Use Device > Setup > Services > Services
Use Device > Setup > Services > Service Route Configuration > Customize > IPv4
Use Device > Setup > Services > Service Route Configuration > Customize > Destination
Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration.
What part of the configuration should the engineer verify?
IKE Crypto Profile
Security policy
Proxy-IDs
PAN-OS versions
Information Security is enforcing group-based policies by using security-event monitoring on Windows User-ID agents for IP-to-User mapping in the network. During the rollout, Information Security identified a gap for users authenticating to their VPN and wireless networks.
Root cause analysis showed that users were authenticating via RADIUS and that authentication events were not captured on the domain controllers that were being monitored. Information Security found that authentication events existed on the Identity Management solution (IDM).
There did not appear to be direct integration between PAN-OS and the IDM solution.
How can Information Security extract and learn IP-to-user mapping information from authentication events for VPN and wireless users?
Configure the integrated User-ID agent on PAN-OS to accept Syslog messages over TLS.
Configure the User-ID XML API on PAN-OS firewalls to pull the authentication events directly from the IDM solution.
Add domain controllers that might be missing to perform security-event monitoring for VPN and wireless users.
Configure the Windows User-ID agents to monitor the VPN concentrators and wireless controllers for IP-to-User mapping.
An administrator troubleshoots an issue that causes packet drops.
Which log type will help the engineer verify whether packet buffer protection was activated?
Configuration
Data Filtering
Traffic
Threat
An engineer creates a set of rules in a Device Group (Panorama) to permit traffic to various services for a specific LDAP user group.
What needs to be configured to ensure Panorama can retrieve user and group information for use in these rules?
A service route to the LDAP server
A User-ID agent on the LDAP server
A Master Device
Authentication Portal
Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.
Given the rule below, what change should be made to make sure the NAT works as expected?
Change destination NAT zone to Trust_L3.
Change destination translation to Dynamic IP (with session distribution) using firewall eth1/2 address.
Change Source NAT zone to Untrust_L3.
Add source Translation to translate original source IP to the firewall eth1/2 interface translation.
An engineer is configuring a template in Panorama which will contain settings that need to be applied to all firewalls in production.
Which three parts of a template an engineer can configure? (Choose three.)
Service Route Configuration
Dynamic Address Groups
NTP Server Address
Antivirus Profile
Authentication Profile
A firewall engineer reviews the PAN-OS GlobalProtect application and sees that it implicitly uses web-browsing and depends on SSL.
When creating a new rule, what is needed to allow the application to resolve dependencies?
Add SSL application to the same rule.
SSL and web-browsing must both be explicitly allowed.
Add SSL and web-browsing applications to the same rule.
Add web-browsing application to the same rule.
In a security-first network, what is the recommended threshold value for apps and threats to be dynamically updated?
1 to 4 hours
6 to 12 hours
24 hours
36 hours
An engineer configures a specific service route in an environment with multiple virtual systems instead of using the inherited global service route configuration.
What type of service route can be used for this configuration?
Destination-Based Service Route
Inherit Global Setting
IPv6 Source or Destination Address
IPv4 Source Interface
An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of VoIP traffic.
Which three elements should the administrator configure to address this issue? (Choose three.)
A QoS policy for each application
An Application Override policy for the SIP traffic
A QoS profile defining traffic classes
QoS on the ingress interface for the traffic flows
QoS on the egress interface for the traffic flows
What are three tasks that cannot be configured from Panorama by using a template stack? (Choose three.)
Rename a vsys on a multi-vsys firewall
Change the firewall management IP address
Enable operational modes such as normal mode, multi-vsys mode, or FIPS-CC mode
Add administrator accounts
Configure a device block list
Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
DATACENTER_DG post-rules -
shared post-rules
shared default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules
DATACENTER_DG post-rules -
DATACENTER_DG default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
shared post-rules
DATACENTER_DG post-rules -
shared default rules
shared pre-rules
DATACENTER_DG pre-rules -
rules configured locally on the firewall
DATACENTER_DG post-rules -
shared post-rules
DATACENTER_DG default rules
A company wants to implement threat prevention to take action without redesigning the network routing.
What are two best practice deployment modes for the firewall? (Choose two.)
Virtual Wire
Layer 2
Layer 3
TAP
Which operation will impact the performance of the management plane?
Enabling DoS protection
Enabling packet buffer protection
Decrypting SSL sessions
Generating a Saas Application report
Which type of policy in Palo Alto Networks firewalls can use Device-ID as a match condition?
Tunnel inspection
NAT
QoS
DOS protection
Why would a traffic log list an application as "not-applicable"?
There was not enough application data after the TCP connection was established.
The TCP connection terminated without identifying any application data.
The firewall denied the traffic before the application match could be performed.
The application is not a known Palo Alto Networks App-ID.
What must be configured to apply tags automatically based on User-ID logs?
Device ID
Log settings
Group mapping
Log Forwarding profile
A firewall engineer creates a NAT rule to translate IP address 1.1.1.10 to 192.168.1.10. The engineer also plans to enable DNS rewrite so that the firewall rewrites the IPv4 address in a DNS response based on the original destination IP address and translated destination IP address configured for the rule. The engineer wants the firewall to rewrite a DNS response of 1.1.1.10 to 192.168.1.10.
What should the engineer do to complete the configuration?
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.
Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.
Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53.
An engineer is monitoring an active/active high availability (HA) firewall pair.
Which HA firewall state describes the firewall that is experiencing a failure of a monitored path?
Initial
Passive
Active-secondary
Tentative
You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles.
For which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three.)
Critical
High
Medium
Informational
Low
In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?
Applications configured in the rule with their dependencies
The security rule with any other security rule selected
Applications configured in the rule with applications seen from traffic matching the same rule
The running configuration with the candidate configuration of the firewall
Given the following snippet of a WildFire submission log, did the end user successfully download a file?
Yes, because the final action is set to "allow."
No, because the action for the wildfire-virus is "reset-both."
No, because the URL generated an alert.
Yes, because both the web-browsing application and the flash file have the "alert" action.
Which two factors should be considered when sizing a decryption firewall deployment? (Choose two.)
Number of security zones in decryption policies
Encryption algorithm
TLS protocol version
Number of blocked sessions
After switching to a different WAN connection, users have reported that various websites will not load, and timeouts are occurring. The web servers work fine from other locations.
The firewall engineer discovers that some return traffic from these web servers is not reaching the users behind the firewall. The engineer later concludes that the maximum transmission unit (MTU) on an upstream router interface is set to 1400 bytes.
The engineer reviews the following CLI output for ethernet1/1.
Which setting should be modified on ethernet1/1 to remedy this problem?
Change the subnet mask from /23 to /24.
Lower the interface MTU value below 1500.
Adjust the TCP maximum segment size (MSS) value
Enable the Ignore IPv4 Don't Fragment (DF) setting.
A company requires the firewall to block expired certificates issued by internet-hosted websites. The company plans to implement decryption in the future, but it does not perform SSL Forward Proxy decryption at this time.
Without the use of SSL Forward Proxy decryption, how is the firewall still able to identify and block expired certificates issued by internet-hosted websites?
By having a Certificate profile that contains the website's Root CA assigned to the respective Security policy rule
By using SSL Forward Proxy to decrypt SSL and TLS handshake communication and the server/client session keys in order to validate a certificate's authenticity and expiration
By using SSL Forward Proxy to decrypt SSL and TLS handshake communication in order to validate a certificates authenticity and expiration
By having a Decryption profile that blocks sessions with expired certificates in the No Decryption section and assigning it to a No Decrypt policy rule
A company is looking to increase redundancy in their network.
Which interface type could help accomplish this?
Tap
Layer 2
Virtual wire
Aggregate ethernet
An engineer is deploying VoIP and needs to ensure that voice traffic is treated with the highest priority on the network.
Which QoS priority should be assigned to such an application?
Medium
Low
High
Real-time
The decision to upgrade to PAN-OS 10.2 has been approved. The engineer begins the process by upgrading the Panorama servers, but gets an error when trying to install.
When performing an upgrade on Panorama to PAN-OS 10.2, what is the potential cause of a failed install?
GlobalProtect agent version
Outdated plugins
Management only mode
Expired certificates
How can Panorama help with troubleshooting problems such as high CPU or resource exhaustion on a managed firewall?
Firewalls send SNMP traps to Panorama when resource exhaustion is detected. Panorama generates a system log and can send email alerts.
Panorama provides visibility into all the system and traffic logs received from firewalls. It does not offer any ability to see or monitor resource utilization on managed firewalls.
Panorama provides information about system resources of the managed devices in the Managed Devices > Health menu.
Panorama monitors all firewalls using SNMP. It generates a system log and can send email alerts when resource exhaustion is detected on a managed firewall.
An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall.
When certificates are being imported to the firewall for these purposes, which three certificates require a private key? (Choose three.)
Forward Untrust certificate
Enterprise Root CA certificate
Forward Trust certificate
End-entity (leaf) certificate
Intermediate certificate(s)
An administrator would like to determine which action the firewall will take for a specific CVE.
Given the screenshot below, where should the administrator navigate to view this information?
The profile rule action
CVE column
The profile rule threat name
Exceptions tab
In an HA failover scenario what happens with sessions decrypted by a SSL Forward Proxy Decryption policy?
The existing session is transferred to the active firewall.
The firewall drops the session.
The session is sent to fastpath.
The firewall allows the session but does not decrypt the session.
An administrator just enabled HA Heartbeat Backup on two devices. However, the status on the firewall's dashboard is showing as down.
What could an administrator do to troubleshoot the issue?
Go to Device > High Availability > General > HA Pair Settings > Setup and configuring the peer IP for heartbeat backup
Go to Device > High Availability > HA Communications > General > and check the Heartbeat Backup under Election Settings
Check peer IP address for heartbeat backup to Device > High Availability > HA Communications > Packet Forwarding settings
Check peer IP address in the permit list in Device > Setup > Management > Interfaces > Management Interface Settings
An engineer troubleshoots an issue that causes packet drops.
Which command should the engineer run in the CLI to see if packet buffer protection is enabled and activated?
show session id
show system state | match packet-buffer-protection
show session packet-buffer- protection
show running resource-monitor
An engineer configures SSL decryption in order to have more visibility to the internal users’ traffic when it is egressing the firewall.
Which three types of interfaces support SSL Forward Proxy? (Choose three.)
High availability (HA)
Layer 3
Layer 2
Tap
Virtual Wire
If an administrator wants to apply QoS to traffic based on source, what must be specified in a QoS policy rule?
Post-NAT destination address
Pre-NAT destination address
Pre-NAT source address
Post-NAT source address
An engineer reviews high availability (HA) settings to understand a recent HA failover event. Review the screenshot below.
Which timer determines how long the passive firewall will wait before taking over as the active firewall after losing communications with the HA peer?
Heartbeat Interval
Promotion Hold Time
Additional Master Hold Up Time
Monitor Fail Hold Up Time
A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below.
What should the NAT rule destination zone be set to?
None
Inside
DMZ
Outside
A consultant deploys a PAN-OS 11.0 VM-Series firewall with the Web Proxy feature in Transparent Proxy mode.
Which three elements must be in place before a transparent web proxy can function? (Choose three.)
User-ID for the proxy zone
DNS Security license
Prisma Access explicit proxy license
Cortex Data Lake license
Authentication Policy Rule set to default-web-form
Which source is the most reliable for collecting User-ID user mapping?
Microsoft Active Directory
Microsoft Exchange
GlobalProtect
Syslog Listener
Which type of zone will allow different virtual systems to communicate with each other?
Tap
Tunnel
Virtual Wire
External
An organization is interested in migrating from their existing web proxy architecture to the Web Proxy feature of their PAN-OS 11.0 firewalls. Currently, HTTP and SSL requests contain the destination IP address of the web server and the client browser is redirected to the proxy.
Which PAN-OS proxy method should be configured to maintain this type of traffic flow?
SSL forward proxy
Explicit proxy
Transparent proxy
DNS proxy
An engineer discovers the management interface is not routable to the User-ID agent.
What configuration is needed to allow the firewall to communicate to the User-ID agent?
Add a Policy Based Forwarding (PBF) policy to the User-ID agent IP
Create a NAT policy for the User-ID agent server
Create a custom service route for the UID Agent
Add a static route to the virtual router
An engineer receives reports from users that applications are not working and that websites are only partially loading in an asymmetric environment. After investigating, the engineer observes the flow_tcp_non_syn_drop counter increasing in the show counters global output.
Which troubleshooting command should the engineer use to work around this issue?
set deviceconfig setting tcp asymmetric-path drop
set session tcp-reject-non-syn yes
set deviceconfig setting tcp asymmetric-path bypass
set deviceconfig setting session tcp-reject-non-syn no
Where is Palo Alto Networks Device Telemetry data stored on a firewall with a device certificate installed?
Panorama
M600 Log Collectors
Cortex Data Lake
On Palo Alto Networks Update Servers
Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?
Satellite mode
Tunnel mode
No Direct Access to local networks
IPSec mode
A superuser is tasked with creating administrator accounts for three contractors. For compliance purposes, all three contractors will be working with different device-groups in their hierarchy to deploy policies and objects.
Which type of role-based access is most appropriate for this project?
Create a Dynamic Admin with the Panorama Administrator role.
Create a Dynamic Read only superuser.
Create a Device Group and Template Admin.
Create a Custom Panorama Admin.
