Font size
S
M
L
XL
WorksheetsPCNSA EXAM TRYOUT
Total questions: 70
Worksheet time: 5hrs 15mins
Name
Class
Date
1.
Within an Anti-Spyware security profile, which tab is used to enable machine learning based engines?
a)
Signature Exceptions
b)
Signature Policies
c)
Machine Learning Policies
d)
Inline Cloud Analysis
2.
What are three ways application characteristics are used? (Choose three.)
a)
As an attribute to define an application group
b)
As a global filter in the Application Command Center (ACC)
c)
As an attribute to define an application filter
d)
As a setting to define a new custom application
e)
As an object to define Security policies
3.
Which two features implement one-to-one translation of a source IP address while allowing the source port to change? (Choose two.)
a)
Dynamic IP/Port Fallback
b)
Static IP
c)
Dynamic IP
d)
Dynamic IP and Port (DIPP)
4.
Which statement applies to Antivirus Dynamic Updates?
a)
When the firewall downloads and installs each new antivirus version in order, it shows as a full update.
b)
They are released every 48 hours.
c)
They include signatures for newly discovered malware.
d)
When the firewall does not download and install a new antivirus version in order, it shows as an incremental update.
5.
What are the two main reasons a custom application is created? (Choose two.)
a)
To visually group similar applications
b)
To correctly identify an internal application in the traffic log
c)
To change the default categorization of an application
d)
To reduce unidentified traffic on a network
6.
A network administrator creates an intrazone security policy rule on a NGFW. The source zones are set to IT, Finance, and HR.
To which two types of traffic will the rule apply? (Choose two.)
a)
Within zone HR
b)
Between zone IT and zone HR
c)
Within zone IT
d)
Between zone IT and zone Finance
7.
Which two actions are needed for an administrator to get real-time WildFire signatures? (Choose two.)
a)
Move within the WildFire public cloud region.
b)
Obtain a Threat Prevention subscription.
c)
Enable Dynamic Updates.
d)
Obtain a WildFire subscription.
8.
Which order of steps is the correct way to create a static route?
a)
1) Enter the route and netmask
2) Specify the outgoing interface for packets to use to go to the next hop
3) Enter the IP address for the specific next hop
4) Add an IPv4 or IPv6 route by name
b)
1) Enter the IP address for the specific next hop
2) Enter the route and netmask
3) Add an IPv4 or IPv6 route by name
4) Specify the outgoing interface for packets to use to go to the next hop
c)
1) Enter the route and netmask
2) Enter the IP address for the specific next hop
3) Specify the outgoing interface for packets to use to go to the next hop
4) Add an IPv4 or IPv6 route by name
d)
1) Enter the IP address for the specific next hop
2) Add an IPv4 or IPv6 route by name
3) Enter the route and netmask
4) Specify the outgoing interface for packets to use to go to the next hop
9.
Which three types of Source NAT are available to users inside a NGFW? (Choose three.)
a)
Dynamic IP and Port (DIPP)
b)
Static IP
c)
Static Port
d)
Dynamic IP
e)
Static IP and Port (SIPP)
10.
Which two statements correctly describe how pre-rules and local device rules are viewed and modified?
a)
Pre-rules can be modified by the local administrator or by a Panorama administrator who has switched to a local firewall.
b)
Pre-rules are modified in Panorama only, and local device rules are modified on local firewalls only
c)
Pre-rules and local device rules can be modified in Panorama.
d)
Pre-rules can be viewed on managed firewalls.
11.
Which administrative management services can be configured to access a management interface?
a)
HTTP, CLI, SNMP, HTTPS
b)
HTTPS, SSH telnet SNMP
c)
SSH: telnet HTTP, HTTPS
d)
HTTPS, HTT
e)
CLI, API
12.
An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic. Which two Security policy rules will accomplish this configuration? (Choose two.)
a)
Untrust (Any) to DMZ (1.1.1.100), ssh - Allow
b)
Untrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
c)
Untrust (Any) to Untrust (10.1.1.1), ssh -Allow
d)
Untrust (Any)to DMZ (10.1.1.100. 10.1.1.101), ssh, web-browsing-Allow
e)
Untrust (Any) to DMZ (1.1.1.100), web-browsing - Allow
13.
An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. The interzone-default was never changed from its default configuration. Why doesn't the administrator see the traffic?
a)
Traffic is being denied on the interzone-default policy.
b)
The Log Forwarding profile is not configured on the policy.
c)
The interzone-default policy is disabled by default
d)
Logging on the interzone-default policy is disabled
14.
What are three valid ways to map an IP address to a username? (Choose three.)
a)
using the XML API
b)
DHCP Relay logs
c)
a user connecting into a GlobalProtect gateway using a GlobalProtect Agent
d)
usernames inserted inside HTTP Headers
e)
WildFire verdict reports
15.
Which administrator type provides more granular options to determine what the administrator can view and modify when creating an administrator account?
a)
Root
b)
Dynamic
c)
Role-based
d)
Superuser
16.
Which two statements are true for the DNS security service introduced in PAN-OS version 10.0?
a)
It functions like PAN-DB and requires activation through the app portal
b)
It removes the 100K limit for DNS entries for the downloaded DNS updates
c)
IT eliminates the need for dynamic DNS updates
d)
IT is automatically enabled and configured
17.
Which administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server. Which security profile components will detect and prevent this threat after the firewall`s signature database has been updated?
a)
antivirus profile applied to outbound security policies
b)
data filtering profile applied to inbound security policies
c)
data filtering profile applied to outbound security policies
d)
vulnerability profile applied to inbound security policies
18.
Complete the statement. A security profile can block or allow traffic
a)
on unknown-tcp or unknown-udp traffic
b)
after it is matched by a security policy that allows traffic
c)
before it is matched by a security policy
d)
after it is matched by a security policy that allows or blocks traffic
19.
The compliance officer requests that all evasive applications need to be blocked on all perimeter firewalls out to the internet The firewall is configured with two zones;
* 1. trust for internal networks
* 2. untrust to the internet
Based on the capabilities of the Palo Alto Networks NGFW, what are two ways to configure a security policy using App-ID to comply with this request? (Choose two )
a)
Create a deny rule at the top of the policy from trust to untrust over any service and select evasive as the application
b)
Create a deny rule at the top of the policy from trust to untrust with service application-default and select evasive as the application
c)
Create a deny rule at the top of the policy from trust to untrust over any service and add an application filter with the evasive characteristic
d)
Create a deny rule at the top of the policy from trust to untrust with service application-default and add an application filter with the evasive characteristic
20.
Which security profile will provide the best protection against ICMP floods, based on individual combinations of a packet`s source and destination IP address?
a)
DoS protection
b)
URL filtering
c)
packet buffering
d)
anti-spyware
21.
An administrator is reviewing another administrator s Security policy log settings Which log setting configuration is consistent with best practices tor normal traffic?
a)
Log at Session Start and Log at Session End both enabled
b)
Log at Session Start disabled Log at Session End enabled
c)
Log at Session Start enabled Log at Session End disabled
d)
Log at Session Start and Log at Session End both disabled
22.
Which dynamic update type includes updated anti-spyware signatures?
a)
Applications and Threats
b)
GlobalProtect Data File
c)
Antivirus
d)
PAN-DB
23.
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command_x0002_and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall’s signature database has been updated? (Choose two.)
a)
vulnerability protection profile applied to outbound security policies
b)
anti-spyware profile applied to outbound security policies
c)
antivirus profile applied to outbound security policies
d)
URL filtering profile applied to outbound security policies
24.
Why does a company need an Antivirus profile?
a)
To prevent command-and-control traffic
b)
To protect against viruses, worms, and trojans
c)
To prevent known exploits
d)
To prevent access to malicious web content
25.
Which two security profile types can be attached to a security policy? (Choose two.)
a)
antivirus
b)
DDoS protection
c)
threat
d)
vulnerability
26.
Which two matching criteria are used when creating a Security policy involving NAT? (Choose two.)
a)
Post-NAT address
b)
Post-NAT zone
c)
Pre-NAT zone
d)
Pre-NAT address
27.
Palo Alto Networks firewall architecture accelerates content map minimizing latency using which two components'? (Choose two )
a)
Network Processing Engine
b)
Single Stream-based Engine
c)
Policy Engine
d)
Parallel Processing Hardware
28.
Which path is used to save and load a configuration with a Palo Alto Networks firewall?
a)
Device>Setup>Services
b)
Device>Setup>Management
c)
Device>Setup>Operations
d)
Device>Setup>Interfaces
29.
What can be used as match criteria for creating a dynamic address group?
a)
Usernames
b)
IP addresses
c)
Tags
d)
MAC addresses
30.
After making multiple changes to the candidate configuration of a firewall, the administrator would like to start over with a candidate configuration that matches the running configuration. Which command in Device > Setup > Operations would provide the most operationally efficient way to accomplish this?
a)
Import named config snapshot
b)
Load named configuration snapshot
c)
Revert to running configuration
d)
Revert to last saved configuration
31.
Which action results in the firewall blocking network traffic without notifying the sender?
a)
Deny
b)
No notification
c)
Drop
d)
Reset Client
32.
What do you configure if you want to set up a group of objects based on their ports alone?
a)
Application groups
b)
Service groups
c)
Address groups
d)
Custom objects
33.
Which User-ID mapping method should be used for an environment with clients that do not authenticate to Windows Active Directory?
a)
Windows session monitoring via a domain controller
b)
passive server monitoring using the Windows-based agent
c)
Captive Portal
d)
passive server monitoring using a PAN-OS integrated User-ID agent
34.
Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that matches new application signatures?
a)
Review Policies
b)
Review Apps
c)
Pre-analyze
d)
Review App Matches
35.
What is the purpose of the automated commit recovery feature?
a)
It reverts the Panorama configuration
b)
It causes HA synchronization to occur automatically between the HA peers after a push from Panorama
c)
It reverts the firewall configuration if the firewall recognizes a loss of connectivity to Panorama after the change
d)
It generates a config log after the Panorama configuration successfully reverts to the last running configuration
36.
Which interface does not require a MAC or IP address?
a)
Virtual Wire
b)
Layer3
c)
Layer2
d)
Loopback
37.
Given the screenshot what two types of route is the administrator configuring? (Choose two )
a)
default route
b)
OSPF
c)
BGP
d)
static route
38.
Which definition describes the guiding principle of the zero-trust architecture?
a)
never trust, never connect
b)
always connect and verify
c)
never trust, always verify
d)
trust, but verity
39.
Which interface type is part of a Layer 3 zone with a Palo Alto Networks firewall?
a)
Management
b)
High Availability
c)
Aggregate
d)
Aggregation
40.
Which security policy rule would be needed to match traffic that passes between the Outside zone and Inside zone, but does not match traffic that passes within
the zones?
a)
intrazone
b)
interzone
c)
universal
d)
global
41.
You need to allow users to access the office–suite application of their choice. How should you configure the firewall to allow access to any office-suite application?
a)
Create an Application Group and add Office 365, Evernote Google Docs and Libre Office
b)
Create an Application Group and add business-systems to it
c)
Create an Application Filter and name it Office Programs, then filter it on the office programs subcategory
d)
Create an Application Filter and name it Office Programs then filter on the business-systems category
42.
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)
a)
Layer-ID
b)
User-ID
c)
QoS-ID
d)
App-ID
43.
Which type of administrative role must you assign to a firewall administrator account, if the account must include a custom set of firewall permissions?
a)
SAML
b)
Multi-Factor Authentication
c)
Role-based
d)
Dynamic
44.
An administrator would like to protect against inbound threats such as buffer overflows and illegal code execution. Which Security profile should be used?
a)
Antivirus
b)
URL filtering
c)
Anti-spyware
d)
Vulnerability protection
45.
Which statement is true about Panorama managed devices?
a)
Panorama automatically removes local configuration locks after a commit from Panorama
b)
Local configuration locks prohibit Security policy changes for a Panorama managed device
c)
Security policy rules configured on local firewalls always take precedence
d)
Local configuration locks can be manually unlocked from Panorama
46.
Which firewall feature do you need to configure to query Palo Alto Networks service updates over a data-plane interface instead of the management interface?
a)
Data redistribution
b)
Dynamic updates
c)
SNMP setup
d)
Service route
47.
An administrator would like to create a URL Filtering log entry when users browse to any gambling website. What combination of Security policy and Security profile actions is correct?
a)
Security policy = drop, Gambling category in URL profile = allow
b)
Security policy = deny, Gambling category in URL profile = block
c)
Security policy = allow, Gambling category in URL profile = alert
d)
Security policy = allow, Gambling category in URL profile = allow
48.
Which object would an administrator create to enable access to all applications in the office-programs subcategory?
a)
HIP profile
b)
Application group
c)
URL category
d)
Application filter
49.
Which license must an administrator acquire prior to downloading Antivirus updates for use with the firewall?
a)
URL filtering
b)
Antivirus
c)
WildFire
d)
Threat Prevention
50.
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?
a)
Policies> Security> Rule Usage> No App Specified
b)
Policies> Security> Rule Usage> Port only specified
c)
Policies> Security> Rule Usage> Port-based Rules
d)
Policies> Security> Rule Usage> Unused Apps
51.
Which Security policy action will message a user's browser thai their web session has been terminated?
a)
Reset server
b)
Deny
c)
Drop
d)
Reset client
52.
Which two settings allow you to restrict access to the management interface? (Choose two )
a)
enabling the Content-ID filter
b)
administrative management services
c)
restricting HTTP and telnet using App-ID
d)
permitted IP addresses
53.
Where within the Firewall GUI can an administrator create a local user database?
a)
Device > Local User Database > Users
b)
Device > Local User Database > Admins
c)
Device > Local User Database > Guests
d)
Device > Local User Database > End Users
54.
Which two DNS Policy actions in the anti-spyware security profile can prevent hacking attacks through DNS queries to malicious domains? (Choose two)
a)
Block
b)
Deny
c)
Override
d)
Sinkhole
55.
How can a complete overview of the logs be displayed to an administrator who has permission in the system to view them?
a)
Select the unified log entry in the side menu
b)
Select the system logs entry in the side menu
c)
Modify the number of columns visible on the page
d)
Modify the number of logs visible on each page
56.
How are service routes used in PAN-OS?
a)
By the OSPF protocol, as part of Dijkstra's algorithm, to give access to the various services offered in the network
b)
To route management plane services through data interfaces rather than the management interface
c)
To statically route subnets so they are joinable from, and have access to the Palo Alto Networks external services
d)
For routing, because they are the shortes path selected by the BGP routing protocol
57.
What are two firewall management access methods? (Choose two)
a)
CLI
b)
Remote desktop protocol (RDP)
c)
VPN
d)
XML API
58.
What are the two default services that are available on the MGT interface? (Choose two)
a)
HTTPS
b)
SSH
c)
HTTP
d)
Telnet
59.
Which command must be performed on the firewall to activate any changes?
a)
Save
b)
Load
c)
Import
d)
Commit
60.
What can be used to control traffic through zones?
a)
Access lists
b)
Security policy lists
c)
Security policy rules
d)
Access policy rules
61.
Which two Dynamic Admin Role types are available on the PAN-OS Software? (Choose two)
a)
Superuser
b)
Superuser (write-only)
c)
Device user
d)
Device administrator (read-only)
62.
What will be the results of one or more occurrences of shadowing?
a)
A failed commit
b)
An invalid configuration
c)
A warning
d)
An alarm window
63.
What are the two default (predefined) Security policy rule types in PAN-OS software?
a)
Universal
b)
Interzone
c)
Intrazone
d)
Extrazone
64.
If you have a Threat Prevention subscription but not a WildFire Subscription, how long must you wait for the WildFire signatures to added into the antivirus update?
a)
1 to 2 hours
b)
2 to 4 hours
c)
10 to 12 hours
d)
24 to 48 hours
65.
A URL Filtering Profile is part of which type of identification?
a)
App-ID
b)
Content-ID
c)
User-ID
d)
Service
66.
Which to valid URLs can be used in a custom URL category? (Choose two)
a)
www.youtube.**
b)
www.**.com
c)
www.youtube.com
d)
**youtube*
e)
*.youtube.com
67.
Which two interface types can belong in a Layer 3 zone? (Choose two)
a)
Loopback
b)
Tap
c)
Tunnel
d)
Virtual Wire
68.
What are two application characteristics? (Choose Two)
a)
Stateful
b)
Excessive Bandwidth use
c)
Intensive
d)
Evasive
69.
Which two actions are available for Antivirus Security Profiles? (choose two)
a)
Continue
b)
Allow
c)
Block IP
d)
Alert
70.
Which profile is used to override global minimum password complexity requirements?
a)
Authentication
b)
Local
c)
User
d)
Password
Reset
