wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

PCNSC question 21 to 40

Total questions: 20

Worksheet time: 16mins

Name
Class
Date
1.

​ ​ ​

​ ​ ​ Match the command with the appropriate scenario for its use

Categorize the following

show system software statusshow\ system\ software\ status  

debug dataplane packet-diag

tail follow yes mp.log authd.log

show running resource-monitor

tail follow yes dp.log authd.log

show system resources

Management plane resource
Data plane resources
State of various processes
Authentication log
2.

Your customer is setting up an IPsec VPN tunnel with a third party. The third-party device only supports policy-based IPsec VPN tunnels.
What must be set up on the IPsec tunnel on the Palo Alto Networks Next-Generation Firewall to support policy-based tunnels?

a)

policy-based forwarding

b)

static route

c)

Proxy-ID

d)

DNS proxy

3.

Which category of Vulnerability Signatures is most likely to trigger false positive alerts?

a)

info-leak

b)

code-execution

c)

phishing

d)

brute-force

4.

What information is required in order to plan the deployment of a perimeter firewall?

a)

the management IP of the DSL device provided by the ISP

b)

The operating system and browser version of the management client

c)

the link type and speed of the surrounding devices

d)

the name of the Internet provider and the cost of the link

5.

A customer uses an application on the network that shows unknown-tcp application in the traffic logs.
Which two actions can the administrator take to make the application display this information? (Choose two.)

a)

Create a custom application by using fingerprinting applications

b)

Submit a request for a new App-ID on the Application & Threat Research Center

c)

Create a customer application by using signatures

d)

Submit a request for new App-ID with Unit-42

6.

What happens when a packet from an existing session is received by a firewall that is not the owner in an HA active/active configuration?

a)

The firewall requests the sender to resend the packet

b)

The firewall forwards the packet to the peer firewall over the HA3 link.

c)

The firewall takes ownership of the session from the peer firewall

d)

The firewall drops the packet to prevent any L3 loops.

7.

You have just completed a firewall migration project in Expedition. Expedition is not directly connected to a firewall. You decide to export the configuration.
What two file types will be available to you in the download options? (Choose two.)

a)

a tech support file for the target firewall

b)

the README file describing how to use the XML file

c)

a TXT file with SET commands

d)

an XML file to upload to the Palo Alto Networks device

8.

Which three steps must an administrator perform to load only address objects from a PAN-OS saved configuration file into a VM-300 firewall that is in production? (Choose three.)

a)

import named configuration snapshot through the web interface

b)

use load config partial command

c)

use the device configuration import in Panorama

d)

load the config in the web interface and commit

e)

enter the configuration mode from the CLI

9.

DRAG DROP -
Match the task for server settings in group mapping with its order in the process

a)

Navigate to Device > User Identification > Group Mapping

b)

Add a new group mapping

c)

Create an Ldap Server Profile

d)

Select the LDAP Server Profile

e)

Enter a unique name to identify the group mapping configuration

1)
2)
3)
4)
5)
10.

DRAG DROP -
Match the App-ID adoption task with its order in the process

a)

Perform a like-for-like (layer 3/4) migration from the legacy firewall to the Palo Alto Networks NGFW

b)

Capture, retain, and verify that all trafic has been logged for a period of time.

c)

Clone the legacy rules and add aplication information to the intended application-based rules

d)

Verify thet no traffic is hitting the legacy rules.

e)

Remove the legacy rules

1)
2)
3)
4)
5)
11.

TAC has requested a PCAP on your Panorama to see why the DNS app is having intermittent issues resolving FQDN.
What is the appropriate CLI command?

a)

tcpdump snaplen 53 filter “port 53”

b)

tcp dump snaplen 0 filter “app dns”

c)

tcpdump snaplen 0 filter “port 53”

d)

tcp dump snaplen 53 filter “tcp 53”

12.

A firewall configuration is being migrated by Expedition from a third-party vendor to a Palo Alto Networks Next-Generation Firewall (NGFW.). Expedition flags one service as invalid following the import of the original configuration file. An engineer investigates and finds the invalid service to be ping which is used by the security policies.
Which action should the engineer take?

a)

Create an Application Override policy to override the ping service classification with ping application.

b)

Remove ping service from all the policies which reference it.

c)

Ignore the invalid flag in Expedition for the firewall to accept ping service.

d)

Use the search & replace in Expedition to replace the ping service classification with ping application

13.

SSL decryption has been implemented in a customer environment. The firewall protecting this environment is using PAN-OS 10.0. Users of an application are filing support cases claiming that a function of this application is no longer working.
Where should the investigation for decryption issues begin?

a)

the Correlated Events log

b)

the “session end reason” column in the Traffic log

c)

the CLI, using the less mp-log ikemgr.log command

d)

the Decryption log

14.

What information is necessary to properly plan the deployment of a Panorama hardware appliance for firewall management?

a)

Virtual router, zones, and interface configuration of the dataplane interface

b)

ESXi Server location and routing to the Panorama appliance

c)

Wiring, power, Console access, and management interface connectivity

d)

Panorama Mode, number of managed devices, CPU, and memory allocation in the hypervisor

15.

Which additional license is required for the feature Host Information Profiles to function on Palo Alto Networks Next-Generation Firewalls?

a)

Threat

b)

WildFire

c)

GlobalProtact gateway

d)

IoT

16.

What is the default port used by the Terminal Services agent to communicate with a firewall?

a)

5009

b)

5007

c)

5007

d)

443

17.

SSL Forward Proxy decryption is enabled on the firewall. When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates. The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates.
Which two options will satisfy this requirement? (Choose two.)

a)

Create a PKI signed Forward Untrust enabled certificate.

b)

Create a self-signed Forward Untrust enabled certificate.

c)

Create a Decryption Profile with the “Block sessions with expired certificates” option enabled.

d)

Remove the Forward Untrust option from the Forward Trust certificate.

18.

Your customer wants to implement Active/Active High Availability for their PA-5260 pair. The following conditions are true in their environment:
-They are using multiple Layer 3 interfaces to process traffic.
-Their routing topology requires the use of Network Address Translation policies to ensure that traffic can reach its destinations correctly.
-They prefer to have the session workload distributed as evenly as possible to ensure both firewalls have lower resource utilization.
-They make use of dynamic routing protocols on their virtual routers for route-based redundancy.
-They chose to go with Active/Active for failover speed reasons.
Which three of the following HA configurations should your customer ensure they use to meet these requirements? (Choose three.)

a)

HA1A, HA1B, and HA2 interfaces

b)

HA1A, HA1B, HA2, and HA3 interfaces

c)

Session selection algorithm – Primary Device

d)

Active/Active HA Binding in the NAT policies

e)

Session selection algorithm – First Packet

19.

Which CLI command should you use to verify whether all SFP, SFP+, or QSFP modules are installed in a firewall?

a)

show system state filter sys.p*.phy

b)

show system state filter sys.s*.p*.phy

c)

show system info

d)

show interface <interface name> detail

20.

Which three attributes can be used to exclude traffic from an SSL Decryption policy? (Choose three.)

a)

User-ID

b)

URL Category

c)

HIP Profile

d)

Application

e)

Destination