Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Paloalto Networks PCNSA Practice Exam with Questions & Answers | Set: 2

Questions 11

In which three places on the PAN-OS interface can the application characteristics be found? (Choose three.)

Options:
A.

Objects tab > Application Filters

B.

Policies tab > Security

C.

ACC tab > Global Filters

D.

Objects tab > Application Groups

E.

Objects tab > Applications

Paloalto Networks PCNSA Premium Access
Questions 12

An administrator creates a new Security policy rule to allow DNS traffic from the LAN to the DMZ zones. The administrator does not change the rule type from its default value.

What type of Security policy rule is created?

Options:
A.

Tagged

B.

Intrazone

C.

Universal

D.

Interzone

Questions 13

Which URL profiling action does not generate a log entry when a user attempts to access that URL?

Options:
A.

Override

B.

Allow

C.

Block

D.

Continue

Questions 14

What is the minimum timeframe that can be set on the firewall to check for new WildFire signatures?

Options:
A.

every 30 minutes

B.

every 5 minutes

C.

once every 24 hours

D.

every 1 minute

Questions 15

Which three types of entries can be excluded from an external dynamic list (EDL)? (Choose three.)

Options:
A.

IP addresses

B.

Domains

C.

User-ID

D.

URLs

E.

Applications

Questions 16

Which statement is true about Panorama managed devices?

Options:
A.

Panorama automatically removes local configuration locks after a commit from Panorama

B.

Local configuration locks prohibit Security policy changes for a Panorama managed device

C.

Security policy rules configured on local firewalls always take precedence

D.

Local configuration locks can be manually unlocked from Panorama

Questions 17

Which object would an administrator create to enable access to all applications in the office-programs subcategory?

Options:
A.

application filter

B.

URL category

C.

HIP profile

D.

application group

Questions 18

An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. The interzone-default was never changed from its default configuration.

Why doesn't the administrator see the traffic?

Options:
A.

Traffic is being denied on the interzone-default policy.

B.

The Log Forwarding profile is not configured on the policy.

C.

The interzone-default policy is disabled by default

D.

Logging on the interzone-default policy is disabled

Questions 19

Based on the security policy rules shown, ssh will be allowed on which port?

PCNSA Question 19

Options:
A.

any port

B.

same port as ssl and snmpv3

C.

the default port

D.

only ephemeral ports

Questions 20

PCNSA Question 20

View the diagram. What is the most restrictive, yet fully functional rule, to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT/Guest and Trust Zones?

A)

PCNSA Question 20

B)

PCNSA Question 20

C)

PCNSA Question 20

D)

PCNSA Question 20

Options:
A.

Option

B.

Option

C.

Option

D.

Option