Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PCNSA Practice Exam with Questions & Answers | Set: 3

Questions 21

Which interface type requires no routing or switching but applies Security or NAT policy rules before passing allowed traffic?

Options:
A.

Layer 3

B.

Virtual Wire

C.

Tap

D.

Layer 2

Questions 22

Which statement best describes the use of Policy Optimizer?

Options:
A.

Policy Optimizer can display which Security policies have not been used in the last 90 days

B.

Policy Optimizer on a VM-50 firewall can display which Layer 7 App-ID Security policies have unused applications

C.

Policy Optimizer can add or change a Log Forwarding profile for each Secunty policy selected

D.

Policy Optimizer can be used on a schedule to automatically create a disabled Layer 7 App-ID Security policy for every Layer 4 policy that exists Admins can then manually enable policies they want to keep and delete ones they want to remove

Questions 23

Which definition describes the guiding principle of the zero-trust architecture?

Options:
A.

never trust, never connect

B.

always connect and verify

C.

never trust, always verify

D.

trust, but verity

Questions 24

Which data flow direction is protected in a zero trust firewall deployment that is not protected in a perimeter-only firewall deployment?

Options:
A.

outbound

B.

north south

C.

inbound

D.

east west

Questions 25

Which three interface deployment methods can be used to block traffic flowing through the Palo Alto Networks firewall? (Choose three.)

Options:
A.

Layer 2

B.

Virtual Wire

C.

Tap

D.

Layer 3

E.

HA

Questions 26

What are three configurable interface types for a data-plane ethernet interface? (Choose three.)

Options:
A.

Layer 3

B.

HSCI

C.

VWire

D.

Layer 2

E.

Management

Questions 27

How are Application Fillers or Application Groups used in firewall policy?

Options:
A.

An Application Filter is a static way of grouping applications and can be configured as a nested member of an Application Group

B.

An Application Filter is a dynamic way to group applications and can be configured as a nested member of an Application Group

C.

An Application Group is a dynamic way of grouping applications and can be configured as a nested member of an Application Group

D.

An Application Group is a static way of grouping applications and cannot be configured as a nested member of Application Group

Questions 28

Which User-ID agent would be appropriate in a network with multiple WAN links, limited network bandwidth, and limited firewall management plane resources?

Options:
A.

Windows-based agent deployed on the internal network

B.

PAN-OS integrated agent deployed on the internal network

C.

Citrix terminal server deployed on the internal network

D.

Windows-based agent deployed on each of the WAN Links

Questions 29

What do dynamic user groups you to do?

Options:
A.

create a QoS policy that provides auto-remediation for anomalous user behavior and malicious activity

B.

create a policy that provides auto-sizing for anomalous user behavior and malicious activity

C.

create a policy that provides auto-remediation for anomalous user behavior and malicious activity

D.

create a dynamic list of firewall administrators

Questions 30

What must be configured before setting up Credential Phishing Prevention?

Options:
A.

Anti Phishing Block Page

B.

Threat Prevention

C.

Anti Phishing profiles

D.

User-ID