Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PCNSA Practice Exam with Questions & Answers | Set: 8

Questions 71

Based on the graphic, what is the purpose of the SSL/TLS Service profile configuration option?

PCNSA Question 71

Options:
A.

It defines the SSUTLS encryption strength used to protect the management interface.

B.

It defines the CA certificate used to verify the client's browser.

C.

It defines the certificate to send to the client's browser from the management interface.

D.

It defines the firewall's global SSL/TLS timeout values.

Paloalto Networks PCNSA Premium Access
Questions 72

Which feature enables an administrator to review the Security policy rule base for unused rules?

Options:
A.

Test Policy Match

B.

Policy Optimizer

C.

View Rulebase as Groups

D.

Security policy tags eb

Questions 73

Which feature would be useful for preventing traffic from hosting providers that place few restrictions on content, whose services are frequently used by attackers to distribute illegal or unethical material?

Options:
A.

Palo Alto Networks Bulletproof IP Addresses

B.

Palo Alto Networks C&C IP Addresses

C.

Palo Alto Networks Known Malicious IP Addresses

D.

Palo Alto Networks High-Risk IP Addresses

Questions 74

An administrator would like to silently drop traffic from the internet to a ftp server.

Which Security policy action should the administrator select?

Options:
A.

Reset-server

B.

Block

C.

Deny

D.

Drop

Questions 75

Which interface type is part of a Layer 3 zone with a Palo Alto Networks firewall?

Options:
A.

Management

B.

High Availability

C.

Aggregate

D.

Aggregation

Questions 76

Which solution is a viable option to capture user identification when Active Directory is not in use?

Options:
A.

Cloud Identity Engine

B.

group mapping

C.

Directory Sync Service

D.

Authentication Portal

Questions 77

If using group mapping with Active Directory Universal Groups, what must you do when configuring the User-ID?

Options:
A.

Create an LDAP Server profile to connect to the root domain of the Global Catalog server on port 3268 or 3269 for SSL

B.

Configure a frequency schedule to clear group mapping cache

C.

Configure a Primary Employee ID number for user-based Security policies

D.

Create a RADIUS Server profile to connect to the domain controllers using LDAPS on port 636 or 389

Questions 78

Which two security profile types can be attached to a security policy? (Choose two.)

Options:
A.

antivirus

B.

DDoS protection

C.

threat

D.

vulnerability

Questions 79

What is used to monitor Security policy applications and usage?

Options:
A.

Policy Optimizer

B.

App-ID

C.

Security profile

D.

Policy-based forwarding

Questions 80

Which setting is available to edit when a tag is created on the local firewall?

Options:
A.

Location

B.

Color

C.

Order

D.

Priority