[2024] Pass PCNSA Exam - Real Questions and Answers
PCNSA Exam Questions Get Updated [2024] with Correct Answers
NEW QUESTION # 209
Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?
- A. ftp
- B. imap
- C. http2
- D. smb
Answer: B
Explanation:
According to the screenshot, only imap, pop3 and smtp have a default (alert) action, which generates an alert for each application traffic flow. The alert is saved in the threat log.
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-profiles
NEW QUESTION # 210
How often are new and modified threat signatures and modified applications signatures published?
- A. daily
- B. monthly
- C. hourly
- D. weekly
Answer: D
NEW QUESTION # 211
Which firewall plane provides configuration, logging, and reporting functions on a separate processor?
- A. control
- B. network processing
- C. data
- D. security processing
Answer: A
NEW QUESTION # 212
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated?
(Choose two.)
- A. antivirus profile applied to outbound security policies
- B. anti-spyware profile applied to outbound security policies
- C. vulnerability protection profile applied to outbound security policies
- D. URL filtering profile applied to outbound security policies
Answer: B,D
NEW QUESTION # 213
Order the steps needed to create a new security zone with a Palo Alto Networks firewall.
Answer:
Explanation:
Explanation
Step 1 - Select network tab
Step 2 - Select zones from the list of available items
Step 3 - Select Add
Step 4 - Specify Zone Name
Step 5 - Specify Zone Type
Step 6 - Assign interfaces as needed
NEW QUESTION # 214
Which administrator type utilizes predefined roles for a local administrator account?
- A. Role-based
- B. Device administrator
- C. Superuser
- D. Dynamic
Answer: D
NEW QUESTION # 215
Choose the option that correctly completes this statement. A Security Profile can block or allow traffic ____________.
- A. before it is matched to a Security policy rule.
- B. after it is matched by a security policy rule that allows or blocks traffic.
- C. on either the data place or the management plane.
- D. after it is matched by a security policy rule that allows traffic.
Answer: D
Explanation:
Explanation/Reference:
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-policy.html After a packet has been allowed by the Security policy, Security Profiles are used to scan packets for threats, vulnerabilities, viruses, spyware, malicious URLs, data exfiltration, and exploitation software.
NEW QUESTION # 216
Arrange the correct order that the URL classifications are processed within the system.
Answer:
Explanation:
NEW QUESTION # 217
Given the cyber-attack lifecycle diagram identify the stage in which the attacker can run malicious code against a vulnerability in a targeted machine.
- A. Act on the Objective
- B. Reconnaissance
- C. Exploitation
- D. Installation
Answer: C
NEW QUESTION # 218
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two.)
- A. DoS Protection profile
- B. QoS profile
- C. Zone Protection profile
- D. DoS Protection policy
Answer: A,C
Explanation:
Explanation
Explanation/Reference:
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-profiles
NEW QUESTION # 219
Which two features can be used to tag a user name so that it is included in a dynamic user group? (Choose two)
- A. XML API
- B. User-ID Windows-based agent
- C. GlobalProtect agent
- D. log forwarding auto-tagging
Answer: B,C
NEW QUESTION # 220 
An administrator is updating Security policy to align with best practices.
Which Policy Optimizer feature is shown in the screenshot below?
- A. New App Viewer
- B. Rules without App Controls
- C. Rule Usage
- D. Unused Unused Apps
Answer: C
NEW QUESTION # 221
An administrator wants to create a No-NAT rule to exempt a flow from the default NAT rule. What is the best way to do this?
- A. Create a Security policy rule to allow the traffic.
- B. Create a static NAT rule translating to the destination interface.
- C. Create a static NAT rule with an application override.
- D. Create a new NAT rule with the correct parameters and leave the translation type as None
Answer: D
NEW QUESTION # 222
Match the Cyber-Attack Lifecycle stage to its correct description.
Answer:
Explanation:
NEW QUESTION # 223
Given the topology, which zone type should interface E1/1 be configured with?
- A. Layer3
- B. Tunnel
- C. Tap
- D. Virtual Wire
Answer: C
NEW QUESTION # 224
A network administrator creates an intrazone security policy rule on a NGFW. The source zones are set to IT. Finance, and HR.
To which two types of traffic will the rule apply? (Choose two.)
- A. Within zone HR
- B. Within zone IT
- C. Between zone IT and zone HR
- D. Between zone IT and zone Finance
Answer: A,B
Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTHCA0
NEW QUESTION # 225
Order the steps needed to create a new security zone with a Palo Alto Networks firewall.
Answer:
Explanation:
Explanation
Step 1 - Select network tab
Step 2 - Select zones from the list of available items
Step 3 - Select Add
Step 4 - Specify Zone Name
Step 5 - Specify Zone Type
Step 6 - Assign interfaces as needed
NEW QUESTION # 226
To protect against illegal code execution, which Security profile should be applied?
- A. Vulnerability Protection profile on allowed traffic
- B. Vulnerability Protection profile on denied traffic
- C. Antivirus profile on allowed traffic
- D. Antivirus profile on denied traffic
Answer: A
Explanation:
You do not create security profiles on Denied Rules. Having security profiles on denied rules will just eat up CPU. It is not needed and there is no benefits
NEW QUESTION # 227
Which administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server. Which security profile components will detect and prevent this threat after the firewall`s signature database has been updated?
- A. antivirus profile applied to outbound security policies
- B. data filtering profile applied to inbound security policies
- C. vulnerability profile applied to inbound security policies
- D. data filtering profile applied to outbound security policies
Answer: D
NEW QUESTION # 228
By default, which action is assigned to the intrazone-default rule?
- A. Allow
- B. Deny
- C. Reset-client
- D. Reset-server
Answer: A
NEW QUESTION # 229
Actions can be set for which two items in a URL filtering security profile? (Choose two.)
- A. Custom URL Categories
- B. PAN-DB URL Categories
- C. Allow List
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/url-filtering-concepts/url-filtering-profile-actions - D. Block List
Answer: C,D
NEW QUESTION # 230
......
Practice PCNSA Questions With Certification guide Q&A from Training Expert PracticeDump: https://testking.practicedump.com/PCNSA-exam-questions.html