Get ready to pass the PCNSE Exam right now using our PCNSE PAN-OS Exam Package
A fully updated 2023 PCNSE Exam Dumps exam guide from training expert PracticeDump
To pass the PCNSE exam, candidates must demonstrate their ability to design, deploy, administer, maintain, and troubleshoot Palo Alto Networks security solutions. PCNSE exam is based on the latest version of the Palo Alto Networks PAN-OS 10.0, which is a next-generation firewall that provides advanced threat prevention capabilities, including intrusion prevention, URL filtering, and malware analysis.
NEW QUESTION # 44
A network administrator is trying to prevent domain username and password submissions to phishing sites on some allowed URL categories Which set of steps does the administrator need to take in the URL Filtering profile to prevent credential phishing on the firewall?
- A. Choose the URL categories on Site Access column and set action to block Click the User credential Detection tab and select IP User Mapping Commit
- B. Choose the URL categories in the User Credential Submission column and set action to block Select the User credential Detection tab and select Use Domain Credential Filter Commit
- C. Choose the URL categories in the User Credential Submission column and set action to block Select the User credential Detection tab and select use IP User Mapping Commit
- D. Choose the URL categories in the User Credential Submission column and set action to block Select the URL filtering settings and enable Domain Credential Filter Commit
Answer: C
NEW QUESTION # 45
What are three valid qualifiers for a Decryption Policy Rule match? (Choose three.)
- A. Destination Zone
- B. Custom URL Category
- C. Source Interface
- D. App-ID
- E. User-ID
Answer: A,B,E
Explanation:
Explanation
The valid qualifiers for a Decryption Policy Rule match are:
* Source Zone
* Destination Zone
* Source Address
* Destination Address
* Source User
* Destination User
* Source Region
* Destination Region
* Service/URL Category
* Custom URL Category
* URL Filtering Profile
Therefore, out of the options given, Destination Zone, Custom URL Category, and User-ID are valid qualifiers. References:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-decryption-policies.html
NEW QUESTION # 46
An engines must configure the Decryption Broker feature To which router must the engineer assign the decryption forwarding interfaces that are used m the Decryption Broker security Chain?
- A. a virtual router that has no additional interfaces for passing data-plane traffic and no other configured routes than those used in for the security chain
- B. the default virtual router (If there is no default virtual router the engineer must create one during setup)
- C. the virtual router that routes the traffic that the Decryption Broker security chain inspects
- D. a virtual router that is configured with at least one dynamic routing protocol and has at least one entry in the RIB
Answer: C
NEW QUESTION # 47
A customer has an application that is being identified as unknown-tcp for one of their custom PostgreSQL database connections.
Which two configuration options can be used to correctly categorize their custom database application?
(Choose two.)
- A. Custom Service object.
- B. Custom application.
- C. Application Override policy.
- D. Security policy to identify the custom application.
Answer: B,C
Explanation:
Explanation/Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clc6CAC
NEW QUESTION # 48
Which two statements correctly describe Session 380280? (Choose two.)
- A. The session went through SSL decryption processing.
- B. The application has been identified as web-browsing.
- C. The session has ended with the end-reason unknown.
- D. The session did not go through SSL decryption processing.
Answer: A,B
NEW QUESTION # 49
In SSL Forward Proxy decryption, which two certificates can be used for certificate signing? (Choose two.)
- A. enterprise CA certificate
- B. server certificate
- C. client certificate
- D. self-signed CA certificate
- E. wildcard server certificate
Answer: A,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-forward-proxy.html
NEW QUESTION # 50
A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone which options differentiates multiple VLAN into separate zones?
- A. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the Tag Allowed" field of the V-Wire object. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each iinterface/sub interface to a unique zone.
- B. Create V-Wire objects with two V-Wire interfaces and define a range of "0-4096 in the "Tag Allowed" field of the V-Wire object.
- C. Create Layer 3 subinterfaces that are each assigned tA. single VLAN ID and a common virtual router.
The physical Layer 3 interface would handle untagged traffic. Assign each interface/subinterface tA.
unique zone. Do not assign any interface an IP address. - D. Create VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/sub interface to a unique zone.
Answer: A
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire- Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic.You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet.
NEW QUESTION # 51
An administrator can not see any Traffic logs from the Palo Alto Networks NGFW in Panorama reports. The configuration problem seems to be on the firewall. Which settings, if configured incorrectly, most likely would stop only Traffic logs from being sent from the NGFW to Panorama?
A)

C)
D)
- A. Option A
- B. Option C
- C. Option D
- D. Option B
Answer: B
NEW QUESTION # 52
An administrator has enabled OSPF on a virtual router on the NGFW. OSPF is not adding new routes to the virtual router. Which two options enable the administrator to troubleshoot this issue? (Choose two.)
- A. View Runtime Stats in the virtual router.
- B. Add a redistribution profile to forward as BGP updates.
- C. View System logs.
- D. Perform a traffic pcap at the routing stage.
Answer: A,D
Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldcCAC
NEW QUESTION # 53
Which menu item enables a firewall administrator to see details about traffic that is currently active through the NGFW?
- A. Session Browser
- B. System Logs
- C. ACC
- D. App Scope
Answer: A
Explanation:
Explanation
Session browser. However ACC will show metadata on traffic through the firewall, and you can create some helpful on-the-fly reports, but these will not provide deep detail. Alternatively for more detail you can go to Monitor > Traffic and filter for relevant sessions.
NEW QUESTION # 54
If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is pushed?
- A. The administrator will be promoted to choose the settings for that chosen firewall.
- B. Depending on the firewall location, Panorama decides with settings to send.
- C. All the settings configured in all templates.
- D. The settings assigned to the template that is on top of the stack.
Answer: D
Explanation:
Reference:
https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/manage- templates-and-template-stacks/configure-a-template-stack
NEW QUESTION # 55
As a best practice, which URL category should you target first for SSL decryption?
- A. Financial Services
- B. Health and Medicine
- C. High Risk
- D. Online Storage and Backup
Answer: C
Explanation:
https://docs.paloaltonetworks.com/best-practices/8-1/decryption-best-practices/decryption-best- practices/plan-ssl-decryption-best-practice-deployment.html Phase in decryption. Plan to decrypt the riskiest traffic first (URL Categories most likely to harbor malicious traffic, such as gaming or high-risk)
NEW QUESTION # 56
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- A. Restful API or the VMware API on the firewall or on the User-ID agent
- B. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
- C. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)
- D. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
Answer: D
Explanation:
To mitigate the challenges of scale, lack of flexibility, and performance, network architectures today allow for virtual machines (VMs) and applications to be provisioned, changed, and deleted on demand. This agility, though, poses a challenge for security administrators because they have limited visibility into the IP addresses of the dynamically provisioned VMs and the plethora of applications that can be enabled on these virtual resources. Firewalls (hardware-based and VM- Series models) support the ability to register IP addresses, IP sets (IP ranges and subnets), and tags dynamically. The IP addresses and tags can be registered on the firewall directly or from Panorama. You can also automatically remove tags on the source and destination IP addresses included in a firewall log.
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/register-ip-addresses-and- tags-dynamically.html
NEW QUESTION # 57
Which Zone Pair and Rule Type will allow a successful connection for a user on the internet zone to a web server hosted in the DMZ zone? The web server is reachable using a destination Nat policy in the Palo Alto Networks firewall.
- A. Zone Pair:
Source Zone: Internet
Destination Zone: DMZ
Rule Type:
"intrazone" or "universal" - B. Zone Pair:
Source Zone: Internet
Destination Zone: Internet
Rule Type:
"intrazone" - C. Zone Pair:
Source Zone: Internet
Destination Zone: DMZ
Rule Type:
"intrazone" - D. Zone Pair:
Source Zone: Internet
Destination Zone: Internet
Rule Type:
"intrazone" or "universal"
Answer: A
NEW QUESTION # 58
A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas)
i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system )
ii. Enterpnse-Untrusted-CA, which is verified as Forward Untrust Certificate
iii. Enterprise-lntermediate-CA
iv. Enterprise-Root-CA which is verified only as Trusted Root CA
An end-user visits https //www example-website com/ with a server certificate Common Name (CN) www example-website com The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall
The end-user's browser will show that the certificate for www.example-website.com was issued by which of the following?
- A. Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
- B. Enterprise-Untrusted-CA which is a self-signed CA
- C. Enterprise-Root-CA which is a self-signed CA
- D. Enterprise-Trusted-CA which is a self-signed CA
Answer: B
NEW QUESTION # 59
An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled.
What must be verified to upgrade the firewalls to the most recent version of PAN-OS?software?
- A. Antivirus update package.
- B. User-ID agent.
- C. Applications and Threats update package.
- D. WildFire update package.
Answer: C
Explanation:
Dependencies
Before you upgrade, make sure the firewall is running a version of app + threat (content version) that meets the minimum requirement of the new PAN-OS (see release notes). We recommend always running the latest version of content to ensure the most accurate and effective protections are being applied.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRrCAK
NEW QUESTION # 60
Which two features can be used to tag a username so that it is included in a dynamic user group? (Choose two)
- A. XML API
- B. log forwarding auto-tagging
- C. User-ID Windows-based agent
- D. GlobafProtect agent
Answer: B,C
Explanation:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/register-ip-addresses-and-tags-dynamically.html You can enable the dynamic registration process using any of the following options:
User-ID agent for Windows*
VM Information Sources
Panorama Plugin
VMware Service Manager
XML API*
Auto-Tag*
https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnse-study-guide.pdf Usernames can also be tagged and untagged using the auto-tagging feature in a Log Forwarding Profile. You also can program another utility to invoke PAN-OS XML API commands to tag or untag usernames.
NEW QUESTION # 61
Which logs enable a firewall administrator to determine whether a session was decrypted?
- A. Security Policy
- B. Correlated Event
- C. Traffic
- D. Decryption
Answer: C
NEW QUESTION # 62
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against
external hosts attempting to exploit a flaw in an operating system on an internal system.
Which Security Profile type will prevent this attack?
- A. URL Filtering
- B. Anti-Spyware
- C. Antivirus
- D. Vulnerability Protection
Answer: D
Explanation:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/objects/
objects-security-profiles-vulnerability-protection
NEW QUESTION # 63
Which protocol is supported by GlobalProtect Clientless VPN?
- A. FTP
- B. RDP
- C. HTTPS
- D. SSH
Answer: B
NEW QUESTION # 64
Which User-ID method maps IP addresses to usernames for users connecting through an 802.1x-enabled wireless network device that has no native integration with PAN-OS® software?
- A. Server Monitoring
- B. Port Mapping
- C. XML API
- D. Client Probing
Answer: C
Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts
NEW QUESTION # 65
If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is pushed?
- A. The administrator will be promoted to choose the settings for that chosen firewall.
- B. Depending on the firewall location, Panorama decides with settings to send.
- C. All the settings configured in all templates.
- D. The settings assigned to the template that is on top of the stack.
Answer: D
Explanation:
Panorama evaluates the templates listed in a stack configuration from top to bottom, with higher templates having priority.
https://docs.paloaltonetworks.com/panorama/7-1/panorama-admin/panorama- overview/templates-and-template-stacks
NEW QUESTION # 66
Click the Exhibit button below,

A firewall has three PBF rules and a default route with a next hop of 172.20.10.1 that is configured in the default VR. A user named Will has a PC with a 192.168.10.10 IP address. He makes an HTTPS connection to
172.16.10.20.
Which is the next hop IP address for the HTTPS traffic from Will's PC?
- A. 172.20.10.1
- B. 172.20.40.1
- C. 172.20.20.1
- D. 172.20.30.1
Answer: C
NEW QUESTION # 67
Which three firewall multi-factor authentication factors are supported by PAN-OS? (Choose three)
- A. Short message service
- B. One-Time Password
- C. SSH key
- D. Push
- E. User logon
Answer: B,D,E
Explanation:
Explanation
According to Palo Alto Networks documentation , multi-factor authentication (MFA) is a method of verifying a user's identity using two or more factors, such as something they know, something they have, or something they are.
The firewall supports MFA for administrative access, GlobalProtect VPN access, and Captive Portal access.
The firewall can integrate with external MFA providers such as RSA SecurID, Duo Security, or Okta Verify.
The three firewall MFA factors that are supported by PAN-OS are:
User logon: This is something the user knows, such as a username and password.
One-Time Password: This is something the user has, such as a code generated by an app or sent by email or SMS.
Push: This is something the user is, such as a biometric verification or a device approval.
NEW QUESTION # 68
......
Master 2023 Latest The Questions PCNSE PAN-OS and Pass PCNSE Real Exam!: https://testking.practicedump.com/PCNSE-exam-questions.html