100% Pass Guaranteed Accurate PCNSC Answers 365 Days Free Updates [Q37-Q61]

Share

100% Pass Guaranteed Accurate PCNSC Answers 365 Days Free Updates

PCNSC DUMPS Q&As with Explanations Verified & Correct Answers

NEW QUESTION 37
Which two methods can be configured to validate the revocation status of a certificate? (Choose two)

  • A. Cert-Validation-Profile
  • B. CRL
  • C. SSL /TLS Service Profile
  • D. CRT
  • E. OCSP

Answer: A,D

 

NEW QUESTION 38
In High Availability, which information is transferred via the HA data link?

  • A. HA state information
  • B. heartbeats
  • C. session information
  • D. User-ID information

Answer: C

 

NEW QUESTION 39
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS software, the administrator enables logs forwarding from the firewalls to panorama Pre-existing logs from the firewall are not appearing in Panorama.
Which action would enables the firewalls to send their preexisting logs to Panorama?

  • A. Use the import option to pull logs panorama.
  • B. The- log database will need to be exported from the firewall and manually imported into Panorama.
  • C. A CLI command will forward the pre-existing logs to Panorama.
  • D. Use the ACC to consolidate pre-existing logs.

Answer: C

 

NEW QUESTION 40
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator Troubleshoot this issue? (Choose two.)

  • A. View the System logs and look for error messages about BGP
  • B. View the ACC lab to isolate routing issues.
  • C. Perform a traffic pcap on the NGFW lo see any BGP problems
  • D. View the Runtime Stats and look for problems with BGP configuration

Answer: B,D

 

NEW QUESTION 41
Which three options are supposed in HA Lite? (Choose three.)

  • A. Configuration synchronization
  • B. synchronization of IPsec security associations
  • C. session synchronization
  • D. active/passive deployment
  • E. Virtual link

Answer: A,B,D

 

NEW QUESTION 42
Which administrative authentication method supports authorization by an external service?

  • A. Certification
  • B. SSH keys
  • C. RADIUS
  • D. LDAP

Answer: B

 

NEW QUESTION 43
The firewall identified a popular application as a unknown-tcp. Which options are available to identify the application? (Choose two.)

  • A. Submit an App-ID request to Palo Alto Networks.
  • B. Create a custom application.
  • C. Create a customer object for the customer application server to identify the custom application.
  • D. Create a Security policy to identify the customer application.

Answer: B,C

 

NEW QUESTION 44
An administrator logs in to the Palo Alto Networks NGFW and reports and reports that the WebUI is missing the policies tab. Which profile is the cause of the missing policies tab?

  • A. Admin Role
  • B. Authorization
  • C. WebUI
  • D. Authentication

Answer: A

 

NEW QUESTION 45
Which PAN-OS policy must you configure to force a user to provide additional credential before he is allowed to access an internal application that contains highly sensitive business data?

  • A. Decryption policy
  • B. Application Override policy
  • C. Authentication policy
  • D. Security policy

Answer: C

 

NEW QUESTION 46
An administrator pushes a new configuration from panorama to a pair of firewalls that are configured as active/passive HA pair.
Which NGFW receives the configuration from panorama?

  • A. the passive firewall, which then synchronizes to the active firewall
  • B. the active firewall, which then synchronizes to the passive firewall
  • C. both the active and passive firewalls, which then synchronizes with each other
  • D. both the active and passive firewalls independently, with no synchronization afterward

Answer: C

 

NEW QUESTION 47
What are two benefits of nested device groups in panorama? (Choose two )

  • A. overwrites local firewall configuration
  • B. all device groups inherit setting from the Shared group
  • C. reuse of the existing Security policy rules and objects
  • D. requires configuration both function and location for every device

Answer: B,D

 

NEW QUESTION 48
An administrator sees several inbound sessions identified as unknown tcp in the Traffic logs. The administrator determines that these sessions are from external users accessing the company's propriety accounting application. The administrator wants to reliability identity this as their accounting application and to scan this traffic for threats.
Which option would achieve this result?

  • A. Create a custom App-ID and enable scanning on the advanced tab.
  • B. Create an Application Override policy
  • C. Create a custom App-ID and use the "ordered condition cheek box.
  • D. Create an Application Override policy and a custom threat signature for the application.

Answer: D

 

NEW QUESTION 49
Which version of Global Protect supports split tunneling based on destination domain, client process, and HTTP/HTTPs video streaming application?

  • A. Glovbalprotect version 4.0 with PAn-OS 8.1
  • B. Glovbalprotect version 4.0 with PAn-OS 8.0
  • C. Glovbalprotect version 4.1 with PAn-OS 8.0
  • D. Glovbalprotect version 4.1 with PAn-OS 8.1

Answer: A

 

NEW QUESTION 50
An administrator has enabled OSPF on a virtual router on the NGFW OSPF is not adding new routes to the virtual router.
Which two options enable the administrator top troubleshoot this issue? (Choose two.)

  • A. Add a redistribution profile to forward as BGP updates.
  • B. View Runtime Status virtual router.
  • C. View System logs.
  • D. Perform a traffic pcap at the routing stage.

Answer: B,C

 

NEW QUESTION 51
What is exchanged through the HA2 link?

  • A. HA state information
  • B. hello heartbeats
  • C. User-ID in information
  • D. session synchronization

Answer: D

 

NEW QUESTION 52
A user's traffic traversing a Palo Alto Networks NGFW sometime can reach http//www company com At the session times out.
The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http //www company com.
How con the firewall be configured to automatically disable the PBF rule if the next hop goes down?

  • A. Configure path monitoring for tine next hop gateway on the default route in tin- virtual router.
  • B. Enable and configure a Link Monitoring Profile for the external interface of the firewall.
  • C. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question.
  • D. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.

Answer: D

 

NEW QUESTION 53
Which User-ID method should b configured to map addresses to usernames for users connected through a terminal server?

  • A. server monitoring
  • B. port mapping
  • C. XFF header
  • D. Client probing

Answer: B

 

NEW QUESTION 54
A web server is hosted in the DMZ and the server re configured to listen for income connections on TCP port
443. A Security policies rules allowing access from the Trust zone to the DMZ zone needs to be configured to allow web-browsing access. The web server host its contents over Traffic from Trust to DMZ is being decrypted with a Forward Proxy rule.
Which combination of service and application, and order of Security policy rules needs to be configured to allow cleaned web-browsing traffic to the server on tcp/443?

  • A. Rule# 1 application: ssl; service application-default: action allow
    Role # 2 application web browsing, service application default, action allow
  • B. Rule#1 application web-brows.no service application-default, action allow Rule #2 application ssl. Service application-default, action allow
  • C. Rule#1application: web-biows.no; service service-https action allow
    Rule#2 application ssl. Service application-default, action allow
  • D. Rule #1application web-browsing, service service imp action allow
    Rule #2 application ssl. service application -default, action allow

Answer: B

 

NEW QUESTION 55
Which three authentication faction factors does PAN-OS software support for MFA? (Choose three.)

  • A. Voice
  • B. SMS
  • C. Okta Adaptive
  • D. Push
  • E. Pull

Answer: A,D,E

 

NEW QUESTION 56
During the packet flow process, which two processes are performed in application identification? (Choose two.)

  • A. application override policy match
  • B. pattern based application identification
  • C. session application identified
  • D. Application changed from content inspection

Answer: A,C

 

NEW QUESTION 57
Winch three steps will reduce the CPU utilization on the management plane? (Choose three. ) Disable logging at session start in Security policies.

  • A. Reduce the traffic being decrypted by the firewall.
  • B. Application override of SSL application.
  • C. Disable predefined reports.
  • D. Disable SNMP on the management interface.

Answer: A,C,D

 

NEW QUESTION 58
Which processing order will be enabled when a panorama administrator selects the setting "Objects defined in ancestors will takes higher precedence?

  • A. Descendant objects, will take precedence over ancestor objects.
  • B. Ancestor will have precedence over descendant objects.
  • C. Ancestor objects will have precedence over other ancestor objects.
  • D. Descendant object will take precedence over other descendant objects.

Answer: B

 

NEW QUESTION 59
View the GlobalProtect configuration screen capture.
What is the purpose of this configuration?

  • A. It enables a Client to perform a reverse DNS lookup on 192 .168. 10 .1. to delect it is an internal client.
  • B. It forces the firewall to perform a dynamic DNS update, Which adds the internal gateway's hostname and IP address to the DNS server.
  • C. It forces an internal client to connect to an internal gateway at IP address 192 168 10 I.
  • D. It configures the tunnel address of all internal clients lo an IP address range starting at 192 168 10 1.

Answer: A

 

NEW QUESTION 60
What will be the egress interface if the traffic's ingress interface is Ethernet 1/6 sourcing form 192.168.11.3 and to the destination 10.46.41.113.during the.

  • A. ethernet 1/3
  • B. ethernet 1/6
  • C. ethernet 1/7
  • D. ethernet 1/5

Answer: A

 

NEW QUESTION 61
......

PCNSC dumps Exam Material with 74 Questions: https://www.testpassking.com/PCNSC-exam-testking-pass.html

PCNSC Questions and Answers Guarantee you Oass the Test Easily: https://drive.google.com/open?id=1lvDMbfq1dLewoNTtdojEjhFg9-5NxEBA