Exam Details

  • Exam Code
    :PCNSA
  • Exam Name
    :Palo Alto Networks Certified Network Security Administrator (PCNSA)
  • Certification
    :Palo Alto Networks Certifications
  • Vendor
    :Palo Alto Networks
  • Total Questions
    :443 Q&As
  • Last Updated
    :

Palo Alto Networks Palo Alto Networks Certifications PCNSA Questions & Answers

  • Question 301:

    What must exist in order for the firewall to route traffic between Layer 3 interfaces?

    A. Virtual router

    B. Virtual wires

    C. Traffic Distribution profile

    D. VLANs

  • Question 302:

    A NetSec manager was asked to create a new firewall administrator profile with customized privileges. The new firewall administrator must be able to download TSF File and Starts Dump File but must not be able to reboot the device. Where does the NetSec manager go to configure the new firewall administrator role profile?

    A. Device > Admin Roles > Add > XML API > Configuration

    B. Device > Admin Roles > Add > XML API > Operational Request

    C. Device > Admin Roles > Add > Web UI > Support

    D. Device > Admin Roles > Add > Web UI > Operations

  • Question 303:

    To enable DNS sinkholing, which two addresses should be reserved? (Choose two.)

    A. MAC

    B. IPv6

    C. Email

    D. IPv4

  • Question 304:

    In which threat profile object would you configure the DNS Security service?

    A. Anti-Spyware

    B. URL Filtering

    C. Antivirus

    D. WildFire

  • Question 305:

    An organization has some applications that are restricted for access by the Human Resources Department only, and other applications that are available for any known user in the organization. What object is best suited for this configuration?

    A. Application Group

    B. Tag

    C. External Dynamic List

    D. Application Filter

  • Question 306:

    Which two configurations does an administrator need to compare in order to see differences between the active configuration and potential changes if committed? (Choose two.)

    A. Device state

    B. Active

    C. Candidate

    D. Running

  • Question 307:

    DNS exceptions can be set under which Security profile?

    A. Data Filtering

    B. URL Filtering

    C. Anti-Spyware

    D. Antivirus

  • Question 308:

    An administrator would like to follow the best-practice approach to log the traffic that traverses the firewall. What action should they take?

    A. Enable both Log at Session Start and Log at Session End.

    B. Enable Log at Session End.

    C. Enable Log at Session Start.

    D. Disable all logging options.

  • Question 309:

    Which two protocols are available on a Palo Alto Networks Firewall Interface Management Profile? (Choose two.)

    A. HTTPS

    B. RDP

    C. SCP

    D. SSH

  • Question 310:

    An administrator wants to filter access to www.paloaltonetworks.com via a custom URL category. Which syntax would match this?

    A. https://paloaltonetworks.com

    B. #.paloaltonetworks.com

    C. http://paloaltonetworks.com

    D. *.paloaltonetworks.com

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCNSA exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.