Skip to main content

PCNSC Real Exam Questions

Palo Alto Networks Certified Network Security Consultant (PCNSC)

141 questions available · Page 1 of 15

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which CLI command is used to verify the high availability state of a Palo Alto Networks firewall?

  1. A

    show high-availability state

  2. B

    show ha state

  3. C

    show ha status

  4. D

    show high-availability status

Show answer and explanation

Correct answer: C

Question 2 Multiple choice

Winch three steps will reduce the CPU utilization on the management plane? (Choose three. )

  1. A

    Disable predefined reports.

  2. B

    Reduce the traffic being decrypted by the firewall.

  3. C

    Disable SNMP on the management interface.

  4. D

    Application override of SSL application.

Show answer and explanation

Correct answers: A, B, C

Question 3 Single choice

When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.

What will be the destination IP Address in that log entry?

  1. A

    The IP Address of sinkhole.paloaltonetworks.com

  2. B

    The IP Address of the command-and-control server

  3. C

    The IP Address specified in the sinkhole configuration

  4. D

    The IP Address of one of the external DNS servers identified in the anti-spyware database

Show answer and explanation

Correct answer: C

Explanation

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Verify-DNS-Sinkhole-Function-is-Working/ta-p/65864

Question 4 Single choice

What is the purpose of the WildFire Analysis Profile in a security policy?

  1. A

    To specify which files are sent to WildFire for analysis

  2. B

    To configure the WildFire subscription settings

  3. C

    To enable WildFire to analyze all network traffic

  4. D

    To define the action to be taken on files analyzed by WildFire

Show answer and explanation

Correct answer: A

Question 5 Single choice

What will be the egress interface if the traffic's ingress interface is Ethernet 1/6 sourcing form 192.168.11.3
and to the destination 10.46.41.113.during the.

  1. A

    ethernet 1/6

  2. B

    ethernet 1/5

  3. C

    ethernet 1/3

  4. D

    ethernet 1/7

Show answer and explanation

Correct answer: C

Question 6 Drag & drop

DRAG DROP

In Panorama the web interface displays the security rules in evaluation order Organize the security rules m the order in which they will be evaluated?

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

In Panorama, security rules are evaluated in a specific order to determine which rule applies to the traffic.
The correct evaluation order is as follows: Shared pre-rules(evaluated first)
Device group pre-rules(evaluated second)
Local firewall rules(evaluated third)
Device group post-rules(evaluated fourth)
Shared post-rules(evaluated fifth)

This order ensures that the most generic rules (shared across all devices) are evaluated first, followed by more specific rules at the device group and local firewall levels, and then the post-rules.

References:
Palo Alto Networks - Panorama Admin Guide: (https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/policy/policy-precedence-and-evaluation-order)
Palo Alto Networks - Security Policy Evaluation: (https://knowledgebase.paloaltonetworks.com)

Question 7 Single choice

In High Availability, which information is transferred via the HA data link?

  1. A

    heartbeats

  2. B

    HA state information

  3. C

    session information

  4. D

    User-ID information

Show answer and explanation

Correct answer: C

Question 8 Single choice

In Panorama, what is the correct order of precedence for security policies?

  1. A

    Device group pre-rules, shared pre-rules, local rules, device group post-rules, shared post-rules

  2. B

    Shared pre-rules, device group pre-rules, local rules, shared post-rules, device group post-rules

  3. C

    Shared pre-rules, device group pre-rules, local rules, device group post-rules, shared post-rules

  4. D

    Device group pre-rules, shared pre-rules, local rules, shared post-rules, device group post-rules

Show answer and explanation

Correct answer: C

Question 9 Multiple choice

An administrator has enabled OSPF on a virtual router on the NGFW OSPF is not adding new routes to the virtual router.

Which two options enable the administrator top troubleshoot this issue? (Choose two.)

  1. A

    Perform a traffic pcap at the routing stage.

  2. B

    View System logs.

  3. C

    Add a redistribution profile to forward as BGP updates.

  4. D

    View Runtime Status virtual router.

Show answer and explanation

Correct answers: B, D

Question 10 Single choice

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-number or bacon out to eternal command-and-control (C2) servers.

Which Security Profile type will prevent these behaviors?

  1. A

    Vulnerability Protection

  2. B

    Antivirus

  3. C

    Wildfire

  4. D

    Anti-Spyware

Show answer and explanation

Correct answer: D