Exam Details

  • Exam Code
    :PCNSE
  • Exam Name
    :Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 11.x
  • Certification
    :Palo Alto Certifications and Accreditations
  • Vendor
    :Palo Alto Networks
  • Total Questions
    :765 Q&As
  • Last Updated
    :

Palo Alto Networks Palo Alto Certifications and Accreditations PCNSE Questions & Answers

  • Question 1:

    When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?

    A. To enable Gateway authentication to the Portal

    B. To enable Portal authentication to the Gateway

    C. To enable user authentication to the Portal

    D. To enable client machine authentication to the Portal

  • Question 2:

    An administrator wants a new Palo Alto Networks NGFW to obtain automatic application updates daily, so it is configured to use a scheduler for the application database. Unfortunately, they required the management network to be isolated so that it cannot reach the internet. Which configuration will enable the firewall to download and install application updates automatically?

    A. Configure a Policy Based Forwarding policy rule for the update server IP address so that traffic sourced from themanagement interfaced destined for the update servers goes out of the interface acting as your internet connection.

    B. Configure a security policy rule to allow all traffic to and from the update servers.

    C. Download and install application updates cannot be done automatically if the MGT port cannot reach the internet.

    D. Configure a service route for Palo Alto networks services that uses a dataplane interface that can route traffic to the internet, and create a security policy rule to allow the traffic from that interface to the update servers if necessary.

  • Question 3:

    Where can an administrator see both the management plane and data plane CPU utilization in the WebUI?

    A. System log

    B. CPU Utilization widget

    C. Resources widget

    D. System Utilization log

  • Question 4:

    Which is not a valid reason for receiving a decrypt-cert-validation error?

    A. Unsupported HSM

    B. Unknown certificate status

    C. Client authentication

    D. Untrusted issuer

  • Question 5:

    Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)

    A. Create a no-decrypt Decryption Policy rule.

    B. Configure an EDL to pull IP addresses of known sites resolved from a CRL.

    C. Create a Dynamic Address Group for untrusted sites

    D. Create a Security Policy rule with vulnerability Security Profile attached.

    E. Enable the "Block sessions with untrusted issuers" setting.

  • Question 6:

    Refer to the exhibit.

    Which certificates can be used as a Forwarded Trust certificate?

    A. Certificate from Default Trust Certificate Authorities

    B. Domain Sub-CA

    C. Forward_Trust

    D. Domain-Root-Cert

  • Question 7:

    What file type upload is supported as part of the basic WildFire service?

    A. PE

    B. BAT

    C. VBS

    D. ELF

  • Question 8:

    Which protection feature is available only in a Zone Protection Profile?

    A. SYN Flood Protection using SYN Flood Cookies

    B. ICMP Flood Protection

    C. Port Scan Protection

    D. UDP Flood Protections

  • Question 9:

    Which virtual router feature determines if a specific destination IP address is reachable?

    A. Heartbeat Monitoring

    B. Failover

    C. Path Monitoring

    D. Ping-Path

  • Question 10:

    A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.

    Which VPN configuration would adapt to changes when deployed to the future site?

    A. Preconfigured GlobalProtect satellite

    B. Preconfigured GlobalProtect client

    C. Preconfigured IPsec tunnels

    D. Preconfigured PPTP Tunnels

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCNSE exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.