An administrator has configured PAN-OS SD-WAN and has received a request to find out the reason for a session failover for a session that has already ended. Where would you find this in Panorama or firewall logs?
A. Traffic Logs B. System Logs C. Session Browser D. You cannot find failover details on closed sessions
You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles. For Which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three)
A. High B. Medium C. Critical D. Informational E. Low
A. High B. Medium C. Critical
Explanation
The best practice Anti-Spyware profile retains the default Action to reset the connection when the firewall detects a medium, high, or critical severity threat, and enables single packet capture (PCAP) for those threats.
Question 123:
Review the screenshot of the Certificates page.
An administrator for a small LLC has created a series of certificates as shown, to use for a planned Decryption roll out. The administrator has also installed the self-signed root certificate in all client systems.
When testing, they noticed that every time a user visited an SSL site, they received unsecured website warnings.
What is the cause of the unsecured website warnings?
A. The forward untrust certificate has not been signed by the self-singed root CA certificate. B. The forward trust certificate has not been installed in client systems. C. The self-signed CA certificate has the same CN as the forward trust and untrust certificates. D. The forward trust certificate has not been signed by the self-singed root CA certificate.
D. The forward trust certificate has not been signed by the self-singed root CA certificate.
Explanation
The cause of the unsecured website warnings is that the forward trust certificate has not been signed by the self-signed root CA certificate. The forward trust certificate is used by the firewall to generate a copy of the server certificate for outbound SSL decryption (SSL Forward Proxy). The firewall signs the copy with the forward trust certificate and presents it to the client. The client then verifies the signature using the public key of the CA that issued the forward trust certificate. If the client does not trust the CA, it will display a warning message. Therefore, the forward trust certificate must be signed by a CA that is trusted by the client. In this case, the administrator has installed the self-signed root CA certificate in all client systems, so this CA should be used to sign the forward trust certificate. However, as shown in the screenshot, the forward trust certificate has a different issuer than the self-signed root CA certificate, which means it has not been signed by it. This causes the client to reject the signature and show a warning message. To fix this issue, the administrator should generate a new forward trust certificate and sign it with the self-signed root CA certificate12.
References: Keys and Certificates for Decryption Policies, How to Configure SSL Decryption
Question 124:
An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)
A. URL categories B. source users C. source and destination IP addresses D. App-ID E. GlobalProtect HIP
A. URL categories B. source users C. source and destination IP addresses
Explanation
Question 125:
A firewall has been assigned to a new template stack that contains both "Global" and "Local" templates in Panorama, and a successful commit and push has been performed. While validating the configuration on the local firewall, the engineer
discovers that some settings are not being applied as intended.
The setting values from the "Global" template are applied to the firewall instead of the "Local" template that has different values for the same settings.
What should be done to ensure that the settings in the "Local" template are applied while maintaining settings from both templates?
A. Move the "Global" template above the "Local" template in the template stack. B. Perform a commit and push with the "Force Template Values" option selected. C. Move the "Local" template above the "Global" template in the template stack. D. Override the values on the local firewall and apply the correct settings for each value.
C. Move the "Local" template above the "Global" template in the template stack.
Explanation
Question 126:
How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?
A. Create a custom application, define its properties and signatures, and ensure all scanning options in the "Advanced" tab are unchecked B. Create a custom application, define its properties, then create an application override and reference the custom application C. Create a new security rule specifically for the affected traffic, but do not reference any Security Profiles inside the rule D. Create a new security rule specifically for the affected traffic, and select "Disable Server Response Inspection"
B. Create a custom application, define its properties, then create an application override and reference the custom application
Explanation
An application override (Option B) bypasses App-ID and content inspection by forcing the firewall to classify traffic as the custom app, skipping deeper analysis. The custom app's properties (e.g., ports) define the match, and no security profiles are applied.
An engineer is monitoring an active/active high availability (HA) firewall pair.
Which HA firewall state describes the firewall that is experiencing a failure of a monitored path?
A. Initial B. Passive C. Active-secondary D. Tentative
D. Tentative
Explanation
In an active/active high availability (HA) firewall pair, when a firewall experiences a failure of a monitored path, it enters the "Tentative" state. This state indicates that the firewall is synchronizing sessions and configurations from its peer due to a failure or a change in monitored objects such as a link or path. The firewall in this state is not fully functional but is working towards resuming normal operations by syncing with its peer. Firewall Stuck in Initial (Leaving Suspended State) Palo Alto Networks
Given the Sample Log Forwarding Profile shown, which two statements are true? (Choose two.)
A. All traffic from source network 192.168.100.0/24 is sent to an external syslog target. B. All threats are logged to Panorama. C. All traffic logs from RFC 1918 subnets are logged to Panorama / Cortex Data Lake. D. All traffic from source network 172.12.0.0/24 is sent to Panorama / Cortex Data Lake.
A. All traffic from source network 192.168.100.0/24 is sent to an external syslog target. C. All traffic logs from RFC 1918 subnets are logged to Panorama / Cortex Data Lake.
Explanation
B is not correct as it is sent externally not to Panorama D is not correct as it is 172.12 (not 172.16)
Question 129:
Which log type would provide information about traffic blocked by a Zone Protection profile?
A. Data Filtering B. IP-Tag C. Traffic D. Threat
D. Threat
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC Zone Protection profile is a set of security policies that you can apply to an interface or zone to protect it from reconnaissance, flooding, brute force, and other types of attacks. The log type that would provide information about traffic blocked by a Zone Protection profile is Threat4. This log type records events such as packet-based attacks, spyware, viruses, vulnerability exploits, and URL filtering.
Question 130:
A security engineer needs to mitigate packet floods that occur on a set of servers behind the internet facing interface of the firewall. Which Security Profile should be applied to a policy to prevent these packet floods?
A. URL Filtering profile B. Vulnerability Protection profile C. Data Filtering profile D. DoS Protection profile
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Palo Alto Networks exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your PCNSE exam preparations
and Palo Alto Networks certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.