An administrator notices interface ethernet1/2 failed on the active firewall in an active I passive firewall high availability(HA) pair.
Based on the image below, what -if any -action was taken by the active firewall when the link failed?
A. No action was taken because interface ethernet1/1 did not fail. B. The active firewall failed over to the passive HA member due to an AE1 Link Group failure. C. No action was taken because Path Monitoring is disabled. D. The active firewall failed over to the passive HA member because "any" is selected for the Link Monitoring "Failure Condition".
A. No action was taken because interface ethernet1/1 did not fail.
Explanation
Question 212:
The following objects and policies are defined in a device group hierarchy
A. Option A B. Option B C. Option C D. Option D
A. Option A
Explanation
Question 213:
Which three firewall states are valid? (Choose three.)
A. Active B. Functional C. Pending D. Passive E. Suspended
The firewall team has been asked to deploy a new Panorama server and to forward all firewall logs to this server By default, which component of the Palo Alto Networks firewall architect is responsible for log forwarding and should be checked for early signs of overutilization?
A. Management plane CPU B. Dataplane CPU C. Packet buffers D. On-chip packet descriptors
A. Management plane CPU
Explanation
Question 215:
An ISP manages a Palo Alto Networks firewall with multiple virtual systems for its tenants.
Where on this firewall can the ISP configure unique service routes for different tenants?
A. Setup > Services > Virtual Systems > Set Location > Service Route Configuration > Inherit Global Service Route Configuration B. Setup > Services > Global > Service Route Configuration > Customize C. Setup > Services > Virtual Systems > Set Location > Service Route Configuration > Customize D. Setup > Services > Global > Service Route Configuration > Use Management Interface for all
C. Setup > Services > Virtual Systems > Set Location > Service Route Configuration > Customize
Explanation
The best option for the ISP to configure unique service routes for different tenants is to use the Setup > Services > Virtual Systems > Set Location > Service Route Configuration > Customize option on the firewall. This option allows the ISP to customize the service routes for each virtual system that represents a tenant. A service route is the path from the interface to the service on a server, such as DNS, email, or Panorama. By customizing the service routes for each virtual system, the ISP can ensure that each tenant uses a different interface or IP address to access these services. Option A is incorrect because it is used to inherit the global service route configuration for a virtual system, not to customize it. Option B is incorrect because it is used to customize the global service route configuration for all virtual systems, not for a specific one. Option D is incorrect because it is used to use the management interface for all service routes, not to customize them.
Question 216:
Which GlobalProtect gateway setting is required to enable split-tunneling by access route, destination domain, and application?
A. No Direct Access to local networks B. Satellite mode C. Tunnel mode D. IPSec mode
C. Tunnel mode
Explanation
To enable split-tunneling by access route, destination domain, and application, you need to configure a split tunnel based on the domain and application on your GlobalProtect gateway. This allows you to specify which domains and applications are included or excluded from the VPN tunnel.
Question 217:
What is the dependency for users to access services that require authentication?
A. An Authentication profile that includes those services B. Disabling the authentication timeout C. An authentication sequence that includes those services D. A Security policy allowing users to access those services
D. A Security policy allowing users to access those services
Explanation
Question 218:
An administrator has users accessing network resources through Citrix XenApp 7 x. Which User-ID mapping solution will map multiple users who are using Citrix to connect to the network and access resources?
A. Client Probing B. Terminal Services agent C. GlobalProtect D. Syslog Monitoring
An enterprise has a large Palo Alto Networks footprint that includes onsite firewalls and Prisma Access for mobile users, which is managed by Panorama The enterprise already uses GlobalProtect with SAML authentication to obtain iP-touser mapping information.
However information Security wants to use this information in Prisma Access for policy enforcement based on group mapping Information Security uses on-prermses Active Directory (AD) but is uncertain about what is needed for Prisma Access to learn groups from AD.
How can portaes based on group mapping be learned and enforced in Prisma Access?
A. Configure Prisma Access to learn group mapping via SAML assertion B. Assign a master device in Panorama through which Prisma Access learns groups C. Set up group mapping redistribution between an onsite Palo Alto Networks firewall and Prisma Access D. Create a group mapping configuration that references an LDAP profile that points to on-premises domain controllers
B. Assign a master device in Panorama through which Prisma Access learns groups
Explanation
Step 3: Allow Panorama to use group mappings in security policies by configuring one or more next-generation on-premises or VM-series firewalls as a Master Device. If you don't configure a Master Device with a Prisma Access User-ID deployment, use long-form distributed name (DN) entries instead. https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/configure-user-based-policies-with-prisma-access/configure-user-id-in-prismaaccess.html
Question 220:
A network administrator created an intrazone Security policy rule on the firewall. The source zones were set to IT, Finance, and HR. Which two types of traffic will the rule apply to? (Choose two.)
A. traffic between zone Finance and zone HR B. traffic between zone IT and zone Finance C. traffic within zone HR D. traffic within zone IT
C. traffic within zone HR D. traffic within zone IT
Explanation
When a rule is configured as "intrazone", the "destination zone" cannot be changed (greyed out). Its value comes from the "source zone".
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Palo Alto Networks exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your PCNSE exam preparations
and Palo Alto Networks certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.