Decrypted packets from the website https://www.microsoft.com will appear as which application and service within the Traffic log?
A. web-browsing and 443 B. SSL and 80 C. SSL and 443 D. web-browsing and 80
A. web-browsing and 443
Explanation
We know that SSL decryption is supposed to give us visibility of traffic that would otherwise be encrypted. Therefore, we'd expect decrypted traffic to be identified as the underlying applications, such as web-browsing, facebook-base or other,
An organization has recently migrated its infrastructure and configuration to NGFWs, for which Panorama manages the devices The organization is coming from a L2-L4 firewall vendor, but wants to use App-ID while identifying policies that are no longer needed.
Which Panorama tool can help this organization?
A. Config Audit B. Policy Optimizer C. Application Groups D. Test Policy Match
B. Policy Optimizer
Explanation
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/app-id-features/policy-optimizer his new feature identifies port-based rules so you can convert them to application-based rules that allow the traffic or add applications to existing rules without compromising application availability. https://docs.paloaltonetworks.com/pan-os/90/pan-os-new-features/app-id-features/policy-optimizer.html
Question 403:
An organization conducts research on the benefits of leveraging the Web Proxy feature of PAN-OS 11.0. What are two benefits of using an explicit proxy method versus a transparent proxy method? (Choose two.)
A. No client configuration is required for explicit proxy, which simplifies the deployment complexity. B. Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy. C. Explicit proxy supports interception of traffic using non-standard HTTPS ports. D. It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request
B. Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy. D. It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.
The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown. The next two entries show traffic allowed as application
SSL.
Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?
A. Create a decryption rule matching the encrypted BitTorrent traffic with action "No-Decrypt," and place the rule at the top of the Decryption policy. B. Create a Security policy rule that matches application "encrypted BitTorrent" and place the rule at the top of the Security policy. C. Disable the exclude cache option for the firewall. D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.
D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRtCAK Block sessions that use cipher suites you don't support. You configure which cipher suites (encryption algorithms) to allow on the SSL Protocol Settings tab. Don't allow users to connect to sites with weak cipher suites.
Question 405:
Which two components are required to configure certificate-based authentication to the web Ul when an administrator needs firewall access on a trusted interface'? (Choose two.)
A. Server certificate B. SSL/TLS Service Profile C. Certificate Profile D. CA certificate
C. Certificate Profile D. CA certificate
Explanation
Question 406:
Which protection feature is available only in a Zone Protection Profile?
A. SYN Flood Protection using SYN Flood Cookies B. ICMP Flood Protection C. Port Scan Protection D. UDP Flood Protections
C. Port Scan Protection
Explanation
Configure one of the following Reconnaissance Protection actions for the firewall to take in response to the corresponding reconnaissance attempt:Allow--The firewall allows the port scan or host sweep reconnaissance to continue. SYN Flood Cookies is also available on DoS Protection Profile, the answer refers to ONLY. DoS Protection profiles protect specific devices (classified profiles) and groups of devices (aggregate profiles) against SYN, UDP, ICMP, ICMPv6, and Other IP flood attacks.
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/network/network-network-profiles/network-network-profiles-zone-protection/reconnaissance-protection.html#ida0512c75-ed54-4b31-8d2c-9f459466d4d2 Port scan protection = Reconnaissance Protection That can only be done in a Zone Protection Profile. That's meant to be configured on an external-facing interface to protect the entire attack surface. DOS Protection profiles are meant to be configured on internal-facing interfaces to protect a specific server or group of servers from flood attacks, including SYN Flood. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/configure-zone-protection-to-increase-network-security/configure-reconnaissance-protection
Question 407:
An existing NGFW customer requires direct interne! access offload locally at each site and iPSec connectivity to all branches over public internet. One requirement is mat no new SD-WAN hardware be introduced to the environment. What is the best solution for the customer?
A. Configure a remote network on PAN-OS B. Upgrade to a PAN-OS SD-WAN subscription C. Deploy Prisma SD-WAN with Prisma Access D. Configure policy-based forwarding
B. Upgrade to a PAN-OS SD-WAN subscription
Explanation
Question 408:
Refer to the exhibit.
Review the screenshots and consider the following information:
1.FW-1 is assigned to the FW-1_DG device group, and FW-2 is assigned to OFFICE_FW_DG.
2.There are no objects configured in REGIONAL_DG and OFFICE_FW_DG device groups. Which IP address will be pushed to the firewalls inside Address Object Server-1?
A. Server-1 on FW-1 will have IP 1.1.1.1. Server-1 will not be pushed to FW-2. B. Server-1 on FW-1 will have IP 3.3.3.3. Server-1 will not be pushed to FW-2. C. Server-1 on FW-1 will have IP 2.2.2.2. Server-1 will not be pushed to FW-2. D. Server-1 on FW-1 will have IP 4.4.4.4. Server-1 on FW-2 will have IP 1.1.1.1.
D. Server-1 on FW-1 will have IP 4.4.4.4. Server-1 on FW-2 will have IP 1.1.1.1.
Explanation
FW-1 will get the value from FW-DG1 while FW-2 will get the value from the Shared DG since no values are present in its parent DGs. https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-devicegroups/manage-precedence-of-inherited-objects
A user at an internal system queries the DNS server for their web server with a private IP of 10 250 241 131 in the. The DNS server returns an address of the web server's public address, 200.1.1.10.
In order to reach the web server, which security rule and U-Turn NAT rule must be configured on the firewall?
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Palo Alto Networks exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your PCNSE exam preparations
and Palo Alto Networks certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.