A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermore, SSL is used to tunnel malicious traffic to command-andcontrol servers on the internet and SSL Forward Proxy Decryption is not enabled.
Which component once enabled on a perirneter firewall will allow the identification of existing infected hosts in an environment?
A. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole B. File Blocking profiles applied to outbound security policies with action set to alert C. Vulnerability Protection profiles applied to outbound security policies with action set to block D. Antivirus profiles applied to outbound security policies with action set to alert
A. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole
Explanation
Question 592:
An engineer is creating a security policy based on Dynamic User Groups (DUG). What benefit does this provide?
A. Automatically include users as members without having to manually create and commit policy or group changes B. DUGs are used to only allow administrators access to the management interface on the Palo Alto Networks firewall C. It enables the functionality to decrypt traffic and scan for malicious behaviour for User-ID based policies D. Schedule commits at a regular intervals to update the DUG with new users matching the tags specified
A. Automatically include users as members without having to manually create and commit policy or group changes
Explanation
Dynamic user groups help you to create policy that provides auto-remediation for anomalous user behavior and malicious activity while maintaining user visibility. Previously, quarantining users in response to suspicious activity meant time-and resource-consuming updates for all members of the group or updating the IP address-to-username mapping to a label to enforce policy at the cost of user visibility, as well as having to wait until the firewall checked the traffic. Now, you can configure a dynamic user group to automatically include users as members without having to manually create and commit policy or group changes and still maintain user-to-data correlation at the device level before the firewall even scans the traffic. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/user-id-features/dynamic-user-groups.html
Question 593:
Which two key exchange algorithms consume the most resources when decrypting SSL traffic? (Choose two.)
A. ECDSA B. ECDHE C. RSA D. DHE
B. ECDHE D. DHE
Explanation
The two key exchange algorithms that consume the most resources when decrypting SSL traffic are ECDHE and DHE. These are both Diffie-Hellman based algorithms that enable perfect forward secrecy (PFS), which means that they generate a new and unique session key for each SSL/TLS session, and do not reuse any previous keys. This enhances the security of the encrypted communication, but also increases the computational cost and complexity of the key exchange process. ECDHE stands for Elliptic Curve Diffie-Hellman Ephemeral, which uses elliptic curve cryptography (ECC) to generate the session key. DHE stands for Diffie-Hellman Ephemeral, which uses modular arithmetic to generate the session key. Both ECDHE and DHE require more CPU and memory resources than RSA, which is a non-PFS algorithm that uses public and private keys to encrypt and decrypt the session key123.
References: Key Exchange Algorithms, Best Practices for Enabling SSL Decryption, PCNSE Study Guide (page 60) https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/prepare-to-deploy-decryption/size-the-decryption-firewall-deployment
Question 594:
Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.
Given the rule below, what change should be made to make sure the NAT works as expected?
A. Change destination NAT zone to Trust_L3. B. Change destination translation to Dynamic IP (with session distribution) using firewall ethI/2 address. C. Change Source NAT zone to Untrust_L3. D. Add source Translation to translate original source IP to the firewall eth1/2 interface translation.
D. Add source Translation to translate original source IP to the firewall eth1/2 interface translation.
Explanation
Question 595:
After some firewall configuration changes, an administrator discovers that application identification has started failing. The administrator investigates further and notices that a high number of sessions were going to a discard state with the
application showing as unknown-tcp.
Which possible firewall change could have caused this issue?
A. enabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup > Content-ID > Content-ID Settings B. enabling Forward segments that exceed the TCP content inspection queue in Device > Setup > Content-ID > Content-ID Settings C. Jumbo frames were enabled on the firewall, which reduced the App-ID queue size and the number of available packet buffers. D. Jumbo frames were disabled on the firewall, which reduced the queue sizes dedicated for out-of-order and application identification.
A. enabling Forward segments that exceed the TCP App-ID inspection queue in Device > Setup > Content-ID > Content-ID Settings
Explanation
Question 596:
Which GlobalProtect Client connect method requires the distribution and use of machine certificates?
A. User-logon (Always on) B. At-boot C. On-demand D. Pre-logon
D. Pre-logon
Explanation
Client certificate refers to user cert, it can be used for 'user-logon'/'on-demand' connect methods. Used to authenticate a user. -Machine certificate refers to device cert, it can be used for 'pre-logon' connect method. This is used to authenticate a device, not a user. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK
Question 597:
A network security engineer is attempting to peer a virtual router on a PAN-OS firewall with an external router using the BGP protocol. The peer relationship is not establishing. What command could the engineer run to see the current state of the BGP state between the two devices?
A. show routing protocol bgp state B. show routing protocol bgp peer C. show routing protocol bgp summary D. show routing protocol bgp rib-out
What is a feature of the PA-440 hardware platform?
A. It supports Zero Touch Provisioning to assist in automated deployments. B. It supports 10GbE SFP+ modules. C. It has twelve 1GbE Copper ports. D. It has dedicated interfaces for high availability.
A. It supports Zero Touch Provisioning to assist in automated deployments.
An administrator logs in to the Palo Alto Networks NGFW and reports that the WebUI is missing the Policies tab. Which profile is the cause of the missing Policies tab?
A. Admin Role B. WebUI C. Authentication D. Authorization
A. Admin Role
Explanation
Question 600:
An administrator needs to assign a specific DNS server to one firewall within a device group. Where would the administrator go to edit a template variable at the device level?
A. Variable CSV export under Panorama > templates B. PDF Export under Panorama > templates C. Manage variables under Panorama > templates D. Managed Devices > Device Association
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Palo Alto Networks exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your PCNSE exam preparations
and Palo Alto Networks certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.