Which value in the Application column indicates UDP traffic that did not match an App-ID signature?
A. not-applicable
B. incomplete
C. unknown-ip
D. unknown-udp
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
A. PAN-OS integrated User-ID agent
B. LDAP Server Profile configuration
C. GlobalProtect
D. Windows-based User-ID agent
Which rule type controls end user SSL traffic to external websites?
A. SSL Outbound Proxyless Inspection
B. SSL Forward Proxy
C. SSL Inbound Inspection
D. SSH Proxy
An administrator receives the following error message:
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id. 172.16.33.33/24 type IPv4 address protocol 0 port 0."
How should the administrator identify the root cause of this error message?
A. Verify that the IP addresses can be pinged and that routing issues are not causing the connection failure.
B. Check whether the VPN peer on one end is set up correctly using policy-based VPN.
C. In the IKE Gateway configuration, verify that the IP address for each VPN peer is accurate.
D. In the IPSec Crypto profile configuration, verify that PFS is either enabled on both VPN peers or disabled on both VPN peers.
In the screenshot above which two pieces ot information can be determined from the ACC configuration shown? (Choose two ) A. The Network Activity tab will display all applications, including FTP.
B. Threats with a severity of "high" are always listed at the top of the Threat Name list
C. Insecure-credentials, brute-force and protocol-anomaly are all a part of the vulnerability Threat Type
D. The ACC has been filtered to only show the FTP application
A network administrator wants to deploy GlobalProtect with pre-logon for Windows 10 endpoints and follow Palo Alto Networks best practices. To install the certificate and key for an endpoint, which three components are required? (Choose three.)
A. server certificate
B. local computer store
C. private key
D. self-signed certificate
E. machine certificate
Which two statements are true for the DNS Security service? (Choose two.)
A. It eliminates the need for dynamic DNS updates
B. It functions like PAN-DB and requires activation through the app portal
C. It removes the 100K limit for DNS entries for the downloaded DNS updates
D. It is automatically enabled and configured
A security engineer needs firewall management access on a Inside interface.
When three settings are required on an SSI/TVS Service Profile to provide secure Wet) Ui authentication? (Choose three.)
A. Maximum TLS version
B. Minimum TLS version
C. Encryption Algorithm
D. Certificate
E. Authentication Algorithm
Which statement is correct given the following message from the PanGPA log on the GlobalProtect app? Failed to connect to server at port:47 67
A. The PanGPS process failed to connect to the PanGPA process on port 4767
B. The GlobalProtect app failed to connect to the GlobalProtect Portal on port 4767
C. The PanGPA process failed to connect to the PanGPS process on port 4767
D. The GlobalProtect app failed to connect to the GlobalProtect Gateway on port 4767
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two)
A. Dos Protection policy
B. QoS Profile
C. Zone Protection Profile
D. DoS Protection Profile
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCNSE exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.