Panorama will not push anything from Data-Centers group. That rules out
C.
Panorama will push all objects from "Shared", which rules out A.
Note that the target of "Shared Policy 2" is NYC-FW, so this policy won't get pushed to Dallas-FW. This rules out
B.
Thus, answer is
D.
Question 752:
An administrator is using Panorama to manage me and suspects an IKE Crypto mismatch between peers, from the firewalls to Panorama. However, pre-existing logs from the firewalls are not appearing in Panorama. Which action should be taken to enable the firewalls to send their pre-existing logs to Panorama?
A. Export the log database. B. Use the import option to pull logs. C. Use the ACC to consolidate the logs. D. Use the scp logdb export command.
Which three split tunnel methods are supported by a globalProtect gateway? (Choose three.)
A. video streaming application B. Client Application Process C. Destination Domain D. Source Domain E. Destination user/group F. URL Category
A. video streaming application B. Client Application Process C. Destination Domain
Explanation
You can configure split tunnel traffic based on an access route, destination domain, application, and HTTP/HTTPS video streaming application. https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/ split-tunnel-traffic-on-globalprotect-gateways.html
Question 754:
An engineer is attempting to resolve an issue with slow traffic.
Which PAN-OS feature can be used to prioritize certain network traffic?
A. Prisma Access for Mobile Users B. Forward Error Correction (FEC) C. SaaS Quality Profile D. Quality of Service (QoS)
D. Quality of Service (QoS)
Explanation
Question 755:
A network administrator configured a site-to-site VPN tunnel where the peer device will act as initiator None of the peer addresses are known. What can the administrator configure to establish the VPN connection1?
A. Set up certificate authentication B. Enable Passive Mode C. Use the Dynamic IP address type D. Configure the peer address as an FQDN
C. Use the Dynamic IP address type
Explanation
When the peer device will act as the initiator and none of the peer addresses are known, the administrator can enable Passive Mode to establish the VPN connection. Passive Mode tells the firewall to wait for the peer device to initiate the VPN connection. The other options are incorrect. Option A, setting up certificate authentication, would require the administrator to know the peer device's certificate. Option C, using the Dynamic IP address type, would require the administrator to know the peer device's dynamic IP address. Option D, configuring the peer address as an FQDN, would require the administrator to know the peer device's fully qualified domain name.
An administrator needs to identify which NAT policy is being used for internet traffic.
From the Monitor tab of the firewall GUI, how can the administrator identify which NAT policy is in use for a traffic flow?
A. Click Session Browser and review the session details. B. Click Traffic view and review the information in the detailed log view. C. Click Traffic view; ensure that the Source or Destination NAT columns are included and review the information in the detailed log view. D. Click App Scope > Network Monitor and filter the report for NAT rules.
C. Click Traffic view; ensure that the Source or Destination NAT columns are included and review the information in the detailed log view.
Explanation
Traffic view in the Monitor tab of the firewall GUI can display the information about the NAT policy that is in use for a traffic flow, if the Source or Destination NAT columns are included and reviewed in the detailed log view1. The Source NAT column shows the translated source IP address and port, and the Destination NAT column shows the translated destination IP address and port2. These columns can help the administrator identify which NAT policy is applied to the traffic flow based on the pre-NAT and post-NAT addresses and ports.
Question 758:
A firewall administrator has confirm reports of a website is not displaying as expected, and wants to ensure that decryption is not causing the issue.
Which three methods can the administrator use to determine if decryption is causing the website to fail? (Choose three.)
A. Disable SSL handshake logging B. Investigate decryption logs of the specific traffic to determine reasons for failure. C. Temporarily disable SSL decryption for all websites to troubleshoot the issue D. Create a policy-based "No Decrypt" rule in the decryption policy to include specific traffic from decryption. E. Move the policy with action decrypt to the top of the decryption policy rulebase.
B. Investigate decryption logs of the specific traffic to determine reasons for failure. C. Temporarily disable SSL decryption for all websites to troubleshoot the issue D. Create a policy-based "No Decrypt" rule in the decryption policy to include specific traffic from decryption.
Explanation
Question 759:
Which DoS protection mechanism detects and prevents session exhaustion attacks?
A. Packet Based Attack Protection B. Flood Protection C. Resource Protection D. TCP Port Scan Protection
In addition to setting IP flood thresholds, you can also use DoS Protection profiles to detect and prevent session exhaustion attacks in which a large number of hosts (bots) establish as many sessions as possible to consume a target's resources. On the profile's Resources Protection tab, you can set the maximum number of concurrent sessions that the device(s) defined in the DoS Protection policy rule to which you apply the profile can receive. When the number of concurrent sessions reaches its maximum limit, new sessions are dropped.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Palo Alto Networks exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your PCNSE exam preparations
and Palo Alto Networks certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.