Complete list of current Q & A>> Download Palo Alto Network Certified Network Security Consultant (PCNSC) – Quiz 1 / 15 Which prerequisite must be satisfied before creating an SSH proxy Decryption policy? A. No prerequisites are required B. SSH keys must be manually generated C. Both SSH keys and SSL certificates must be generated D. SSL certificates must be generated 2 / 15 A Palo Alto Networks NGFW just submitted a file lo WildFire tor analysis Assume a 5-minute window for analysis. The firewall is configured to check for verdicts every 5 minutes. How quickly will the firewall receive back a verdict? A. 10 to 15 minutes B. 5 to 10 minutes C. More than 15 minutes D. 5 minutes 3 / 15 What are two benefits of nested device groups in panorama? (Choose two ) A. overwrites local firewall configuration B. requires configuration both function and location for every device C. all device groups inherit setting from the Shared group D. reuse of the existing Security policy rules and objects 4 / 15 An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between panorama and the managed firewall and Log Collectors. How would the administrator establish the chain of trust? A. Configure strong password B. Set up multiple-factor authentication. C. Use custom certificates. D. Enable LDAP or RADIUS integration. 5 / 15 Which three authentication faction factors does PAN-OS® software support for MFA? (Choose three.) A. Voice B. Pull C. SMS D. Push E. Okta Adaptive 6 / 15 Which option would an administration choose to define the certificate and protect that Panorama and its managed devices uses for SSL/ITS services? A. Set Up SSL/TLS under Policies > Service/URL Category > Service. B. Configure on SSL/TLS Profile C. Configure a Decryption Profile and select SSL/TLS services. D. Set up Security policy rule to allow SSL communication. 7 / 15 An administrator logs in to the Palo Alto Networks NGFW and reports and reports that the WebUI is missing the policies tab. Which profile is the cause of the missing policies tab? A. WebUI B. Admin Role C. Authorization D. Authentication 8 / 15 Which DoS protection mechanism detects and prevents session exhaustion attacks? A. TCP Port Scan Protection B. Flood Protection C. Resource Protection D. Pocket Based Attack Protection 9 / 15 Which CLI command enables an administrator to view detail about the firewall including uptime. PAN -OS® version, and serial number? A. debug system details B. Show system detail C. Show system info D. Show session info 10 / 15 Which Captive Portal mode must be contoured to support MFA authentication? A. Single Sign-On B. Redirect C. Transparent D. NTLM 11 / 15 Which version of Global Protect supports split tunneling based on destination domain, client process, and HTTP/HTTPs video streaming application? A. Globalprotect version 4.0 with PAn-OS 8.0 B. Globalprotect version 4.1 with PAn-OS 8.1 C. Globalprotect version 4.0 with PAn-OS 8.1 D. Globalprotect version 4.1 with PAn-OS 8.0 12 / 15 A session in the Traffic log is reporting the application as “incomplete” What does “incomplete” mean? A. The three-way TCP handshake did not complete. B. Data was received but wan instantly discarded because of a Deny policy was applied before App ID could be applied C. The three-way TCP handshake was observed, but the application could not be identified. D. The traffic is coming across UDP, and the application could not be identified. 13 / 15 Which three options are supposed in HA Lite? (Choose three.) A. Configuration synchronization B. Virtual link C. active/passive deployment D. session synchronization E. synchronization of IPsec security associations 14 / 15 Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.) A. User-ID B. Antivirus C. Application and Threats D. Content-ID 15 / 15 When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log. What will be the destination IP Address in that log entry? A. The IP Address of sinkhole.paloaltonetworks.com B. The IP Address of the command-and-control server C. The IP Address specified in the sinkhole configuration D. The IP Address of one of the external DNS servers identified in the anti-spyware database Your score is 0% Restart quiz Send feedback