Share Palo Alto Networks PCNSA exam practice questions and answers from Lead4Pass latest updated PCNSA dumps free of charge. Get the latest uploaded PCNSA dumps pdf from google driver online. To get the full Palo Alto Networks PCNSA dumps PDF or dumps VCE visit: https://www.leads4pass.com/pcnsa.html (Q&As: 121). all Palo Alto Networks PCNSA exam questions have been updated, the answer has been corrected!
Make sure your exam questions are real and effective to help you pass your first exam!
[Palo Alto Networks PCNSA Dumps pdf] Latest Palo Alto Networks PCNSA Dumps PDF collected by Lead4pass Google Drive:
https://drive.google.com/file/d/1lt4J3Q-d-crk1wxpHx4SS-yKfwjrRxTR/
Latest Update Palo Alto Networks PCNSA Exam Practice Questions and Answers Online Test
QUESTION 1
The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had
malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which
ordered the infected machine to begin Exfiltrating data from the laptop.
A. Create an anti-spyware profile and enable DNS Sinkhole
B. Create an antivirus profile and enable DNS Sinkhole
C. Create a URL filtering profile and block the DNS Sinkhole category
D. Create a security policy and enable DNS Sinkhole
Correct Answer: A
Reference: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/objects/objects-security-profilesanti-spyware-profile
QUESTION 2
Which file is used to save the running configuration with a Palo Alto Networks firewall?
A. running-config.xml
B. run-config.xml
C. running-configuration.xml
D. run-configuratin.xml
Correct Answer: A
QUESTION 3
Which option shows the attributes that are selectable when setting up application filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology
Correct Answer: B
Reference: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/objects/objects-application-filters
QUESTION 4
Which action related to App-ID updates will enable a security administrator to view the existing security policy rule that
matches new application signatures?
A. Review Policies
B. Review Apps
C. Pre-analyze
D. Review App Matches
Correct Answer: A
Reference: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-ids-introduced-incontent-releases/review-new-app-id-impact-on-existing-policy-rules
QUESTION 5
For the firewall to use Active Directory to authenticate users, which Server Profile is required in the Authentication
Profile?
A. TACACS+
B. RADIUS
C. LDAP
D. SAML
Correct Answer: C
Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-an-authenticationprofile-and-sequence
QUESTION 6
Which URL profiling action does not generate a log entry when a user attempts to access that URL?
A. Override
B. Allow
C. Block
D. Continue
Correct Answer: B
Reference: https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/url-filtering/url-filtering-concepts/url-filteringprofile-actions
QUESTION 7
The CFO found a malware-infected USB drive in the parking lot, which when inserted infected their corporate laptop.the
malware contacted a known command-and-control server, which caused the infected laptop to begin exfiltrating
corporate data.
Which security profile feature could have been used to prevent the communication with the command-and-control
server?
A. Create a Data Filtering Profile and enable its DNS sinkhole feature.
B. Create an Antivirus Profile and enable its DNS sinkhole feature.
C. Create an Anti-Spyware Profile and enable its DNS sinkhole feature.
D. Create a URL Filtering Profile and block the DNS sinkhole URL category.
Correct Answer: A
QUESTION 8
Which license must an Administrator acquire prior to downloading Antivirus Updates for use with the firewall?
A. Threat Prevention License
B. Threat Implementation License
C. Threat Environment License
D. Threat Protection License
Correct Answer: A
Reference: https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/threat-prevention/set-up-antivirus-anti-spywareand-vulnerability-protection.html
QUESTION 9
Which interface does not require a MAC or IP address?
A. Virtual Wire
B. Layer3
C. Layer2
D. Loopback
Correct Answer: A
QUESTION 10
Actions can be set for which two items in a URL filtering security profile? (Choose two.)
A. Block List
B. Custom URL Categories
C. PAN-DB URL Categories
D. Allow List
Correct Answer: BC
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boO3CAI
QUESTION 11
Identify the correct order to configure the PAN-OS integrated USER-ID agent.
3. add the service account to monitor the server(s)
2. define the address of the servers to be monitored on the firewall
4. commit the configuration, and verify agent connection status
1. create a service account on the Domain Controller with sufficient permissions to execute the User-ID agent
A. 2-3-4-1
B. 1-4-3-2
C. 3-1-2-4
D. 1-3-2-4
Correct Answer: D
QUESTION 12
Which administrator receives a global notification for a new malware that infects hosts. The infection will result in the
infected host attempting to contact and command-and-control (C2) server. Which security profile components will detect
and prevent this threat after the firewall`s signature database has been updated?
A. antivirus profile applied to outbound security policies
B. data filtering profile applied to inbound security policies
C. data filtering profile applied to outbound security policies
D. vulnerability profile applied to inbound security policies
Correct Answer: C
QUESTION 13
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks
Firewall? (Choose two.)
A. Layer-ID
B. User-ID
C. QoS-ID
D. App-ID
Correct Answer: BD
Reference: http://www.firewall.cx/networking-topics/firewalls/palo-alto-firewalls/1152-palo-alto-firewall-single-passparallel-processing-hardware-architecture.html
For the full Palo Alto Networks PCNSA exam dumps from Lead4pass PCNSA Dumps pdf or Dumps VCE visit: https://www.leads4pass.com/pcnsa.html (Q&As: 121 dumps)
ps.
Get free Palo Alto Networks PCNSA dumps PDF online: https://drive.google.com/file/d/1lt4J3Q-d-crk1wxpHx4SS-yKfwjrRxTR/