Get Full Version of the Exam
http://www.EnsurePass.com/PCNSE.html
Question No.161
Which two actions are required to make MicrosoftActive Directory users appear in a firewall traffic log? (Choose two.)
-
Run the User-ID Agent using an Active Directory account that has quot;event log viewerquot; permissions
-
Enable User-ID on the zone object for the destination zone
-
Run the User-ID Agentusing an Active Directory account that has quot;domain administratorquot; permissions
-
Enable User-ID on the zone object for the source zone
-
Configure a RADIUS server profile to point to a domain controller
Correct Answer: AD
Question No.162
Which field is optional when creating a new Security Policy rule?
-
Name
-
Description
-
Source Zone
-
Destination Zone
-
Action
Correct Answer: B
Question No.163
Which three function are found on the dataplane of a PA-5050? (Choose three)
-
Protocol Decoder
-
Dynamic routing
-
Management
-
Network Processing
-
Signature Match
Correct Answer: BDE
Question No.164
After pushing a security policy from Panorama to a PA-3020 firwall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama#39;s traffic logs. What could be the problem?
-
A Server Profile has not been configured for logging to this Panorama device.
-
Panorama is not licensed to receive logs from this particular firewall.
-
The firewall is not licensed for logging to this Panorama device.
-
None of the firwwall#39;s policies have been assigned a Log Forwarding profile
Correct Answer: D
Question No.165
An Administrator is configuring an IPSec VPN toa Cisco ASA at the administrator#39;s home and experiencing issues completing the connection. The following is th output from the command:
What could be the cause of this problem?
-
The public IP addresse do not match forboth the Palo Alto Networks Firewall and the ASA.
-
The Proxy IDs on the Palo Alto Networks Firewall do not match the settings on the ASA.
-
The shared secerts do not match between the Palo Alto firewall and the ASA
-
The deed peer detection settings do not match between the Palo Alto Networks Firewall and the ASA
Correct Answer: B
Question No.166
Site-A and Site-B need to use IKEv2 to establish a VPN connection. Site A connects directlyto the internet using a public IP address. Site-B uses a private IP address behind an ISP router to connect to the internet. How should NAT Traversal be implemented for the VPN connection to be established between Site-A and Site-B?
-
Enable on Site-A only
-
Enable on Site-B only
-
Enable on Site-B only with passive mode
-
Enable on Site-A and Site-B
Correct Answer: D
Question No.167
When is it necessary to activate a license when provisioning a new Palo Alto Networks firewall?
-
When configuring Certificate Profiles
-
When configuring GlobalProtect portal
-
When configuring User Activity Reports
-
When configuring Antivirus Dynamic Updates
Correct Answer: D
Question No.168
Click the Exhibit button. An administrator has noticed a large increase in bittorrent activity. The administrator wants to determine where the traffic is going on the company. What would be the administrator#39;s next step?
-
Right-Click on the bittorrent link and select Value from the context menu
-
Create a global filter for bittorrent traffic and then view Traffic logs.
-
Create local filter for bittorrent traffic and then view Trafficlogs.
-
Click on the bittorrent application link to view network activity
Correct Answer: D
Question No.169
Several offices are connected with VPNs using static IPV4 routes. An administrator has been tasked with implementing OSPF to replace static routing. Which step is required to accoumplish this goal?
-
Assign an IP address on each tunnel interface at each site
-
Enable OSPFv3 on each tunnel interface and use Area ID 0.0.0.0
-
Assign OSPF Area ID 0.0.0.0 to all Ethernet and tunnel interfaces
-
Create new VPN zones at each site to terminate each VPN connection
Correct Answer: C
Question No.170
Which option is an IPv6 routing protocol?
-
RIPv3
-
OSPFv3
-
OSPv3
-
BGP NG
Correct Answer: B
Get Full Version of the Exam
PCNSE Dumps
PCNSE VCE and PDF