Get Full Version of the Exam
http://www.EnsurePass.com/PCNSE.html
Question No.81
How would an administrator monitor/capture traffic on the managementinterface of the Palo Alto Networks NGFW?
-
Use the debug dataplane packet-diag set capture stage firewall file command.
-
Enable all four stages of traffic capture (TX, RX, DROP, Firewall).
-
Use the debug dataplane packet-diag set capture stage management file command.
-
Use the tcpdump command. Correct Answer: D Explanation:
https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390
Question No.82
Which three authentication services can administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall?
(Choose three.)
-
Kerberos
-
PAP
-
SAML
-
TACACS
-
RADIUS
-
LDAP
Correct Answer: DEF
Question No.83
If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is pushed?
-
The settings assigned to the template that is on top of thestack.
-
The administrator will be promoted to choose the settings for that chosen firewall.
-
All the settings configured in all templates.
-
Depending on the firewall location, Panorama decides with settings to send.
Correct Answer: B
Explanation: https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage- firewalls/manage-templates-and-template-stacks/configure-a-template-stack
Question No.84
Which three options are supported in HA Lite? (Choose three.)
-
Virtual link
-
Active/passive deployment
-
Synchronization of IPsec security associations
-
Configuration synchronization
-
Sessionsynchronization
Correct Answer: BCD
Explanation:
https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/device/device- high-availability/ha-lite
Question No.85
During the packet flow process, which two processes are performed in application identification? (Choose two.)
-
Pattern based application identification
-
Application override policy match
-
Application changed from content inspection
-
Session application identified.
Correct Answer: BD
Question No.86
Which method does an administrator use to integrate all non-native MFA platforms in PAN-OS庐 software?
-
Okta
-
DUO
-
RADIUS
-
PingID
Correct Answer: C
Question No.87
What is exchanged through the HA2 link?
-
hello heartbeats
-
User-ID information
-
sessionsynchronization
-
HA state information
Correct Answer: C
Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability/ha-links-and- backup-links
Question No.88
An administrator just submitted a newlyfound piece of spyware for WildFire analysis. The spyware passively monitors behavior without the user#39;s knowledge. What is the expected verdict from WildFire?
-
Gray ware
-
Malware
-
Spyware
-
Phishing
Correct Answer: A
Question No.89
If the firewall has the link monitoringconfiguration, what will cause a failover?
-
ethernet1/3 and ethernet1/6 going down
-
ethernet1/3 going down
-
ethernet1/3 or Ethernet1/6 going down
-
ethernet1/6 going down
Correct Answer: A
Question No.90
View the GlobalProtect configuration screen capture. What is the purpose of this configuration?
-
It configures the tunnel address of all internal clients to an IP address range starting at 192.168.10.1.
-
It forces an internal client to connect to an internal gateway at IP address 192.168.10.1.
-
It enables a client to perform a reverse DNS lookup on 192.168.10.1 to detect that it is an internal client.
-
It forces the firewall to perform a dynamic DNS update, which adds the internal gateway#39;s hostname and IP address to the DNS server.
Correct Answer: C
Explanation:
https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin- guide/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define- the-globalprotect-agent-configurations
Get Full Version of the Exam
PCNSE Dumps
PCNSE VCE and PDF