無料提供中のPCNSE試験問題集で(2024年最新のPDF問題集)信頼度の高いテストエンジン [Q32-Q53]

Share

無料提供中のPCNSE試験問題集で(2024年最新のPDF問題集)信頼度の高いテストエンジン

PCNSEのPDFで最近更新された問題です集試験点数を伸ばそう

質問 # 32
What must be configured to apply tags automatically based on User-ID logs?

  • A. Log settings
  • B. Group mapping
  • C. Log Forwarding profile
  • D. Device ID

正解:A

解説:
Depending on the type of log you want to use for tagging, create a log forwarding profile or configure the log settings to define how you want the firewall or Panorama to handle logs. For Authentication, Data, Threat, Traffic, Tunnel Inspection, URL, and WildFire logs, create a log forwarding profile. For User-ID, GlobalProtect, and IP-Tag logs, configure the log settings. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-auto-tagging-to-automate-security-actions


質問 # 33
Which method does an administrator use to integrate all non-native MFA platforms in PAN-OS® software?

  • A. RADIUS
  • B. DUO
  • C. PingID
  • D. Okta

正解:A


質問 # 34
You have upgraded Panorama to 10.2 and need to upgrade six Log Collectors. When upgrading Log Collectors to 10.2, you must do what?

  • A. Add a Global Authentication Profile to each Managed Collector.
  • B. Upgrade all the Log Collectors at the same time.
  • C. Upgrade the Log Collectors one at a time.
  • D. Add Panorama Administrators to each Managed Collector.

正解:B

解説:
You must upgrade all Log Collectors in a collector group at the same time to avoid losing log data https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-panorama/deploy-updates-to-firewalls-log-collectors-and-wildfire-appliances-using-panorama/deploy-an-update-to-log-collectors-when-panorama-is-internet-connected


質問 # 35
A network administrator wants to deploy SSL Forward Proxy decryption. What two attributes should a forward trust certificate have? (Choose two.)

  • A. A subject alternative name
  • B. A server certificate
  • C. A private key
  • D. A certificate authority (CA) certificate

正解:C、D

解説:
The two attributes that a forward trust certificate should have for SSL Forward Proxy decryption are:
* B: A private key. This is the key that the firewall uses to sign the certificates that it generates for the decrypted sessions. The private key must be securely stored on the firewall and not shared with anyone1.
* D: A certificate authority (CA) certificate. This is the certificate that the firewall uses to issue the certificates for the decrypted sessions. The CA certificate must be trusted by the client browsers and devices that receive the certificates from the firewall1.


質問 # 36
Which DoS protection mechanism detects and prevents session exhaustion attacks?

  • A. Flood Protection
  • B. Resource Protection
  • C. Packet Based Attack Protection
  • D. TCP Port Scan Protection

正解:B

解説:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/dos- protection-profiles


質問 # 37
What is exchanged through the HA2 link?

  • A. User-ID information
  • B. HA state information
  • C. hello heartbeats
  • D. session synchronization

正解:D

解説:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/ha-concepts/ ha-links-and-backup-links


質問 # 38
The firewall identifies a popular application as an unknown-tcp.
Which two options are available to identify the application? (Choose two.)

  • A. Create a Security policy to identify the custom application.
  • B. Create a custom application.
  • C. Create a custom object for the custom application server to identify the custom application.
  • D. Submit an Apple-ID request to Palo Alto Networks.

正解:B、D

解説:

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/manage-custom-or- unknown-applications


質問 # 39
A network administrator configured a site-to-site VPN tunnel where the peer device will act as initiator None of the peer addresses are known What can the administrator configure to establish the VPN connection?

  • A. Set up certificate authentication.
  • B. Configure the peer address as an FQDN.
  • C. Enable Passive Mode
  • D. Use the Dynamic IP address type.

正解:D

解説:
When the peer device will act as the initiator and none of the peer addresses are known, the administrator can enable Passive Mode to establish the VPN connection. Passive Mode tells the firewall to wait for the peer device to initiate the VPN connection. The other options are incorrect. Option A, setting up certificate authentication, would require the administrator to know the peer device's certificate. Option C, using the Dynamic IP address type, would require the administrator to know the peer device's dynamic IP address. Option D, configuring the peer address as an FQDN, would require the administrator to know the peer device's fully qualified domain name.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0


質問 # 40
An engineer is configuring a firewall with three interfaces:
* MGT connects to a switch with internet access.
* Ethernet1/1 connects to an edge router.
* Ethernet1/2 connects to a visualization network.
The engineer needs to configure dynamic updates to use a dataplane interface for internet traffic. What should be configured in Setup > Services > Service Route Configuration to allow this traffic?

  • A. Set DNS and Palo Alto Networks Services to use the ethernet1/2 source interface.
  • B. Set DDNS and Palo Alto Networks Services to use the MGT source interface.
  • C. Set DNS and Palo Alto Networks Services to use the ethernet1/1 source interface.
  • D. Set DNS and Palo Alto Networks Services to use the MGT source interface.

正解:C


質問 # 41
Which two firewall components enable you to configure SYN flood protection thresholds? (Choose two)

  • A. Zone Protection Profile
  • B. QoS Profile
  • C. Dos Protection policy
  • D. DoS Protection Profile

正解:A、D

解説:
Flood Attack Protection
Zone Protection Profiles protect against of five types of floods:
* SYN (TCP)
* UDP
* ICMP
* ICMPv6
* Other IP


質問 # 42
A company wants to add threat prevention to the network without redesigning the network routing.
What are two best practice deployment modes for the firewall? (Choose two.)

  • A. TAP
  • B. Layer3
  • C. VirtualWire
  • D. Layer2

正解:C、D

解説:
Explanation
* A and D are the best practice deployment modes for the firewall if the company wants to add threat prevention to the network without redesigning the network routing. This is because these modes allow the firewall to act as a transparent device that does not affect the existing network topology or routing1.
* A: VirtualWire mode allows the firewall to be inserted into any existing network segment without changing the IP addressing or routing of that segment2. The firewall inspects traffic between two interfaces that are configured as a pair, called a virtual wire. The firewall applies security policies to the traffic and forwards it to the same interface from which it was received2.
* D: Layer 2 mode allows the firewall to act as a switch that forwards traffic based on MAC addresses3.
The firewall inspects traffic between interfaces that are configured as Layer 2 interfaces and belong to the same VLAN. The firewall applies security policies to the traffic and forwards it to the appropriate interface based on the MAC address table3.
Verified References:
* 1: https://www.garlandtechnology.com/blog/whats-your-palo-alto-ngfw-deployment-plan
* 2:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/networking/configure-interfaces/virtual-wire
* 3:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/networking/configure-interfaces/layer-2.htm


質問 # 43
An administrator has configured PAN-OS SD-WAN and has received a request to find out the reason for a session failover for a session that has already ended Where would you find this in Panorama or firewall logs?

  • A. System Logs
  • B. You cannot find failover details on closed sessions
  • C. Session Browser
  • D. Traffic Logs

正解:D

解説:
Explanation
https://docs.paloaltonetworks.com/sd-wan/1-0/sd-wan-admin/configure-sd-wan/sd-wan-traffic-distribution-profil


質問 # 44
What are the differences between using a service versus using an application for Security Policy match?

  • A. Use of a "service" enables the firewall to take action after enough packets allow for App-ID identification
  • B. There are no differences between "service" or "application" Use of an "application" simplifies configuration by allowing use of a friendly application name instead of port numbers.
  • C. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers Use of an "application" allows the firewall to take action after enough packets allow for App-ID identification regardless of the ports being used.
  • D. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take immediate action it the port being used is a member of the application standard port list

正解:C

解説:
Explanation
https://live.paloaltonetworks.com/t5/blogs/what-are-applications-and-services/ba-p/342508# A service on the Palo Alto Networks firewall is a TCP or UDP portes which port is open or closed and does not look beyond Layer 4. An application it goes into Layer 7 inspection to ascertain which application is active in a data flow and will enforce "normal" behavior onto it, DNS Query
https://live.paloaltonetworks.com/t5/blogs/what-are-applications-and-services/ba-p/342508# Concept 1 A service on the Palo Alto Networks firewall is a TCP or UDP port, as it would be defined on a traditional firewall or access list. It simply defines which port is open or closed and does not look beyond Layer 4.
Concept 2
An application is what makes the Palo Alto Networks next-generation firewall so powerful; it goes into Layer
7 inspection to ascertain which application is active in a data flow and will enforce "normal" behavior onto it (e.g., a session identified as DNS that suddenly sends an SQL query is abnormal and will be blocked).


質問 # 45
Refer to the exhibit.

An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)

  • A. Untrust (Any) to DMZ (10.1.1.1), web-browsing -Allow
  • B. Untrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow
  • C. Untrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
  • D. Untrust (Any) to Untrust (10.1.1.1), ssh -Allow
  • E. Untrust (Any) to DMZ (10.1.1.1), ssh -Allow

正解:A、E


質問 # 46
Which data flow describes redistribution of user mappings?

  • A. User-ID agent to Panorama
  • B. User-ID agent to firewall
  • C. Domain Controller to User-ID agent
  • D. firewall to firewall

正解:D


質問 # 47
For which two functions is the management plane responsible? (Choose two.)

  • A. Forwarding logs
  • B. Protocol decoding
  • C. Reassembling packets
  • D. Answering HTTP requests

正解:A、D


質問 # 48
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for the pair.
Which configuration will enable this HA scenario?

  • A. The two firewalls will share a single floating IP and will use gratuitous ARP to share the floating IP.
  • B. The firewalls will share the same interface IP address, and device 1 will use the floating IP if device 0 fails.
  • C. The firewalls do not use floating IPs in active/active HA.
  • D. Each firewall will have a separate floating IP, and priority will determine which firewall has the primary IP.

正解:A

解説:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability/floating-ip-address-and-virtual-mac-address


質問 # 49
An administrator notices that an interface configuration has been overridden locally on a firewall. They require all configuration to be managed from Panorama and overrides are not allowed.
What is one way the administrator can meet this requirement?

  • A. Perform a template commit push from Panorama using the "Force Template Values" option.
  • B. Perform a device-group commit push from Panorama using the "Include Device and Network Templates" option.
  • C. Reload the running configuration and perform a Firewall local commit.
  • D. Perform a commit force from the CLI of the firewall.

正解:A

解説:
The best way for the administrator to meet the requirement of managing all configuration from Panorama and preventing local overrides is B: Perform a template commit push from Panorama using the "Force Template Values" option. This option allows the administrator to overwrite any local configuration on the firewall with the values defined in the template1. This way, the administrator can ensure that the interface configuration and any other


質問 # 50
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans. Which Security Profile type will protect against worms and trojans?

  • A. Vulnerability Protection
  • B. Anti-Spyware
  • C. Antivirus
  • D. WildFire

正解:B

解説:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/policy/antivirus-profiles


質問 # 51
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?

  • A. Using the same user's corporate username and password.
  • B. First four letters of the username matching any valid corporate username.
  • C. Mapping to the IP address of the logged-in user.
  • D. Marching any valid corporate username.

正解:C

解説:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/credential-phishing-prevention Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/content-inspection-features/credential- phishing-prevention


質問 # 52
Starting with PAN-OS version 9.1, Global logging information is now recoded in which firewall log?

  • A. System
  • B. Configuration
  • C. Globalprotect
  • D. Authentication

正解:A


質問 # 53
......

PCNSE完全版問題集には無料PDF問題で合格させる:https://www.jpntest.com/shiken/PCNSE-mondaishu

無料PCNSE PAN-OS PCNSE公式認定ガイドPDFダウンロード:https://drive.google.com/open?id=13TUnZkL2j9X1vT639MQ7nlFSIbmhW2tJ

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡