2024年12月04日に更新された最新のJPNTest PCNSE試験問題リアルPCNSE問題集で
PCNSE別格な問題集で最上級の成績にさせるPCNSE問題
PCNSE試験は、候補者がPalo Alto Networksプラットフォームとそのさまざまな機能を深く理解する必要がある包括的で挑戦的なテストです。候補者は、プラットフォームでの実践的な経験と、ネットワーキングの概念とセキュリティのベストプラクティスを強く理解することが期待されています。この試験は、複数の選択の質問と、プラットフォームのさまざまな側面を構成およびトラブルシューティングする候補者の能力をテストする実践的なシミュレーションで構成されています。
質問 # 67
SSL Forward Proxy decryption is configured but the firewall uses Untrusted-CA to sign the website https //www important-website com certificate End-users are receiving me "security certificate is not trusted is warning Without SSL decryption the web browser shows that the website certificate is trusted and signed by a well-known certificate chain Well-Known-lntermediate and Well-Known-Root- CA.
The network security administrator who represents the customer requires the following two behaviors when SSL Forward Proxy is enabled:
1 End-users must not get the warning for the https://www.very-important-website.com website.
2 End-users should get the warning for any other untrusted website
Which approach meets the two customer requirements?
- A. Navigate to Device > Certificate Management - Certificates s Default Trusted Certificate Authorities import Well-Known-intermediate-CA and Well-Known-Root-CA select the Trusted Root CA check box and commit the configuration
- B. Clear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the configuration
- C. Navigate to Device > Certificate Management > Certificates > Device Certificates import Well-Known-lntermediate-CA and Well-Known-Root-CA select the Trusted Root CA checkbox and commit the configuration
- D. Install the Well-Known-lntermediate-CA and Well-Known-Root-CA certificates on all end-user systems m the user and local computer stores
正解:A
解説:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-certificate-management-certificates/manage-default-trusted-certificate-authorities
質問 # 68
Refer to the exhibit.
Which certificates can be used as a Forward Trust certificate?
- A. Domain-Root-Cert
- B. Domain Sub-CA
- C. Forward_Trust
- D. Certificate from Default Trust Certificate Authorities
正解:D
質問 # 69
An administrator has been asked to create 100 virtual firewalls in a local, on-premise lab environment (not in "the cloud"). Bootstrapping is the most expedient way to perform this task.
Which option describes deployment of a bootstrap package in an on-premise virtual environment?
- A. Use config-drive on a USB stick.
- B. Use a virtual CD-ROM with an ISO.
- C. Use an S3 bucket with an ISO.
- D. Create and attach a virtual hard disk (VHD).
正解:B
解説:
Reference:
https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/management-features/bootstrapping- firewalls-for-rapid-deployment.html
質問 # 70
With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?
- A. not-applicable
- B. unknown-udp
- C. Incomplete
- D. Insufficient-data
正解:B
質問 # 71
In the New App Viewer under Policy Optimizer, what does the compare option for a specific rule allow an administrator to compare?
- A. Applications configured in the rule with their dependencies
- B. The security rule with any other security rule selected
- C. Applications configured in the rule with applications seen from traffic matching the same rule
- D. The running configuration with the candidate configuration of the firewall
正解:C
解説:
Explanation
The compare option for a specific rule in the New App Viewer under Policy Optimizer allows an administrator to compare the applications configured in the rule with the applications seen from traffic matching the same rule. This helps the administrator to identify any new applications that are not explicitly defined in the rule, but are implicitly allowed by the firewall based on the dependencies of the configured applications. The compare option also shows the usage statistics and risk levels of the applications, and provides suggestions for optimizing the rule by adding, removing, or replacing applications12. References: New App Viewer (Policy Optimizer), PCNSE Study Guide (page 47) Why use Security Policy Optimizer and what are the benefits?
質問 # 72
Exhibit:
What will be the egress interface if the traffic's ingress interface is ethernet1/6 sourcing from 192.168.111.3 and to the destination 10.46.41.113 during the time shown in the image?
- A. ethernet1/6
- B. ethernet1/5
- C. ethernet1/7
- D. ethernet1/3
正解:D
質問 # 73
An engineer needs to configure SSL Forward Proxy to decrypt traffic on a PA-5260. The engineer uses a forward trust certificate from the enterprise PKI that expires December 31, 2025. The validity date on the PA-generated certificate is taken from what?
- A. The untrusted certificate
- B. The server certificate
- C. The root CA
- D. The trusted certificate
正解:B
解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8wCAC
"The validity date on the Palo Alto Networks firewall generated certificate is taken from the validity date on the real server certificate."
質問 # 74
Which Panorama feature protects logs against data loss if a Panorama server fails?
- A. Panorama Collector Group automatically ensures that no logs are lost if a server fails inside the Collector Group
- B. Panorama HA with Log Redundancy ensures that no logs are lost if a server fails inside the HA Cluster.
- C. Panorama Collector Group with Log Redundancy ensures that no logs are lost if a server fails inside the Collector Group.
- D. Panorama HA automatically ensures that no logs are lost if a server fails inside the HA Cluster.
正解:C
解説:
Redundancy ensures that no logs are lost if any one Log Collector becomes unavailable.
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log- collection/manage-collector-groups/configure-a-collector-group
質問 # 75
Which statement about High Availability timer settings is true?
- A. Use the Critical timer for faster failover timer settings.
- B. Use the Aggressive timer for faster failover timer settings
- C. Use the Moderate timer for typical failover timer settings
- D. Use the Recommended timer for faster failover timer settings.
正解:D
解説:
Recommended: Use for typical failover timer settings. Unless you're sure that you need different settings, the best practice is to use the Recommended settings.
Aggressive: Use for faster failover timer settings.
Advanced: Allows you to customize the values to suit your network requirement for each of the following timers:
質問 # 76
Which two mechanisms help prevent a spilt brain scenario an Active/Passive High Availability (HA) pair? (Choose two)
- A. Configure Ethernet 1/1 as HA1 Backup
- B. Configure the management interface as HA2 Backup
- C. Configure ethernet1/1 as HA3 Backup
- D. Configure the management interface as HA1 Backup
- E. Configure Ethernet 1/1 as HA2 Backup
- F. Configure the management interface as HA3 Backup
正解:A、D
解説:
E: For firewalls without dedicated HA ports, select two data interfaces for the HA2 link and the backup HA1 link. Then, use an Ethernet cable to connect these in-band HA interfaces across both firewalls.
Use the management port for the HA1 link and ensure that the management ports can connect to each other across your network.
B:
1. In Device > High Availability > General, edit the Control Link (HA1) section.
2. Select the interface that you have cabled for use as the HA1 link in the Port drop down menu.
Set the IP address and netmask. Enter a Gateway IP address only if the HA1 interfaces are on separate subnets. Do not add a gateway if the devices are directly connected.
https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/high-availability/configure- active-passive-ha
質問 # 77
Which event will happen if an administrator uses an Application Override Policy?
- A. Threat-ID processing time is decreased.
- B. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.
- C. App-ID processing time is increased.
- D. The application name assigned to the traffic by the security rule is written to the Traffic log.
正解:B
解説:
Explanation/Reference: https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an- Application-Override/ta-p/65513
質問 # 78
An internal system is not functioning. The firewall administrator has determined that the incorrect egress interface is being used. After looking at the configuration, the administrator believes that the firewall is not using a static route.
What are two reasons why the firewall might not use a static route? (Choose two.)
- A. no install on the route
- B. disabling of the static route
- C. path monitoring on the static route
- D. duplicate static route
正解:A、C
質問 # 79
Which three are valid configuration options in a WildFire Analysis Profile? (Choose three.)
- A. direction
- B. maximum file size
- C. file types
- D. application
正解:A、C、D
解説:
Define for the profile rule to match to unknown traffic and to forward samples for analysis based on:
https://docs.paloaltonetworks.com/wildfire/10-0/wildfire-admin/submit-files-for-wildfire- analysis/forward-files-for-wildfire-analysis.html
質問 # 80
When is the content inspection performed in the packet flow process?
- A. after the SSL Proxy re-encrypts the packet
- B. before session lookup
- C. before the packet forwarding process
- D. after the application has been identified
正解:D
解説:
Explanation/Reference:
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081
質問 # 81
Which three firewall multi-factor authentication factors are supported by PAN-OS? (Choose three.)
- A. Short message service
- B. Push
- C. One-Time Password
- D. SSH key
- E. User logon
正解:A、B、C
解説:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/authentication- types/multi-factor-authentication
質問 # 82
Updates to dynamic user group membership are automatic therefore using dynamic user groups instead of static group objects allows you to:
- A. respond to changes in user behavior or potential threats without automatic policy changes
- B. respond to changes in user behavior or potential threats using manual policy changes
- C. respond to changes in user behavior and confirmed threats with manual policy changes
- D. respond to changes in user behavior or potential threats without manual policy changes
正解:D
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/user-id-features/dynamic-user-groups#:~:text
質問 # 83
An organization conducts research on the benefits of leveraging the Web Proxy feature of PAN-OS 11.0.
What are two benefits of using an explicit proxy method versus a transparent proxy method? (Choose two.)
- A. Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy.
- B. It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing request.
- C. Explicit proxy supports interception of traffic using non-standard HTTPS ports.
- D. No client configuration is required for explicit proxy, which simplifies the deployment complexity.
正解:A、B
解説:
https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-cloud-managed-admin/secure-mobile-users-with-prisma-access/explicit-proxy/explicit-proxy-how-it-works
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy
質問 # 84
Which configuration task is best for reducing load on the management plane?
- A. Disable pre-defined reports
- B. Disable logging on the default deny rule
- C. Enable session logging at start
- D. Set the URL filtering action to send alerts
正解:A
解説:
Explanation
Report generation can also consume considerable resources, while some pre-defined reports may not be useful to the organization, or they've been replaced by a custom report. These pre-defined reports can be disabled from Device > Setup > Logging and Reporting Settings
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSvCAK
質問 # 85
A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas)
i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system )
ii. Enterpnse-Untrusted-CA, which is verified as Forward Untrust Certificate
iii. Enterprise-lntermediate-CA
iv. Enterprise-Root-CA which is verified only as Trusted Root CA
An end-user visits https //www example-website com/ with a server certificate Common Name (CN) www example-website com The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall
The end-user's browser will show that the certificate for www.example-website.com was issued by which of the following?
- A. Enterprise-Untrusted-CA which is a self-signed CA
- B. Enterprise-Root-CA which is a self-signed CA
- C. Enterprise-Trusted-CA which is a self-signed CA
- D. Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
正解:A
質問 # 86
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
- A. .dll
- B. .apk
- C. .jar
- D. .pdf
- E. .fon
- F. .exe
正解:B、C、D
質問 # 87
If the firewall has the link monitoring configuration, what will cause a failover?
- A. ethernet1/3 going down
- B. ethernet1/3 or Ethernet1/6 going down
- C. ethernet1/3 and ethernet1/6 going down
- D. ethernet1/6 going down
正解:C
質問 # 88
Which feature prevents the submission of corporate login information into website forms?
- A. Data filtering
- B. Credential phishing prevention
- C. File blocking
- D. User-ID
正解:B
解説:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/cyberpedia/how-the-next-generation-security-platform- contributes-to-gdpr-compliance
質問 # 89
Which statement accurately describes service routes and virtual systems?
- A. The interface must be used for traffic to the required external services.
- B. Virtual systems cannot have dedicated service routes configured; and virtual systems always use the global service and service route settings for the firewall.
- C. Virtual systems that do not have specific service routes configured inherit the global service and service route settings for the firewall.
- D. Virtual systems can only use one interface for all global service and service routes of the firewall.
正解:C
質問 # 90
Which option enables a Palo Alto Networks NGFW administrator to schedule Application and Threat updates while applying only new content IDs to traffic?
- A. Select download-and-install, with "Disable new apps in content update" selected
- B. Select download-only
- C. Select download-and-install
- D. Select disable application updates and select "Install only Threat updates"
正解:C
質問 # 91
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS
servers.
Which option will protect the individual servers?
- A. Apply an Anti-Spyware Profile with DNS sinkholing.
- B. Enable packet buffer protection on the Zone Protection Profile.
- C. Apply a classified DoS Protection Profile.
- D. Use the DNS App-ID with application-default.
正解:B
質問 # 92
......
PCNSE認定試験は、少なくとも2年間のネットワークセキュリティの経験と、TCP/IPネットワーキング、ルーティング、スイッチングの堅牢な理解を持つセキュリティ専門家を対象としています。認定試験の候補者は、ファイアウォール、侵入防止システム、およびその他のセキュリティ技術の設計、実装、および管理の経験を持っている必要があります。候補者は、ネットワークセキュリティの概念にも精通しており、ネットワークセグメンテーション、仮想プライベートネットワーク(VPN)、およびセキュアアクセスに関する経験がある必要があります。
PCNSE試験問題集でベストPCNSE試験問題を試そう:https://www.jpntest.com/shiken/PCNSE-mondaishu
手に入れよう!最新PCNSE認定有効な試験問題集解答:https://drive.google.com/open?id=17mjB4PAxq34WY4uk-8FQHqwA2nIuKrLG