[2025年更新]PCNSEはPCNSE PAN-OSリアルな無料試験練習テスト
無料PCNSE PAN-OS PCNSE試験問題を提供します
PCNSE試験は、Palo Alto Networksプラットフォームに関連するさまざまな分野のセキュリティエンジニアの知識とスキルをテストするように設計されています。これには、ファイアウォールの構成、ネットワークセキュリティ、VPNセットアップ、脅威防止などのトピックが含まれます。 PCNSE試験に合格した候補者は、ネットワークセキュリティの分野の専門家として認識されており、セキュリティインフラストラクチャを管理するための熟練した専門家を探している組織にしばしば求められます。
質問 # 104
Use the image below If the firewall has the displayed link monitoring configuration what will cause a failover?
- A. etheme!1/3 going down
- B. ethernet1/3 or ethernet1/6 going down
- C. ethernet1/3 and ethernet1/6 going down
- D. ethernet1/6 going down
正解:C
質問 # 105
Given the following table.
Which configuration change on the firewall would cause it to use 10.66.24.88 as the next hop for the 192.168.93.0/30 network?
- A. Configuring the metric for RIP to be higher than that of OSPF Int.
- B. Configuring the administrative Distance for RIP to be lower than that of OSPF Int.
- C. Configuring the administrative Distance for RIP to be higher than that of OSPF Ext.
- D. Configuring the metric for RIP to be lower than that OSPF Ext.
正解:B
質問 # 106
Which two factors should be considered when sizing a decryption firewall de-ployment? (Choose two.)
- A. Encryption algorithm
- B. Number of blocked sessions
- C. TLS protocol version
- D. Number of security zones in decryption policies
正解:A、C
解説:
According to the Palo Alto Networks documentation1, decryption consumes firewall CPU resources, so it is important to evaluate the amount of SSL decryption that the firewall deployment can support. Two factors that affect the CPU consumption are the TLS protocol version and the encryption algorithm used by the encrypted traffic. The newer versions of TLS (such as TLS 1.3) and the stronger encryption algorithms (such as AES-256-GCM) require more CPU resources to decrypt than the older versions and weaker algorithms. Therefore, the correct answer is B and C.
The other options are not relevant or important for sizing a decryption firewall deployment:
Number of blocked sessions: This option refers to the number of sessions that the firewall blocks based on Security policy rules. It does not affect the decryption performance or resource consumption.
Number of security zones in decryption policies: This option refers to the number of security zones that are used to define the source and destination of the traffic to be decrypted. It does not affect the decryption performance or resource consumption.
質問 # 107
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- A. Restful API or the VMWare API on the firewall or on the User-ID agent or the read-only domain controller (RODC)
- B. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
- C. XML-API or the VMware API on the firewall or on the User-ID agent or the CLI
- D. Restful API or the VMware API on the firewall or on the User-ID agent
正解:B
解説:
Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/register-ip-addresses-and-tags-dynam
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/
質問 # 108
An administrator has configured OSPF with Advanced Routing enabled on a Palo Alto Networks firewall running PAN-OS 10.2. After OSPF was configured, the administrator noticed that OSPF routes were not being learned.
Which two actions could an administrator take to troubleshoot this issue? (Choose two.)
- A. Run the CLI command show advanced-routing ospf neighbor
- B. In the WebUI, view Runtime Stats in the logical router
- C. Look for configuration problems in Network > virtual router > OSPF
- D. In the WebUI, view the Runtime Stats in the virtual router
正解:A、B
解説:
A: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/network/network-virtual-routers/more-runtime-stats-for-a-logical-router#id5628a5e4-e908-457e-a2fd-270a476ab752 D: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/cli-cheat-sheets/cli-cheat-sheet-networking
質問 # 109
When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?
- A. To enable Portal authentication to the Gateway
- B. To enable user authentication to the Portal
- C. To enable client machine authentication to the Portal
- D. To enable Gateway authentication to the Portal
正解:B
解説:
The additional options of Browser and Satellite enable you to specify the authentication profile to use for specific scenarios. Select Browser to specify the authentication profile to use to authenticate a user accessing the portal from a web browser with the intent of downloading the GlobalProtect agent (Windows and Mac). Select Satellite to specify the authentication profile to use to authenticate the satellite.
https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/globalprotect/network-globalprotect-portals
質問 # 110
Exhibit:
What will be the egress interface if the traffic's ingress interface is ethernet1/6 sourcing from 192.168.111.3 and to the destination 10.46.41.113 during the time shown in the image?
- A. ethernet1/5
- B. ethernet1/3
- C. ethernet1/6
- D. ethernet1/7
正解:B
質問 # 111
A network design change requires an existing firewall to start accessing Palo Alto Updates from a data plane interface address instead of the management interface.
Which configuration setting needs to be modified?
- A. Management profile
- B. Service route
- C. Authentication profile
- D. Default route
正解:B
質問 # 112
Which two features does PAN-OS software use to identify applications? (Choose two)
- A. port number
- B. transaction characteristics
- C. application layer payload
- D. session number
正解:A、B
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/app-id/application-level-gateways# The Palo Alto Networks firewall does not classify traffic by port and protocol; instead it identifies the application based on its unique properties and transaction characteristics using the App-ID technology.
Some applications, however, require the firewall to dynamically open pinholes to establish the connection, determine the parameters for the session and negotiate the ports that will be used for the transfer of data; these applications use the application-layer payload to communicate the dynamic TCP or UDP ports on which the application opens data connections. For such applications, the firewall serves as an Application Level Gateway (ALG), and it opens a pinhole for a limited time and for exclusively transferring data or control traffic. The firewall also performs a NAT rewrite of the payload when necessary.
質問 # 113
An Administrator is configuring an IPSec VPN toa Cisco ASA at the administrator's home and experiencing issues completing the connection. The following is th output from the command:
less mp-log ikemgr.log:
What could be the cause of this problem?
- A. The public IP addresse do not match for both the Palo Alto Networks Firewall and the ASA.
- B. The deed peer detection settings do not match between the Palo Alto Networks Firewall and the ASA
- C. The shared secerts do not match between the Palo Alto firewall and the ASA
- D. The Proxy IDs on the Palo Alto Networks Firewall do not match the settings on the ASA.
正解:D
質問 # 114
A firewall has been assigned to a new template stack that contains both "Global" and "Local" templates in Panorama, and a successful commit and push has been performed. While validating the configuration on the local firewall, the engineer discovers that some settings are not being applied as intended.
The setting values from the "Global" template are applied to the firewall instead of the "Local" template that has different values for the same settings.
What should be done to ensure that the settings in the "Local" template are applied while maintaining settings from both templates?
- A. Perform a commit and push with the "Force Template Values" option selected.
- B. Move the "Local" template above the "Global" template in the template stack.
- C. Override the values on the local firewall and apply the correct settings for each value.
- D. Move the "Global" template above the "Local" template in the template stack.
正解:B
解説:
https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/templates-and-template-stacks
質問 # 115
Which feature must you configure to prevent users form accidentally submitting their corporate credentials to a phishing website?
- A. Anti-Spyware profile
- B. Zone Protection profile
- C. Vulnerability Protection profile
- D. URL Filtering profile
正解:D
解説:
Reference:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/prevent-credential-phishin
質問 # 116
A standalone firewall with local objects and policies needs to be migrated into Panoram
a. What procedure should you use so Panorama is fully managing the firewall?
- A. Use the "import Panorama configuration snapshot" operation, then perform a device-group commit push with "include device and network templates"
- B. Use the "import device configuration to Panorama" operation, then perform a device-group commit push with "include device and network templates"
- C. Use the "import Panorama configuration snapshot" operation, then "export or push device config bundle" to push the configuration
- D. Use the "import device configuration to Panorama" operation, then "export or push device config bundle" to push the configuration
正解:D
解説:
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management.html
質問 # 117
Which User-ID mapping method should be used in a high-security environment where all IP address-to-user mappings should always be explicitly known?
- A. GlobalProtect
- B. Windows-based User-ID agent
- C. PAN-OS integrated User-ID agent
- D. LDAP Server Profile configuration
正解:A
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprote Because GlobalProtect users must authenticate to gain access to the network, the IP address-to-username mapping is explicitly known.
Because GlobalProtect users must authenticate to gain access to the network, the IP address-to-username mapping is explicitly known. This is the best solution in sensitive environments where you must be certain of who a user is in order to allow access to an application or service.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprote
"On sensitive and high security networks, WMI probing increases the overall attack surface, and administrators are recommended to disable WMI probing and instead rely upon User-ID mappings obtained from more isolated and trusted sources, such as domain controllers. If you are using the User-ID Agent to parse AD security event logs, syslog messages, or the XML API to obtain User-ID mappings, then WMI probing should be disabled. Captive portal can be used as a fallback mechanism to re-authenticate users where security event log data may be stale."
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVPCA0
質問 # 118
Which GlobalProtect component must be configured to enable Chentless VPN?
- A. GlobalProtect gateway
- B. GlobalProtect portal
- C. GlobalProtect app
- D. GlobalProtect satellite
正解:B
解説:
Explanation
Creating the GlobalProtect portal is as simple as letting it know if you have accessed it already. A new gateway for accessing the GlobalProtect portal will appear. Client authentication can be used with an existing one.
https://www.nstec.com/how-to-configure-clientless-vpn-in-palo-alto/#5
質問 # 119
Which log type would provide information about traffic blocked by a Zone Protection profile?
- A. Traffic
- B. Threat
- C. IP-Tag
- D. Data Filtering
正解:B
解説:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhzCAC D is the correct answer because the threat log type would provide information about traffic blocked by a Zone Protection profile. This is because Zone Protection profiles are used to protect the network from attacks, including common flood, reconnaissance attacks, and other packet-based attacks1. These attacks are classified as threats by the firewall and are logged in the threat log2. The threat log displays information such as the source and destination IP addresses, ports, zones, applications, threat types, actions, and severity of the threats2.
Verified References:
1: Zone protection profiles - Palo Alto Networks Knowledge Base
2: Threat Log Fields - Palo Alto Networks
質問 # 120
Which three items are import considerations during SD-WAN configuration planning? (Choose three.)
- A. link requirements
- B. the name of the ISP
- C. IP Addresses
- D. branch and hub locations
正解:A、C、D
解説:
https://docs.paloaltonetworks.com/sd-wan/1-0/sd-wan-admin/sd-wan-overview/plan-sd-wan-configuration
質問 # 121
An engineer reviews high availability (HA) settings to understand a recent HA failover event. Review the screenshot below.
Which timer determines the frequency at which the HA peers exchange messages in the form of an ICMP (ping)
- A. Promotion Hold Time
- B. Monitor Fail Hold Up Time
- C. Hello Interval
- D. Heartbeat Interval
正解:A
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-timers
質問 # 122
What is the URL for the full list of applications recognized by Palo Alto Networks?
- A. http://applications.paloaltonetworks.com
- B. http://applipedia.paloaltonetworks.com
- C. http://www.Applipedia.com
- D. http://www.MyApplipedia.com
正解:B
質問 # 123
An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring Is enabled with the Failure Condition set to "any." There is one link group configured containing member interfaces ethernet1/1 and ethernet1/2 with a Group Failure Condition set to "all." Which HA state will the Active firewall go into if ethernet1/1 link goes down due to a failure?
- A. Passive
- B. Active-Secondary
- C. Active
- D. Non-functional
正解:C
解説:
Explanation
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClG7CAK
質問 # 124
......
Palo Alto Networks PCNSE認定試験は、Palo Alto Networksテクノロジーの専門知識を証明したいセキュリティプロフェッショナルにとって、価値のある資格です。認定試験は、複雑なネットワーク環境においてPalo Alto Networks次世代ファイアウォールとPanorama管理サーバーを実装および管理するために必要なスキルと知識を検証します。認定試験は、候補者のサイバーセキュリティの様々な領域における知識とスキルを厳密に評価し、ネットワークセキュリティにおける2年以上の経験が必要です。
Palo Alto Networks PCNSEリアルな問題と知能問題集:https://www.jpntest.com/shiken/PCNSE-mondaishu
PCNSE問題集でPCNSE PAN-OS高確率練習問題集:https://drive.google.com/open?id=1jsAxOkUGdrlMkhFtC-2M3ybw4jGgsrqY