[2025年05月26日]PCNSE試験ブレーン問題集で学習注釈と理論
合格させるPalo Alto Networks PCNSEテスト練習テスト問題試験問題集
質問 # 198
Given the following configuration, which route is used for destination 10.10.0.4?
- A. Route 4
- B. Route 3
- C. Route 1
- D. Route 3
正解:A
質問 # 199
Based on the graphic, which statement accurately describes the output shown in the Server Monitoring panel?
- A. The User-ID agent is connected to the firewall labeled lab-client.
- B. The User-ID agent is connected to a domain controller labeled lab-client.
- C. The host lab-client has been found by a domain controller.
- D. The host lab-client has been found by the User-ID agent.
正解:B
解説:
The User-ID agent is connected to a domain controller labeled lab-client.
質問 # 200
A firewall administrator notices that many Host Sweep scan attacks are being allowed through the firewall sourced from the outside zone. What should the firewall administrator do to mitigate this type of attack?
- A. Create a DOS Protection profile with SYN Flood protection enabled and apply it to all rules allowing traffic from the outside zone
- B. Create a Security rule to deny all ICMP traffic from the outside zone.
- C. Create a Zone Protection profile, enable reconnaissance protection, set action to Block, and apply it to the outside zone.
- D. Enable packet buffer protection in the outside zone.
正解:C
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/configure-zone
質問 # 201
Which CLI command enables an administrator to check the CPU utilization of the dataplane?
- A. show running resource-monitor
- B. debug data-plane dp-cpu
- C. debug running resources
- D. show system resources
正解:A
質問 # 202
Refer to the exhibit.
Which certificates can be used as a Forwarded Trust certificate?
- A. Domain Sub-CA
- B. Certificate from Default Trust Certificate Authorities
- C. Domain-Root-Cert
- D. Forward_Trust
正解:B
質問 # 203
A company configures its WildFire analysis profile to forward any file type to the WildFire public cloud. A company employee receives an email containing an unknown link that downloads a malicious Portable Executable (PE) file.
What does Advanced WildFire do when the link is clicked?
- A. Performs malicious content analysis on the linked page: but not the corresponding PE file
- B. Does not perform malicious content analysis on the linked page but performs it on the corresponding PE file
- C. Does not perform malicious content analysis on either the linked page or the corresponding PE file
- D. Performs malicious content analysis on the linked page and the corresponding PE file
正解:D
質問 # 204
What best describes the HA Promotion Hold Time?
- A. the time that is recommended to avoid a failover when both firewalls experience the same link/path monitor failure simultaneously
- B. the time that a passive firewall with a low device priority will wait before taking over as the active firewall if the firewall is operational again
- C. the time that the passive firewall will wait before taking over as the active firewall after communications with the HA peer have been lost
- D. the time that is recommended to avoid an HA failover due to the occasional flapping of neighboring devices
正解:C
解説:
Explanation
HA Promotion Hold Time is the time that the passive firewall will wait before taking over as the active firewall after communications with the HA peer have been lost 2. References: 2: PAN-OS New Features Guide
質問 # 205
An engineer must configure the Decryption Broker feature. To which router must the engineer assign the decryption forwarding interfaces that are used in Decryption Broker security chain?
- A. The virtual router that routes the traffic that the Decryption Broker security chain inspects.
- B. The default virtual router. If there is no default virtual router , the engineer must create one during setup.
- C. A virtual router that has no additional interfaces for passing data-type traffic and no other configured routes than those used for the security chain.
- D. A virtual router that is configured with at least one dynamic routing protocol and has at least one entry in the RIB
正解:A
解説:
Decryption Broker is a feature that allows you to use a Palo Alto Networks firewall as a decryption broker for other security devices in your network. It works by decrypting traffic on one interface and forwarding it to another interface where it can be inspected by other devices before being re- encrypted and sent to its destination. The firewall acts as a transparent bridge between the two interfaces and does not change the source or destination IP addresses of the traffic. To configure Decryption Broker, you need to assign decryption forwarding interfaces (DFIs) to the virtual router that routes the traffic that you want to inspect. The DFIs are used to forward decrypted traffic from one interface to another in a security chain. A security chain is a set of devices that perform different security functions on the same traffic flow. You can have multiple security chains for different types of traffic or different segments of your network. The reason why you need to assign DFIs to the virtual router that routes the traffic is because Decryption Broker uses routing tables to determine which DFI belongs to which security chain and how to forward traffic between them. If you assign DFIs to a different virtual router than the one that routes the traffic, Decryption Broker will not be able to find them or forward traffic correctly.
質問 # 206
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed to multiple remote offices and the Network Administrator decides to use Panorama to deploy the configurations.
How should this be accomplished?
- A. Create a Device Group with the appropriate IKE Gateway settings.
- B. Create a Template with the appropriate lKE Gateway settings.
- C. Create a Template with the appropriate lPSec tunnel settings.
- D. Create a Device Group with the appropriate lPSec tunnel settings.
正解:C
解説:
Note: The administrator of the satellite must enter the credentials when the satellite connects to the portal.
This is done on the satellite by navigating to Network > IPSec Tunnels and choosing "gateway info" and then clicking on "Enter Credentials".
質問 # 207
When overriding a template configuration locally on a firewall, what should you consider?
- A. Panorama will lose visibility into the overridden configuration
- B. The firewall template will show that it is out of sync within Panorama
- C. Only Panorama can revert the override
- D. Panorama will update the template with the overridden value
正解:A
解説:
Based on my knowledge out-of-sync message appear on Panorama only was perform a commit to Panorama but not pushed to the NGFW. https://live.paloaltonetworks.com/t5/general-topics/reason-for-out-of-sync-message-in-panorama/td-p/328292
質問 # 208
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
- A. Check the WebUI Dashboard AutoFocus widget.
- B. Verify AutoFocus is enabled below Device Management tab.
- C. Verify AutoFocus status using CLI.
- D. Check for WildFire forwarding logs.
- E. Check the license
正解:B、E
質問 # 209
Which operation will impact the performance of the management plane?
- A. Generating a SaaS Application report
- B. Enabling DoS protection
- C. Enabling packet buffer protection
- D. Decrypting SSL sessions
正解:A
解説:
Explanation
According to the Palo Alto Networks documentation , generating a SaaS Application report can impact the performance of the management plane because it requires querying and processing a large amount of log data.
Therefore, the correct answer is B.
The other options are not related to the management plane performance:
Decrypting SSL sessions: This option affects the data plane performance, not the management plane performance. Decrypting SSL sessions consumes CPU resources on the data plane, which handles traffic processing and security enforcement Enabling DoS protection: This option also affects the data plane performance, not the management plane performance. Enabling DoS protection allows the firewall to detect and prevent denial-of-service (DoS) attacks by monitoring and limiting the rate of sessions and packets3.
Enabling packet buffer protection: This option also affects the data plane performance, not the management plane performance. Enabling packet buffer protection allows the firewall to monitor and control the packet buffer usage on each interface to prevent buffer exhaustion and packet drops4.
References: 1:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-the-application-command-center-acc
2:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/how-decryption-wo
3:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/prevent-denial-of-service-dos-atta
4: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-packet-buffer-protection
質問 # 210
How would an administrator configure a Bidirectional Forwarding Detection profile for BGP after enabling the Advance Routing Engine run on PAN-OS 10.2?
- A. create a BFD profile under Network > Routing > Routing Profiles > BFD and then select the BFD profile under Network > Virtual Router > BGP > General > Global BFD Profile
- B. create a BFD profile under Network > Network Profiles > BFD Profile and then select the BFD profile under Network > Virtual Router > BGP > BFD
- C. create a BFD profile under Network > Network Profiles > BFD Profile and then select the BFD profile under Network > Routing > Logical Routers > BGP > BFD
- D. create a BFD profile under Network > Routing > Routing Profiles > BFD and then select the BFD profile under Network > Routing > Logical Routers > BGP > General > Global BFD Profile
正解:D
解説:
The Advanced Routing Engine uses Logical Routers, not Virtual Routers.
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/advanced- routing/configure-bgp-on-an-advanced-routing-engine
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/advanced- routing/create-bfd-profiles
質問 # 211
What is the best definition of the Heartbeat Interval?
- A. The frequency at which the HA peers check link or path availability
- B. The interval in milliseconds between hello packets
- C. The interval during which the firewall will remain active following a link monitor failure
- D. The frequency at which the HA peers exchange ping
正解:D
解説:
Explanation
"A "heartbeat-interval" CLI command was added to the election settings for HA, this interval has a 1000ms minimum for all Palo Alto Networks platforms and is an ICMP ping to the other device through the HA control link."https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMaCAK
質問 # 212
Given the following snippet of a WildFire submission log, did the end user successfully download a file?
- A. No, because the action for the wildfire-virus is "reset-both."
- B. Yes, because the final action is set to "allow.''
- C. Yes, because both the web-browsing application and the flash file have the 'alert" action.
- D. No, because the URL generated an alert.
正解:A
解説:
* URL profile action alert.
* File Profile action alert.
* AV and Wildfire action Reset-both
* Policy Action Allow.
The firewall inspects the content as per all the security profiles attached to the original matching rule. If it results in threat detection, then the corresponding security profile action is taken.
質問 # 213
An administrator accidentally closed the commit window/screen before the commit was finished. Which two
options could the administrator use to verify the progress or success of that commit task? (Choose two.)
A:
B:
C:
D:
- A. Option B
- B. Option C
- C. Option D
- D. Option A
正解:C、D
質問 # 214
If an administrator does not possess a website's certificate, which SSL decryption mode will allow the Palo Alto networks NGFW to inspect when users browse to HTTP(S) websites?
- A. SSL Forward Proxy
- B. TLS Bidirectional proxy
- C. SSL Outbound Inspection
- D. SSL Inbound Inspection
正解:A
解説:
https://live.paloaltonetworks.com/t5/Learning-Articles/Difference-Between-SSL-Forward-Proxy- and-Inbound-Inspection/ta-p/55553
質問 # 215
......
Palo Alto NetworksのPCNSE認定試験は、ネットワークセキュリティの分野で専門知識を証明したい専門家にとって、高く評価され、求められている資格です。この認定は、Palo Alto Networks次世代ファイアウォールの展開、設計、構成、維持、トラブルシューティングを担当するセキュリティエンジニア向けに設計されています。PCNSE認定試験は、候補者がPalo Alto Networksネットワークセキュリティプラットフォームを管理および管理するための知識とスキルをテストします。
Palo Alto NetworksのPCNSE(Palo Alto Networks Certified Security Engineer)認定試験は、ITセキュリティ専門家にとって非常に求められる認定資格です。この認定資格は、リアルワールド環境でのPalo Alto Networksの次世代ファイアウォールの展開、管理、トラブルシューティングに必要なスキルと知識を検証するために設計されています。この認定資格は、セキュリティ管理者、ネットワークエンジニア、サポートスタッフを含む、Palo Alto Networksのファイアウォールの展開と管理を担当する個人を対象としています。
厳密検証されたPCNSE問題集と解答でPCNSE問題集と正解付き:https://www.jpntest.com/shiken/PCNSE-mondaishu
ベストPCNSE PAN-OS学習ガイドPCNSE試験:https://drive.google.com/open?id=1Q45i6oGjYqJiy04OaZCx5JHSIuesT03V