[Q20-Q44] 実際にあるPCNSE問題集でリアルPalo Alto Networks問題集PDFを提供しています [2025年01月]

Share

実際にあるPCNSE問題集でリアルPalo Alto Networks問題集PDFを提供しています [2025年01月]

実際のJPNTest PCNSE問題集PDFで100%合格率を保証します


PCNSE認定試験は、同社の次世代ファイアウォールで使用されるオペレーティングシステムであるPalo Alto Networks Pan-OS 10.0の最新バージョンに基づいています。試験は、筆記試験と実用的な試験の2つの部分に分かれています。筆記試験は、試験でカバーされている概念に関する候補者の知識をテストする75の複数選択質問で構成されています。一方、実際の試験は、Palo Alto Networksの次世代ファイアウォールを構成およびトラブルシューティングする候補者の能力をテストする実践的なラボです。 2年間有効なPCNSE認定を獲得するには、両方の試験に合格する必要があります。


この試験は、120分以内に完了する必要がある75問の多肢選択問題で構成されています。問題は、候補者のPalo Alto Networksのファイアウォールに関する知識と、その知識をリアルワールドのシナリオに適用する能力をテストするように設計されています。この試験は、英語、日本語、スペイン語、フランス語、ドイツ語など、複数の言語で利用可能です。

 

質問 # 20
Why would a traffic log list an application as "not-applicable"?

  • A. The application is not a known Palo Alto Networks App-ID.
  • B. The TCP connection terminated without identifying any application data
  • C. There was not enough application data after the TCP connection was established
  • D. The firewall denied the traffic before the application match could be performed.

正解:D

解説:
According to the documentation, not-applicable means that the Palo Alto device has received data that will be discarded because the port or service that the traffic is coming in on is not allowed, or there is no rule or policy allowing that port or service. This occurs because the traffic was dropped or denied before the application match could be performed. Reference: 1 Not-applicable in Traffic Logs - Palo Alto Networks 2 Not-Applicable, Incomplete, Insufficient Data in the Application Field - Palo Alto Networks
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClspCAC


質問 # 21
Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?

  • A. check
  • B. find
  • C. sim
  • D. test

正解:D

解説:
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQSCA0


質問 # 22
An engineer is troubleshooting a traffic-routing issue.
What is the correct packet-flow sequence?

  • A. PBF > Zone Protection Profiles > Packet Buffer Protection
  • B. BGP < PBF > NAT
  • C. NAT > Security policy enforcement > OSPF
  • D. PBF > Static route > Security policy enforcement

正解:D

解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0 Under Slowpath(session setup stage) PBF, then static routes and then policy enforment.


質問 # 23
Which type of zone will allow different virtual systems to communicate with each other?

  • A. Virtual Wire
  • B. External
  • C. Tap
  • D. Tunnel

正解:B

解説:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/virtual-systems/communication-between-virtual-systems/inter-vsys-traffic-that-remains-within-the-firewall/external-zone


質問 # 24
Which Palo Alto Networks VM-Series firewall is valid?

  • A. VM-50
  • B. VM-400
  • C. VM-25
  • D. VM-800

正解:A

解説:
Reference:
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series-firewall/vm-series-models.html


質問 # 25
Which event will happen if an administrator uses an Application Override Policy?

  • A. Threat-ID processing time is decreased.
  • B. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.
  • C. App-ID processing time is increased.
  • D. The application name assigned to the traffic by the security rule is written to the Traffic log.

正解:A

解説:
Reference:
https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/app-id/manage-custom-or-unknown- applications#


質問 # 26
A firewall administrator requires an A/P HA pair to fail over more quickly due to critical business application uptime requirements.
What is the correct setting?

  • A. Change the HA timer profile to "aggressive" or customize the settings in advanced profile.
  • B. Change the HA timer profile to "fast".
  • C. Change the HA timer profile to "quick" and customize in advanced profile.
  • D. Change the HA timer profile to "user-defined" and manually set the timers.

正解:A

解説:
Use the Recommended profile for typical failover timer settings and the Aggressive profile for faster failover timer settings. The Advanced profile allows you to customize the timer values to suit your network requirements. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-timers.html


質問 # 27
An administrator Just enabled HA Heartbeat Backup on two devices However, the status on tie firewall's dashboard is showing as down High Availability.

What could an administrator do to troubleshoot the issue?

  • A. Go to Device > High Availability > HA Communications> General> and check the Heartbeat Backup under Election Settings
  • B. Go to Device > High Availability> General > HA Pair Settings > Setup and configuring the peer IP for heartbeat backup
  • C. Check peer IP address In the permit list In Device > Setup > Management > Interfaces > Management Interface Settings
  • D. Check peer IP address for heartbeat backup to Device > High Availability > HA Communications > Packet Forwarding settings.

正解:A


質問 # 28
What should an administrator consider when planning to revert Panorama to a pre-PAN-OS 8.1 version?

  • A. Panorama cannot be reverted to an earlier PAN-OS release if variables are used in templates or
    template stacks.
  • B. Administrators need to manually update variable characters to those used in pre-PAN-OS 8.1.
  • C. An administrator must use the Expedition tool to adapt the configuration to the pre-PAN-OS 8.1 state.
  • D. When Panorama is reverted to an earlier PAN-OS release, variables used in templates or template
    stacks will be removed automatically.

正解:A

解説:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-
pan-os-81/upgradedowngrade-considerations


質問 # 29
An administrator creates an application-based security policy rule and commits the change to the firewall. Which two methods should be used to identify the dependent applications for the respective rule? (Choose two.)

  • A. Open the security policy rule and review the Depends On application list.
  • B. Review the App Dependency application list from the Commit Status view.
  • C. Reference another application group containing similar applications.
  • D. Use the show predefined xpath <value> command and review the output.

正解:A、B

解説:
These two methods allow the administrator to see the dependent applications for a security policy rule that uses application-based criteria. The App Dependency application list shows the applications that are required for the rule to function properly1. The Depends On application list shows the applications that are implicitly added to the rule based on the predefined dependencies2. Reference: 1: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/app-id-features/simplified-application-dependency-workflow 2: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/use-application-objects-in-policy/resolve-application-dependencies


質問 # 30
Which Panorama administrator types require the configuration of at least one access domain?
(Choose two.)

  • A. Device Group
  • B. Template Admin
  • C. Custom Panorama Admin
  • D. Dynamic
  • E. Role Based

正解:A、B

解説:
https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/role- based-access-control/access-domains


質問 # 31
Refer to the diagram. Users at an internal system want to ssh to the SSH server The server is configured to respond only to the ssh requests coming from IP 172.16.16.1.
In order to reach the SSH server only from the Trust zone, which Security rule and NAT rule must be configured on the firewall?

A)

B)

C)

D)

  • A. Option B
  • B. Option C
  • C. Option A
  • D. Option D

正解:B


質問 # 32
An engineer is creating a template and wants to use variables to standardize the configuration across a large number of devices Which Mo variable types can be defined? (Choose two.)

  • A. IP netmask
  • B. Path group
  • C. FQDN
  • D. Zone

正解:A、C

解説:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/panorama-web-interface/panorama-templates/panorama-templates-template-variable


質問 # 33
Which protection feature is available only in a Zone Protection Profile?

  • A. SYN Flood Protection using SYN Flood Cookies
  • B. UDP Flood Protections
  • C. ICMP Flood Protection
  • D. Port Scan Protection

正解:D

解説:
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/network/network-network-profiles-zone-protection


質問 # 34
In the following image from Panorama, why are some values shown in red?

  • A. sg2 has misconfigured session thresholds.
  • B. uk3 has a logging rate that deviates from the seven-day calculated baseline.
  • C. us3 has a logging rate that deviates from the administrator-configured thresholds.
  • D. sg2 session count is the lowest compared to the other managed devices.

正解:B

解説:
https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/panorama- features/device-monitoring-through-panorama


質問 # 35
A company has configured a URL Filtering profile with override action on their firewall. Which two profiles are needed to complete the configuration? (Choose two)

  • A. Interface Management
  • B. HTTP Server
  • C. Decryption
  • D. SSL/TLS Service

正解:A、D

解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRdCAK
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/url-filtering/configure-url-filtering
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/url-filtering/allow-password-access-to-certain-sites


質問 # 36
An administrator would like to determine which action the firewall will take for a specific CVE. Given the screenshot below, where should the administrator navigate to view this information?

  • A. The profile rule action
  • B. Exceptions lab
  • C. The profile rule threat name
  • D. CVE column

正解:B

解説:
Explanation
The Exceptions settings allows you to change the response to a specific signature. For example, you can block all packets that match a signature, except for the selected one, which generates an alert. The Exception tab supports filtering functions.
If you not believed, then login the firewall go to Vulnerability > Exceptions and select "Show all signatures".
From there you will see all threat information including specific actions.
More detail: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm4yCAC


質問 # 37
Where can a service route be configured for a specific destination IP?

  • A. Use Device > Setup > Services > Service Route Configuration > Customize > IPv4
  • B. Use Device > Setup > Services > Service Route Configuration > Customize > Destination
  • C. Use Network > Virtual Routers, select the Virtual Router > Static Routes > IPv4
  • D. Use Device > Setup > Services > Services

正解:A

解説:
A service route is the path from the interface to the service on a server. By default, the firewall uses the management interface to communicate to various servers, including DNS, Email, Palo Alto Updates, User-ID agent, Syslog, Panorama, dynamic updates, URL updates, licenses, and AutoFocus. etc. Sometimes, it is necessary to use an alternative path other than Firewall management IP due to many restrictions. To configure service routes for non-predefined services, the destination addresses can be manually entered in the Destination section under Device > Setup > Services > Service Route Configuration > Customize1. Option A is incorrect because it is used to configure static routes for network traffic, not service routes for firewall services. Option B is incorrect because it is used to configure general service settings such as NTP server and proxy server, not service routes for specific destinations. Option D is incorrect because it is used to configure service routes for predefined services such as DNS and Syslog, not service routes for non-predefined services2.


質問 # 38
How can a candidate or running configuration be copied to a host external from Panorama?

  • A. Save a configuration snapshot.
  • B. Commit a running configuration.
  • C. Save a candidate configuration.
  • D. Export a named configuration snapshot.

正解:D

解説:
Reference:
https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/administer-panorama/ba panorama-and-firewall-configurations


質問 # 39
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans.
Which Security Profile type will protect against worms and trojans?

  • A. Antivirus
  • B. Anti-Spyware
  • C. Instruction Prevention
  • D. File Blocking

正解:A

解説:
Explanation/Reference: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/security-profiles


質問 # 40
For which two reasons would a firewall discard a packet as part of the packet flow sequence? (Choose two )

  • A. equal-cost multipath
  • B. rule match with action "deny"
  • C. ingress processing errors
  • D. rule match with action "allow"

正解:B、C

解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0
Denying traffic will discard the packet. Packets can also be discarded due to malformed or incorrect frames, datagrams or packets.


質問 # 41
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?

  • A. Both SSH keys and SSL certificates must be generated.
  • B. SSL certificates must be generated.
  • C. SSH keys must be manually generated.
  • D. No prerequisites are required.

正解:D

解説:
Explanation/Reference:
Reference: https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/configure-ssh- proxy


質問 # 42
An administrator needs to troubleshoot a User-ID deployment The administrator believes that there is an issue related to LDAP authentication The administrator wants to create a packet capture on the management plane Which CLI command should the administrator use to obtain the packet capture for validating the configuration^

  • A. > scp export pcap from pcap to (usernameQhost:path)
  • B. > ftp export mgmt-pcap from mgmt.pcap to <FTP host>
  • C. > scp export pcap-mgmt from pcap.mgiat to (username@host:path)
  • D. > scp export mgmt-pcap from mgmt.pcap to {usernameQhost:path>

正解:C


質問 # 43
Which three authentication types can be used to authenticate users? (Choose three.)

  • A. Cloud authentication service
  • B. GlobalProtect client
  • C. PingID
  • D. Local database authentication
  • E. Kerberos single sign-on

正解:C、D、E

解説:
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/authentication/authentication-types


質問 # 44
......


Palo Alto NetworksのPCNSE認定試験は、認定セキュリティエンジニアになることを目指す個人を対象としています。この包括的な試験は、Palo Alto Networksセキュリティソリューションを設計、展開、構成、トラブルシューティングするために必要なスキルと知識をカバーしています。この試験は、最新のPAN-OS 10.0プラットフォームに基づいており、これまでで最も高度なソフトウェアバージョンです。

 

検証済みPCNSE問題集と解答で最新PCNSEをダウンロード:https://www.jpntest.com/shiken/PCNSE-mondaishu

無料Palo Alto Networks PCNSE試験問題と解答があります:https://drive.google.com/open?id=1zkLPtcAE9QZKgCjwcIfm0kQpqYoesIGq

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡