Palo Alto Networks Certified Network Security Consultant - PCNSC 模擬練習

In an HA (High Availability) setup, what is the purpose of the HA3 link?

正解: D
Which CLI command should you use to verify whether all SFP SFP*, or QSFP modules are installed in a firewall?

正解: D
解説: (PassTest メンバーにのみ表示されます)
A customer has a five-year-old firewall in production in the time since the firewall was installed, the IT team deleted unused security policies on a regular basis but they did not remove the address objects and groups that were part ofthese security policies.
What is the best way to delete all of the unused address objects on the firewall?

正解: A
解説: (PassTest メンバーにのみ表示されます)
A customer has a pair of Panorama HA appliances tunning local log collectors and wants to have log redundancy on logs forwarded from firewalls Which two configuration options fulfill the customer's requirement for log redundancy? (Choose two)

正解: B,D
解説: (PassTest メンバーにのみ表示されます)
Which GlobalProtect feature ensures that only trusted endpoints can connect to the network?

正解: A
Which of the following is a primary use case for the Decryption Broker feature?

正解: A
Match the task for server settings in group mapping with its order in the process.
正解:

Explanation:
To configure group mapping on a Palo Alto Networks firewall, follow these steps in order:
* Navigate to Device > User Identification > Group Mapping:
* This is the initial step where you access the group mapping settings in the web interface.
* Add a new group mapping:
* After navigating to the group mapping section, the next step is to add a new group mapping configuration.
* Enter a unique name to identify the group mapping configuration:
* Provide a unique and descriptive name for the new group mapping configuration to easily identify it.
* Create an LDAP Server Profile:
* This step involves creating an LDAP Server Profile, which defines the connection settings for the LDAP server that will be queried for user and group information.
* Select the LDAP Server Profile:
* Finally, associate the created LDAP Server Profile with the group mapping configuration. This links the group mapping to the specific LDAP server.
Order in Process:
* Navigate to Device > User Identification > Group Mapping
* Add a new group mapping.
* Enter a unique name to identify the group mapping configuration.
* Create an LDAP Server Profile.
* Select the LDAP Server Profile.
References:
* Palo Alto Networks - Configuring Group Mapping:
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/user-id/map-users-to-groups
* Palo Alto Networks - User-ID Agent and Group Mapping Configuration:
https://knowledgebase.paloaltonetworks.com