2025年最新のPCNSE日本語問題集にはPCNSE認証済み試験問題と解答 [Q227-Q242]

Share

2025年最新のPCNSE日本語問題集にはPCNSE認証済み試験問題と解答

実際に出ると確認されたPCNSE日本語試験問題集と解答でPCNSE日本語無料更新

質問 # 227
アクティブ/パッシブのペアとして構成されたファイアウォールを含むファイアウォール クラスターを実装する場合、HA4 インターフェイスはどの機能を提供しますか?

  • A. ルート、IPSec セキュリティ アソシエーション、およびユーザー ID 情報の同期を実行します。
  • B. セッションのセットアップ中および非対称トラフィック フロー中に、アクティブ/パッシブ ピアへのパケット転送を実行します。
  • C. 同じクラスター ID を持つすべての HA クラスター メンバーに対してセッション キャッシュの同期を実行します。
  • D. HA ペア内のファイアウォール間で、セッション、転送テーブル、および IPSec セキュリティ アソシエーションの同期を実行します。

正解:D

解説:
In a High Availability (HA) configuration, particularly in an active-passive setup, it's crucial that the passive unit is kept up to date with the current state of the active unit. This ensures a seamless transition in the event of a failover. The HA4 interface is dedicated to this synchronization task.
D . Perform synchronization of sessions, forwarding tables, and IPSec security associations between firewalls in an HA pair:
The HA4 interface is responsible for the synchronization of critical stateful information between the active and passive units in an HA pair. This includes session information, ensuring that the passive unit can continue existing sessions without interruption if it needs to become active.
In addition to session information, HA4 also synchronizes forwarding tables, which contain information on how to route packets, and IPSec security associations, which are necessary for maintaining secure VPN tunnels.
This synchronization ensures that both units in an HA pair have identical information regarding the current state of the network, sessions, and security associations, enabling a smooth and immediate transition to the passive unit in case the active unit fails.


質問 # 228
管理者が、リソースの枯渇を防ぐために、Palo Alto Networks NGFWで保護設定を定義しています。 プラットフォーム使用率を考慮した場合、管理者はパケットバッファ保護を設定して適用するためにどの手順を実行する必要がありますか。

  • A. すべての入力ゾーンにゾーン保護プロファイルを作成して適用します。入力ゾーンごとにパケットバッファ保護を有効にします。
  • B. すべての出力ゾーンに対してゾーン保護プロファイルを設定および適用します。出力ゾーンの前にパケットバッファ保護を有効にします。
  • C. パケットバッファしきい値を有効にしてから設定するインターフェイスバッファ保護を有効にします。
  • D. パケットバッファ保護しきい値を有効にして設定します。入力ゾーンごとにパケットバッファ保護を有効にします。
  • E. vsysごとのセッションしきい値アラートを有効にし、パケットバッファ制限をトリガーします。ゾーンごとにゾーンバッファ保護を有効にします。

正解:D


質問 # 229
PA5260でSSLFrowardProxyを構成することを計画している場合、ユーザーは、パロアルトネットワークスのベストプラクティスに沿った段階的アプローチを使用してSSL復号化を実装する方法を尋ねます。

  • A. 既知の悪意のある送信元IPアドレスのSSL復号化を有効にする
  • B. ソースユーザーと既知の悪意のあるURLカテゴリに対してSSL復号化を有効にする
  • C. 既知の悪意のある宛先IPアドレスのSSL復号化を有効にする
  • D. 悪意のあるソースユーザーに対してSSL復号化を有効にする

正解:B

解説:
According to the Palo Alto Networks best practices, one of the ways to implement SSL decryption using a phased approach is to enable SSL decryption for source users and known malicious URL categories. This will allow you to block or alert on traffic that is likely to be malicious or risky, while minimizing the impact on legitimate traffic and user privacy. Reference: https://docs.paloaltonetworks.com/best-practices/9-1/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-a-phased-approach


質問 # 230
画像を参照してください。

管理者は、グローバル テンプレート NTP サーバーを使用できないファイアウォールの NTP サービス構成を修正する必要があります。管理者は、このテンプレート スタックに適したサーバーに IP アドレスを変更する必要がありますが、他のテンプレート スタックに影響を与えることはできません。
問題はどのように修正できますか?

  • A. パノラマ設定で「先祖で定義されたオブジェクトが優先される」を有効にします。
  • B. NYCFW テンプレートの値をオーバーライドします。
  • C. グローバル テンプレートの値をオーバーライドします。
  • D. テンプレート スタック変数を使用してテンプレート値をオーバーライドします。

正解:D

解説:
Both templates and template stacks support variables. Variables allow you to create placeholder objects with their value specified in the template or template stack based on your configuration needs. Create a template or template stack variable to replace IP addresses, Group IDs, and interfaces in your configurations. https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/manage-templates-and-template-stacks/override-a-template-setting.html


質問 # 231
PAS-OS 7.0 では、ログ パターンを分析し、新しいアプリケーション コマンド センター (ACC) に表示される相関イベントを生成する自動相関エンジンが導入されました。
新しい相関目標を取得するには、ファイアウォールにどのライセンスが必要ですか?

  • A. グローバルプロテクト
  • B. URLフィルタリング
  • C. アプリケーションセンター
  • D. 脅威の防止

正解:D


質問 # 232
管理者は、アクティブな脅威防止サブスクリプションを備えたPA-820ファイアウォールを持っています。管理者は、WildFireサブスクリプションの追加を検討しています。WildFireサブスクリプションを追加すると、組織のセキュリティ体制がどのように改善されますか1。

  • A. WildFireとThreat Preventionを組み合わせて、攻撃対象領域を最小限に抑えます
  • B. 24時間後、WildFire署名がウイルス対策アップデートに含まれます
  • C. WildFireとThreat Preventionを組み合わせて、ファイアウォールに最大限のセキュリティ体制を提供します
  • D. 未知のマルウェアに対する保護をほぼリアルタイムで提供できます

正解:D

解説:
Explanation
Adding a WildFire subscription can improve the security posture of the organization by providing protection against unknown malware in near real-time. With a WildFire subscription, the firewall can forward various file types for WildFire analysis, and can retrieve WildFire signatures for newly-discovered malware as soon as they are generated by the WildFire public cloud or a private cloud appliance. This reduces the exposure window and prevents further infection by the same malware.
References:https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/wildfire-subscriptio


質問 # 233
ファイアウォール管理者は、多くのホスト スイープ スキャン攻撃が外部ゾーンから発信されたファイアウォールを介して許可されていることに気付きました。この種の攻撃を軽減するために、ファイアウォール管理者は何をすべきですか?

  • A. SYN フラッド保護を有効にして DOS 保護プロファイルを作成し、ゾーン外からのトラフィックを許可するすべてのルールに適用します。
  • B. ゾーン保護プロファイルを作成し、偵察保護を有効にし、アクションをブロックに設定し、ゾーン外に適用します。
  • C. 外部ゾーンでパケット バッファ保護を有効にします。
  • D. 外部ゾーンからのすべての ICMP トラフィックを拒否するセキュリティ ルールを作成します。

正解:B

解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/configure-zone


質問 # 234
管理者は、特定の期間、更新プログラムのインストールを延期しながら、アプリケーションおよび脅威の動的更新をどのようにスケジュールするのですか?

  • A. 「しきい値」のオプションを設定します。
  • B. 自動的に "ダウンロードしてインストールする"が、 "新しいアプリケーションを無効にする"オプションが使用されます。
  • C. 平日に自動更新を無効にする。
  • D. 管理者が更新プログラムを承認した後、自動的に「ダウンロードのみ」し、その後、アプリケーションと脅威をインストールします。

正解:A

解説:
Explanation
For Antivirus and Applications and Threats updates, you have the option to set a minimum Threshold of time that a content update must be available before the firewall installs it. Very rarely, there can be an error in a content update and this threshold ensures that the firewall only downloads content releases that have been available and functioning in customer environments for the specified amount of time.
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/device/device-dynamic-updates
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/device/device-dynamic-updates.html


質問 # 235
脅威管理チームのメンバーは、この社内アプリケーションは非常に敏感であると識別されているすべてのトラフィックをContent-IDエンジンで検査する必要があります述べています。
company.comがパロアルトネットワークデバイス上のこのトラフィックに直ちに対処するために使用する方法はどれですか?

  • A. Palo Alto Networksから公式のアプリケーション署名が提供されるまで待ちます。
  • B. シグネチャなしでカスタムアプリケーションを作成し、トラフィックの送信元、宛先、宛先ポート/プロトコル、およびカスタムアプリケーションを含むアプリケーションオーバーライドポリシーを作成します。
  • C. 社内アプリケーショントラフィックの唯一の識別子に一致するシグネチャでカスタムアプリケーションを作成する
  • D. 社内アプリケーションのニーズを満たすために最も近い参照アプリケーションのセッションタイマー設定を変更する

正解:C

解説:
Create a Custom Application with a signature and attach it to a security policy, or create a custom application and define an application override policy--A custom application allows you to customize the definition of the internal application--its characteristics, category and sub-category, risk, port, timeout--and exercise granular policy control in order to minimize the range of unidentified traffic on your network. Creating a custom application also allows you to correctly identify the application in the ACC and traffic logs and is useful in auditing/reporting on the applications on your network. For a custom application you can specify a signature and a pattern that uniquely identifies the application and attach it to a security policy that allows or denies the application.
Alternatively, if you would like the firewall to process the custom application using fast path (Layer-4 inspection instead of using App-ID for Layer-7 inspection), you can reference the custom application in an application override policy rule. An application override with a custom application will prevent the session from being processed by the App-ID engine, which is a Layer-7 inspection. Instead it forces the firewall to handle the session as a regular stateful inspection firewall at Layer-4, and thereby saves application processing time.
For example, if you build a custom application that triggers on a host header www.mywebsite.com, the packets are first identified as web-browsing and then are matched as your custom application (whose parent application is web-browsing). Because the parent application is web-browsing, the custom application is inspected at Layer-7 and scanned for content and vulnerabilities.
If you define an application override, the firewall stops processing at Layer-4. The custom application name is assigned to the session to help identify it in the logs, and the traffic is not scanned for threats.
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/app-id/manage-custom-or- unknown-applications.html#id74b58a78-164f-4dc5-aa4e-31ce62f2af0d


質問 # 236
すべてのIPアドレスからユーザーへのマッピングを常に明示的に知る必要がある高セキュリティ環境で使用する必要があるユーザーIDマッピング方法はどれですか?

  • A. WindowsベースのユーザーIDエージェント
  • B. GlobalProtect
  • C. LDAPサーバープロファイルの構成
  • D. PAN-OS統合ユーザーIDエージェント

正解:B


質問 # 237
展示を参照してください。

上の ACC のスクリーンショットを使用して、グローバル フィルターを設定し、ブロックされたユーザー アクティビティを絞り込み、ボットネットによって侵害される可能性のあるユーザーを特定するための最良の方法は何ですか?

  • A. ホットポート脅威カテゴリのハイパーリンクをクリックします。
  • B. Zero Access.Gen 脅威の横にある左矢印をクリックします。
  • C. Zero Access.Gen 脅威のハイパーリンクをクリックします。
  • D. 脅威数が最も多い送信元ユーザーをクリックします。

正解:B

解説:
Explanation
Hover over an attribute in the table below the chart and click the arrow icon to the right of the attribute.
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-the-application-command-center/int


質問 # 238
管理者がWildfire分析のために新たに見つかったスパイウェアの一部を提出しました。 スパイウェアは、ユーザーの知識なしに動作をパッシブに監視します。
WildFireの予想される評決は何ですか?

  • A. Malware
  • B. Phishing
  • C. Gray ware
  • D. Spyware

正解:C

解説:
Explanation
Wildfire verdictions are as follow1-Begnin2-Greyware3-Mallicious4-Phishing
https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/wildfire-overview/wildfire-concepts/ve The sample does not pose a direct security threat, but might display otherwise obtrusive behavior. Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs)


質問 # 239
管理者は、ビデオ トラフィックが適切に分類されない理由のトラブルシューティングを行っています。
このトラフィックがどの QoS クラスにも一致しない場合、どのデフォルト クラスが割り当てられますか?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:C

解説:
The default class that is assigned to traffic that does not match any QoS classes is class 4. Class 4 is the default class for any session not matched to a QoS policy. QoS policy, like security policy, is processed top to bottom and the first policy match will be applied. If no policy match is found, the traffic is assigned to class 412. Option A is incorrect because class 1 is not the default class for unmatched traffic. Class 1 is a user-defined class that can be used to assign traffic based on QoS policy criteria. Option B is incorrect because class 2 is not the default class for unmatched traffic. Class 2 is a user-defined class that can be used to assign traffic based on QoS policy criteria. Option C is incorrect because class 3 is not the default class for unmatched traffic. Class 3 is a user-defined class that can be used to assign traffic based on QoS policy criteria3.


質問 # 240

  • A. RADIUS
  • B. Kerberos
  • C. TACACS+
  • D. PAP
  • E. LDAP
  • F. SAML

正解:A、C、E


質問 # 241
ユーザーが認証を必要とするサービスにアクセスするための依存関係は何ですか?

  • A. それらのサービスを含む認証シーケンス
  • B. これらのサービスを含む認証プロファイル
  • C. 認証タイムアウトの無効化
  • D. ユーザーがそれらのサービスにアクセスできるようにするセキュリティ ポリシー

正解:D

解説:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authentication- policy/configure-authentication-policy


質問 # 242
......

実際問題を使ってPCNSE日本語問題集で100%無料PCNSE日本語試験問題集:https://www.passtest.jp/Palo-Alto-Networks/PCNSE-JPN-shiken.html