PCNSA問題集を掴み取れ![最新2022]Palo Alto Networks試験合格させます [Q48-Q73]

Share

PCNSA問題集を掴み取れ![最新2022]Palo Alto Networks試験合格させます

PCNSA試験問題集PDF正確率保証と更新された問題

質問 48
Which two components are utilized within the Single-Pass Parallel Processing architecture on a Palo Alto Networks Firewall? (Choose two.)

  • A. QoS-ID
  • B. App-ID
  • C. User-ID
  • D. Layer-ID

正解: B,C

解説:
Explanation/Reference: http://www.firewall.cx/networking-topics/firewalls/palo-alto-firewalls/1152-palo-alto-firewall-single- pass-parallel-processing-hardware-architecture.html

 

質問 49
Which administrator type utilizes predefined roles for a local administrator account?

  • A. Device administrator
  • B. Superuser
  • C. Role-based
  • D. Dynamic

正解: D

解説:
References:

 

質問 50

Given the topology, which zone type should interface E1/1 be configured with?

  • A. Tunnel
  • B. Layer3
  • C. Tap
  • D. Virtual Wire

正解: C

 

質問 51
Which data flow direction is protected in a zero trust firewall deployment that is not protected in a perimeter-only firewall deployment?

  • A. outbound
  • B. north south
  • C. inbound
  • D. east west

正解: D

 

質問 52
You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact a command-and-control server.
Which Security Profile detects and prevents this threat from establishing a command-and-control connection?

  • A. Vulnerability Protection Profile applied to outbound Security policy rules.
  • B. Antivirus Profile applied to outbound Security policy rules
  • C. Data Filtering Profile applied to outbound Security policy rules.
  • D. Anti-Spyware Profile applied to outbound security policies.

正解: D

 

質問 53
Which path in PAN-OS 10.0 displays the list of port-based security policy rules?

  • A. Policies> Security> Rule Usage> Unused Apps
  • B. Policies> Security> Rule Usage> No App Specified
  • C. Policies> Security> Rule Usage> Port only specified
  • D. Policies> Security> Rule Usage> Port-based Rules

正解: B

解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/security-policy-rule-optimization/migrate-po

 

質問 54
Which update option is not available to administrators?

  • A. New Spyware Notifications
  • B. New Application Signatures
  • C. New Antivirus Signatures
  • D. New URLs
  • E. New Malicious Domains

正解: D

解説:
Explanation/Reference:

 

質問 55
The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.
Which security profile feature could have been used to prevent the communication with the CnC server?

  • A. Create an anti-spyware profile and enable DNS Sinkhole
  • B. Create an antivirus profile and enable DNS Sinkhole
  • C. Create a security policy and enable DNS Sinkhole
  • D. Create a URL filtering profile and block the DNS Sinkhole category

正解: A

解説:
Explanation/Reference: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/objects/objects-security- profiles-anti-spyware-profile

 

質問 56
Which statement is true regarding a Prevention Posture Assessment?

  • A. It performs over 200 security checks on Panorama/firewall for the assessment
  • B. It provides a percentage of adoption for each assessment area
  • C. The Security Policy Adoption Heatmap component filters the information by device groups, serial numbers, zones, areas of architecture, and other categories
  • D. It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture

正解: D

解説:
Explanation/Reference: https://docs.paloaltonetworks.com/best-practices/8-1/data-center-best-practices/data-center-best- practice-security-policy/use-palo-alto-networks-assessment-and-review-tools

 

質問 57
Which two statements are correct about App-ID content updates? (Choose two.)

  • A. Updated application content may change how security policy rules are enforced
  • B. Existing security policy rules are not affected by application content updates
  • C. After an application content update, new applications are automatically identified and classified
  • D. After an application content update, new applications must be manually classified prior to use

正解: B,C

 

質問 58

Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH. web-browsing and SSL applications Which policy achieves the desired results?
A)

B)

C)

D)

  • A. Option
  • B. Option
  • C. Option
  • D. Option

正解: A

 

質問 59
An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?

  • A. Create an Application Filter and name it Office Programs, the filter it on the business-systems category, office-programs subcategory
  • B. Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office An application filter is an object that dynamically groups applications based on application attributes that you define, including category, subcategory, technology, risk factor, and characteristic. This is useful when you want to safely enable access to applications that you do not explicitly sanction, but that you want users to be able to access. For example, you may want to enable employees to choose their own office programs (such as Evernote, Google Docs, or Microsoft Office 365) for business use. To safely enable these types of applications, you could create an application filter that matches on the Category business-systems and the Subcategory office-programs. As new applications office programs emerge and new App-IDs get created, these new applications will automatically match the filter you defined; you will not have to make any additional changes to your policy rulebase to safely enable any application that matches the attributes you defined for the filter.
  • C. Create an Application Filter and name it Office Programs, then filter it on the business-systems category
  • D. Create an Application Group and add business-systems to it

正解: A

解説:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/use-application-objects-in -policy/create-an-application-filter.html

 

質問 60
An administrator notices that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would the administrator need to monitor and block to mitigate the malicious activity?

  • A. branch office traffic
  • B. perimeter traffic
  • C. north-south traffic
  • D. east-west traffic

正解: D

 

質問 61
At which point in the app-ID update process can you determine if an existing policy rule is affected by an app-ID update?

  • A. after downloading the update
  • B. after connecting the firewall configuration
  • C. after installing the update
  • D. after clicking Check New in the Dynamic Update window

正解: A

 

質問 62
Given the screenshot what two types of route is the administrator configuring? (Choose two )

  • A. default route
  • B. static route
  • C. OSPF
  • D. BGP

正解: A

 

質問 63
Given the image, which two options are true about the Security policy rules. (Choose two.)

  • A. The Allow Office Programs rule is using an Application Filter
  • B. In the Allow Social Networking rule, allows all of Facebook's functions
  • C. In the Allow FTP to web server rule, FTP is allowed using App-ID
  • D. The Allow Office Programs rule is using an Application Group

正解: B,C

 

質問 64
Given the cyber-attack lifecycle diagram identify the stage in which the attacker can run malicious code against a vulnerability in a targeted machine.

  • A. Installation
  • B. Exploitation
  • C. Act on the Objective
  • D. Reconnaissance

正解: B

 

質問 65
Match the network device with the correct User-ID technology.

正解:

解説:

 

質問 66
How does an administrator schedule an Applications and Threats dynamic update while delaying installation of the update for a certain amount of time?

  • A. Automatically "download only" and then install Applications and Threats later, after the administrator approves the update
  • B. Configure the option for "Threshold"
  • C. Automatically "download and install" but with the "disable new applications" option used
  • D. Disable automatic updates during weekdays

正解: B

 

質問 67
Which protocol used to map username to user groups when user-ID is configured?

  • A. RADIUS
  • B. SAML
  • C. LDAP
  • D. TACACS+

正解: C

 

質問 68
How many zones can an interface be assigned with a Palo Alto Networks firewall?

  • A. four
  • B. one
  • C. two
  • D. three

正解: B

解説:
Explanation/Reference:
Reference: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/network/network- zones/security-zone-overview

 

質問 69
Which dynamic update type includes updated anti-spyware signatures?

  • A. Applications and Threats
  • B. GlobalProtect Data File
  • C. Antivirus
  • D. PAN-DB

正解: A

 

質問 70
How is the hit count reset on a rule?

  • A. with a dataplane reboot
  • B. in the CLI, type command reset hitcount <POLICY-NAME>
  • C. select a security policy rule, right click Hit Count > Reset
  • D. Device > Setup > Logging and Reporting Settings > Reset Hit Count

正解: C

 

質問 71
What do dynamic user groups you to do?

  • A. create a policy that provides auto-remediation for anomalous user behavior and malicious activity
  • B. create a QoS policy that provides auto-remediation for anomalous user behavior and malicious activity
  • C. create a policy that provides auto-sizing for anomalous user behavior and malicious activity
  • D. create a dynamic list of firewall administrators

正解: D

 

質問 72
Which two configuration settings shown are not the default? (Choose two.)

  • A. Enable Probing
  • B. Enable Session
  • C. Enable Security Log
  • D. Server Log Monitor Frequency (sec)

正解: B,D

 

質問 73
......


Palo Alto Networks PCNSA 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Effectively Deploy the Firewalls to Enable Network Traffic
トピック 2
  • Identify Stages in the Cyber-Attack Lifecycle Firewall Mitigations
トピック 3
  • Network Design Scenario
  • Identify and Schedule Dynamic Updates
トピック 4
  • Validates your ability to Configure the Central Features of Palo Alto Networks
トピック 5
  • Identify the Components and Operation of Single-Pass Parallel Processing Architecture
トピック 6
  • Identify and Configure Firewall Interfaces
  • Identify the Purpose of Specific Security Rule Types
トピック 7
  • Configure Internal and External Services for Account Administration
トピック 8
  • Given a Scenario Identify Steps to Create and Configure a Virtual Router

 

最新をゲットせよ!PCNSA認定練習テスト問題 試験問題集:https://www.passtest.jp/Palo-Alto-Networks/PCNSA-shiken.html

合格させるPCNSA試験にはリアルテストエンジンPDFには170問題あります:https://drive.google.com/open?id=14fJZqW_urcalttSMghNHUS3m1UpRYKHp