Palo Alto Networks PCNSA Übungsprüfungen
Zuletzt aktualisiert am 17.06.2025- Prüfungscode: PCNSA
- Prüfungsname: Palo Alto Networks Certified Network Security Administrator
- Zertifizierungsanbieter: Palo Alto Networks
- Zuletzt aktualisiert am: 17.06.2025
Issue to the Client a Certificate with Common Name = New Admin
Drag and Drop Question
Match the network device with the correct User-ID technology.
An administrator is trying to implement an exception to an external dynamic list manually. Some entries are shown underlined in red.
What would cause this error?
- A . Entries contain symbols.
- B . Entries are wildcards.
- C . Entries contain regular expressions.
- D . Entries are duplicated.
Assume that traffic matches a Security policy rule but the attached Security Profiles is configured to block matching traffic.
Which statement accurately describes how the firewall will apply an action to matching traffic?
- A . If it is a block rule, then Security Profile action is applied last.
- B . If it is an allow rule, then the Security policy rule is applied last.
- C . If it is a block rule, then the Security policy rule action is applied last.
- D . If it is an allowed rule, then the Security Profile action is applied last.
Which action results in the firewall blocking network traffic without notifying the sender?
- A . Drop
- B . Deny
- C . Reset Server
- D . Reset Client
Actions can be set for which two items in a URL filtering security profile? (Choose two.)
- A . Block List
- B . Custom URL Categories
- C . PAN-DB URL Categories
- D . Allow List
Where can you apply URL Filtering policy in a Security policy rule?
- A . Within the applications selection
- B . Within a destination address
- C . Within a service type
- D . Within the actions tab
Where can you apply URL Filtering policy in a Security policy rule?
- A . Within the applications selection
- B . Within a destination address
- C . Within a service type
- D . Within the actions tab
What are two valid selections within an Anti-Spyware profile? (Choose two.)
- A . Random early drop
- B . Drop
- C . Deny
- D . Default
You have been tasked to configure access to a new web server located in the DMZ. Based on the diagram what configuration changes are required in the NGFW virtual router to route traffic from the 10.1.1.0/24 network to 192.168.1.0/24?
- A . Add a route with the destination of 192.168.1.0/24 using interface Eth 1/2 with a next-hop of 172.16.1.2.
- B . Add a route with the destination of 192.168.1.0/24 using interface Eth 1/3 with a next-hop of 192.168.1.10
- C . Add a route with the destination of 192.168.1.0/24 using interface Eth 1/3 with a next-hop of 172.16.1.2.
- D . Add a route with the destination of 192.168.1.0/24 using interface Eth 1/3 with a next-hop of 192.168.1.254.