Palo Alto Networks PCNSA Übungsprüfungen
Zuletzt aktualisiert am 12.07.2025- Prüfungscode: PCNSA
- Prüfungsname: Palo Alto Networks Certified Network Security Administrator
- Zertifizierungsanbieter: Palo Alto Networks
- Zuletzt aktualisiert am: 12.07.2025
What is an advantage for using application tags?
- A . They are helpful during the creation of new zones
- B . They help with the design of IP address allocations in DHCP.
- C . They help content updates automate policy updates
- D . They help with the creation of interfaces
How do you reset the hit count on a Security policy rule?
- A . select a security policy rule, right click Hit Count > Reset
- B . with a dataplane reboot
- C . Device > Setup > Logging and Reporting Settings > Reset Hit Count
- D . in the CLI, type command reset hitcount <POLICY-NAME>
How do you reset the hit count on a Security policy rule?
- A . select a security policy rule, right click Hit Count > Reset
- B . with a dataplane reboot
- C . Device > Setup > Logging and Reporting Settings > Reset Hit Count
- D . in the CLI, type command reset hitcount <POLICY-NAME>
You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact a command-and-control server.
Which Security Profile detects and prevents this threat from establishing a command-and-control
connection?
- A . Vulnerability Protection Profile applied to outbound Security policy rules.
- B . Anti-Spyware Profile applied to outbound security policies.
- C . Antivirus Profile applied to outbound Security policy rules
- D . Data Filtering Profile applied to outbound Security policy rules.
Which security policy rule would be needed to match traffic that passes between the Outside zone and Inside zone, but does not match traffic that passes within the zones?
- A . global
- B . intrazone
- C . interzone
- D . universal
What is a recommended consideration when deploying content updates to the firewall from Panorama?
- A . Before deploying content updates, always check content release version compatibility.
- B . Content updates for firewall A/P HA pairs can only be pushed to the active firewall.
- C . Content updates for firewall A/A HA pairs need a defined master device.
- D . After deploying content updates, perform a commit and push to Panorama.
What is a recommended consideration when deploying content updates to the firewall from Panorama?
- A . Before deploying content updates, always check content release version compatibility.
- B . Content updates for firewall A/P HA pairs can only be pushed to the active firewall.
- C . Content updates for firewall A/A HA pairs need a defined master device.
- D . After deploying content updates, perform a commit and push to Panorama.
A network administrator is required to use a dynamic routing protocol for network connectivity.
Which three dynamic routing protocols are supported by the NGFW Virtual Router for this purpose? (Choose three.)
- A . RIP
- B . OSPF
- C . IS-IS
- D . EIGRP
- E . BGP
A network administrator is required to use a dynamic routing protocol for network connectivity.
Which three dynamic routing protocols are supported by the NGFW Virtual Router for this purpose? (Choose three.)
- A . RIP
- B . OSPF
- C . IS-IS
- D . EIGRP
- E . BGP
At which stage of the cyber-attack lifecycle would the attacker attach an infected PDF file to an email?
- A . delivery
- B . command and control
- C . exploitation
- D . reinsurance
- E . installation