Palo Alto Networks PCNSE Übungsprüfungen
Zuletzt aktualisiert am 05.05.2025- Prüfungscode: PCNSE
- Prüfungsname: Palo Alto Networks Certified Network Security Engineer Exam
- Zertifizierungsanbieter: Palo Alto Networks
- Zuletzt aktualisiert am: 05.05.2025
An engineer decides to use Panorama to upgrade devices to PAN-OS 10.2.
Which three platforms support PAN-OS 10.2? (Choose three.)
- A . PA-220
- B . PA-800 Series
- C . PA-5000 Series
- D . PA-500
- E . PA-3400 Series
Refer to Exhibit:
An administrator can not see any Traffic logs from the Palo Alto Networks NGFW in Panorama reports. The configuration problem seems to be on the firewall.
Which settings, if configured incorrectly, most likely would stop only Traffic logs from being sent from the NGFW to Panorama?
A)
B)
C)
D)
- A . Option A
- B . Option B
- C . Option C
- D . Option D
If a URL is in multiple custom URL categories with different actions, which action will take priority?
- A . Allow
- B . Override
- C . Block
- D . Alert
An administrator needs to identify which NAT policy is being used for internet traffic.
From the Monitor tab of the firewall GUI, how can the administrator identify which NAT policy is in use for a traffic flow?
- A . Click Session Browser and review the session details.
- B . Click Traffic view and review the information in the detailed log view.
- C . Click Traffic view; ensure that the Source or Destination NAT columns are included and review the information in the detailed log view.
- D . Click App Scope > Network Monitor and filter the report for NAT rules.
An engineer is tasked with deploying SSL Forward Proxy decryption for their organization.
What should they review with their leadership before implementation?
- A . Browser-supported cipher documentation
- B . Cipher documentation supported by the endpoint operating system
- C . URL risk-based category distinctions
- D . Legal compliance regulations and acceptable usage policies
Which protocol is supported by GlobalProtect Clientless VPN?
- A . FTP
- B . RDP
- C . SSH
- D . HTTPS
After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?
- A . Ensure Force Template Values is checked when pushing configuration.
- B . Push the Template first, then push Device Group to the newly managed firewall.
- C . Perform the Export or push Device Config Bundle to the newly managed firewall.
- D . Push the Device Group first, then push Template to the newly managed firewall
An engineer needs to configure a standardized template for all Panorama-managed firewalls. These settings will be configured on a template named "Global" and will be included in all template stacks.
Which three settings can be configured in this template? (Choose three.)
- A . Log Forwarding profile
- B . SSL decryption exclusion
- C . Email scheduler
- D . Login banner
- E . Dynamic updates
Which log type would provide information about traffic blocked by a Zone Protection profile?
- A . Data Filtering
- B . IP-Tag
- C . Traffic
- D . Threat
Refer to the exhibit.
Which will be the egress interface if the traffic’s ingress interface is ethernet1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?
- A . ethernet1/6
- B . ethernet1/3
- C . ethernet1/7
- D . ethernet1/5