Free PCNSE Exam Braindumps (page: 35)

Page 34 of 152

Which logs enable a firewall administrator to determine whether a session was decrypted?

  1. Traffic
  2. Security Policy
  3. Decryption
  4. Correlated Event

Answer(s): A



An administrator needs to upgrade an NGFW to the most current version of PAN-OS® software. The following is occurring:

-Firewall has internet connectivity through e 1/1.
-Default security rules and security rules allowing all SSL and web-browsing traffic to and from any zone.
-Service route is configured, sourcing update traffic from e1/1.
-A communication error appears in the System logs when updates are performed.
-Download does not complete.

What must be configured to enable the firewall to download the current version of PAN-OS software?

  1. Static route pointing application PaloAlto-updates to the update servers
  2. Security policy rule allowing PaloAlto-updates as the application
  3. Scheduler for timed downloads of PAN-OS software
  4. DNS settings for the firewall to use for resolution

Answer(s): D



A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?

  1. Add an Anti-Spyware Profile to block attacking IP address
  2. Define a custom App-ID to ensure that only legitimate application traffic reaches the server
  3. Add QoS Profiles to throttle incoming requests
  4. Add a tuned DoS Protection Profile

Answer(s): D



An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled.

What must be verified to upgrade the firewalls to the most recent version of PAN-OS® software?

  1. Antivirus update package.
  2. Applications and Threats update package.
  3. User-ID agent.
  4. WildFire update package.

Answer(s): B


Reference:

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/upgrade-to-pan-os-80/upgrade-the-firewall-to-pan-os-80/upgrade-an-ha-firewall-pair-to-pan-os-80






Post your Comments and Discuss Palo Alto Networks PCNSE exam with other Community members:

PCNSE Discussions & Posts