Free PCNSE Exam Braindumps (page: 51)

Page 50 of 152

When you configure an active/active high availability pair, which two links can you use? (Choose two.)

  1. HA3
  2. Console Backup
  3. HSCI-C
  4. HA2 backup

Answer(s): A,D


Reference:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activeactive-ha/configure-activeactive-ha.html



What are two common reasons to use a "No Decrypt" action to exclude traffic from SSL decryption? (Choose two.)

  1. the web server requires mutual authentication
  2. the website matches a category that is not allowed for most users
  3. the website matches a high-risk category
  4. the website matches a sensitive category

Answer(s): A,D



PBF can address which two scenarios? (Choose two.)

  1. routing FTP to a backup ISP link to save bandwidth on the primary ISP link
  2. providing application connectivity the primary circuit fails
  3. enabling the firewall to bypass Layer 7 inspection
  4. forwarding all traffic by using source port 78249 to a specific egress interface

Answer(s): A,B


Reference:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/policy-based-forwarding/use-case-pbf-for-outbound-access-with-dual-isps



A firewall should be advertising the static route 10.2.0.0/24 into OSPF. The configuration on the neighbour is correct, but the route is not in the neighbour's routing table.

Which two configurations should you check on the firewall? (Choose two.)

  1. Ensure that the OSPF neighbour state is "2-Way"
  2. In the OSPF configuration, ensure that the correct redistribution profile is selected in the OSPF Export Rules section.
  3. Within the redistribution profile ensure that Redist is selected.
  4. In the redistribution profile check that the source type is set to "ospf."

Answer(s): B,C






Post your Comments and Discuss Palo Alto Networks PCNSE exam with other Community members:

PCNSE Exam Discussions & Posts