Free PCNSE Exam Braindumps (page: 56)

Page 55 of 152

A network administrator wants to use a certificate for the SSL/TLS Service Profile. Which type of certificate should the administrator use?

  1. machine certificate
  2. server certificate
  3. certificate authority (CA) certificate
  4. client certificate

Answer(s): B



In a security-first network, what is the recommended threshold value for content updates to be dynamically updated?

  1. 1 to 4 hours
  2. 6 to 12 hours
  3. 24 hours
  4. 36 hours

Answer(s): B


Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/best-practices-for-content-and-threat-content-updates/best-practices-security-first.html#:~:text=In%20a%20security%2Dfirst%20network%2C%20schedule%20a,six%20to%20twelve%20hour%20threshold.&text=App%2DID%20Threshold-,.,based%20on%20new%20App%2DIDs



A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system.

Where is the best place to validate if the firewall is blocking the user's TAR file?

  1. Threat log
  2. Data Filtering log
  3. WildFire Submissions log
  4. URL Filtering log

Answer(s): B


Reference:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZ1CAK



In a firewall, which three decryption methods are valid? (Choose three.)

  1. SSL Outbound Proxyless Inspection
  2. SSL Inbound Inspection
  3. SSH Proxy
  4. SSL Inbound Proxy
  5. Decryption Mirror

Answer(s): B,C,E


Reference:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-overview.html






Post your Comments and Discuss Palo Alto Networks PCNSE exam with other Community members:

PCNSE Exam Discussions & Posts