Free PCNSE Exam Braindumps (page: 58)

Page 57 of 152

When an in-band data port is set up to provide access to required services, what is required for an interface that is assigned to service routes?

  1. You must set the interface to Layer 2, Layer 3, or virtual wire.
  2. The interface must be used for traffic to the required services.
  3. You must use a static IP address.
  4. You must enable DoS and zone protection.

Answer(s): C



What does SSL decryption require to establish a firewall as a trusted third party and to establish trust between a client and server to secure SSL/TLS connection?

  1. link state
  2. profiles
  3. stateful firewall connection
  4. certificates

Answer(s): D


Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-overview.html



When you configure a Layer 3 interface, what is one mandatory step?

  1. Configure virtual routers to route the traffic for each Layer 3 interface.
  2. Configure Interface Management profiles, which need to be attached to each Layer 3 interface.
  3. Configure Security profiles, which need to be attached to each Layer 3 interface.
  4. Configure service routes to route the traffic for each Layer 3 interface.

Answer(s): A


Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/layer-3-interfaces.html



Which statement accurately describes service routes and virtual systems?

  1. Virtual systems can only use one interface for all global service and service routes of the firewall.
  2. Virtual systems that do not have specific service routes configured inherit the global service and service route settings for the firewall.
  3. Virtual systems cannot have dedicated service routes configured; and virtual systems always use the global service and service route settings for the firewall.
  4. The interface must be used for traffic to the required external services.

Answer(s): B


Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/virtual-systems/customize-service-routes-for-a-virtual-system






Post your Comments and Discuss Palo Alto Networks PCNSE exam with other Community members:

PCNSE Exam Discussions & Posts