100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
PCNSA exam|144 Questions and Answers |A+ Graded $12.49   Add to cart

Exam (elaborations)

PCNSA exam|144 Questions and Answers |A+ Graded

 4 views  0 purchase
  • Course
  • Institution

PCNSA exam|144 Questions and Answers |A+ Graded

Preview 2 out of 13  pages

  • September 7, 2024
  • 13
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
avatar-seller
PCNSA exam|144 Questions and
Answers |A+ Graded
Which firewall plane provides configuration, logging, and reporting functions
on a separate processor? - -Control plane

-A security administrator has configured App-ID updates to be automatically
downloaded and installed. The company is currently using an application
identified byApp-ID as SuperApp_base.On a content update notice, Palo Alto
Networks is adding new app signatures labeled SuperApp_chat and
SuperApp_download, which will be deployed in 30 days.Based on the
information, how is the SuperApp traffic affected after the 30 days have
passed? - -No impact because the firewall automatically adds the rules to
the App-ID interface

-How many zones can an interface be assigned with a Palo Alto Networks
firewall? - -One

-Which two configuration settings shown are not the default? - -Server Log
Monitor Frequency (sec)
Enable Session

-Which data-plane processor layer provides uniform matching for spyware
and vulnerability exploits on a Palo Alto Networks Firewall? - -Signature
Matching

-Which option shows the attributes that are selectable when setting up
application filters? - -Category, Subcategory, Technology, Risk, and
Characteristic

-Actions can be set for which two items in a URL filtering security profile? - -
Custom URL Categories
PAN-DB URL Categories

-Which two statements are correct about App-ID content updates? - -
Existing security policy rules are not affected by application content updates
After an application content update, new applications are automatically
identified and classified

-Which User-ID mapping method should be used for an environment with
clients that do not authenticate to Windows Active Directory? - -Captive
Portal

, -An administrator needs to allow users to use their own office applications.
How should the administrator configure the firewall to allow multiple
applications in a dynamic environment? - -Create an Application Group and
add business-systems to it

-Which statement is true regarding a Best Practice Assessment? - -It
provides a percentage of adoption for each assessment data

-Complete the statement. A security profile can block or allow traffic. - -
after it is evaluated by a security policy that allows traffic

-When creating a Source NAT policy, which entry in the Translated Packet
tab will display the options Dynamic IP and Port, Dynamic, Static IP, and
None? - -Translation Type

-Which interface does not require a MAC or IP address? - -Virtual Wire

-A company moved its old port-based firewall to a new Palo Alto Networks
NGFW 60 days ago. Which utility should the company use to identify out-of-
date or unused rules on the firewall? - -Rule Usage Filter > Hit Count >
Unused in 90 days

-What are two differences between an implicit dependency and an explicit
dependency in App-ID? - -An implicit dependency does not require the
dependent application to be added in the security policy
An explicit dependency requires the dependent application to be added in
the security policy

-Recently changes were made to the firewall to optimize the policies and the
security team wants to see if those changes are helping.What is the quickest
way to reset the hit counter to zero in all the security policy rules? - -Use the
Reset Rule Hit Counter > All Rules option

-Which two App-ID applications will need to be allowed to use Facebook-
chat? - -Facebook-base
Facebook-chat

-Which User-ID agent would be appropriate in a network with multiple WAN
links, limited network bandwidth, and limited firewall management plane
resources? - -Windows-based agent deployed on the internal network

-Your company requires positive username attribution of every IP address
used by wireless devices to support a new compliance requirement. You
must collect IP-to-user mappings as soon as possible with minimal downtime
and minimal configuration changes to the wireless devices themselves. The

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Victorious23. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $12.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

77254 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$12.49
  • (0)
  Add to cart