100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
PCNSA Exam Practice Questions and Answers 100% Pass $12.49   Add to cart

Exam (elaborations)

PCNSA Exam Practice Questions and Answers 100% Pass

 0 view  0 purchase
  • Course
  • Prep Tests
  • Institution
  • Prep Tests

PCNSA Exam Practice Questions and Answers 100% Pass A client downloads a malicious file from the internet. The Palo Alto firewall has a valid WildFire subscription. The Security policy rule shown above matches the client HTTP session: Which three actions take place when the firewall's Content-I...

[Show more]

Preview 2 out of 12  pages

  • November 11, 2024
  • 12
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • Prep Tests
  • Prep Tests
avatar-seller
OliviaWest
Copyright © OLIVIAWEST2024/2025 ACADEMIC YEAR. ALL RIGHTS RESERVED




PCNSA Exam Practice Questions and

Answers 100% Pass


A client downloads a malicious file from the internet. The Palo Alto firewall has a valid WildFire

subscription. The Security policy rule shown above matches the client HTTP session: Which three actions

take place when the firewall's Content-ID engine detects a virus in the file and the decoder action is set

to "block"? (Choose three.) - ANSWER✔✔-A threat log entry is generated.




The file download is terminated.




The client receives a block page.


A company has a pair of PA-3050s running PAN-OS 6.0.4. Antivirus, Threat Prevention, and URL Filtering

Profiles are in place and properly configured on both inbound and outbound policies. A Security

Operation Center (SOC) engineer starts his shift and faces the traffic logs presented in the screenshot

shown above. He notices that the traffic is being allowed outbound. Which actions should the SOC

engineer take to safely allow known but not yet qualified applications, without disrupting the remaining

traffic policies? - ANSWER✔✔-Create Application Override policies after a packet capture to identify the

applications that are triggering the "unknown-tcp". Then create new custom applications for those

policies, and add these new policies above the current policy that allows the traffic.




Copyright ©Stuvia International BV 2010-2024 Page 1/12

, Copyright © OLIVIAWEST2024/2025 ACADEMIC YEAR. ALL RIGHTS RESERVED


A company has a Palo Alto Networks firewall configured with the following three zones: Internet DMZ

Inside. All users are located on the Inside zone and are using public DNS servers for name resolution. The

company hosts a publicly accessible web application on a server in the DMZ zone. Which NAT rule

configuration will allow users on the Inside zone to access the web application using its public IP

address? - ANSWER✔✔-Three zone U-turn NAT


A company has a Palo Alto Networks firewall configured with the following three zones: Untrust-L3 DMZ

Trust-L3. The company hosts a publicly accessible web application on a server that resides in the Trust-L3

zone. The web server is associated with the following IP addresses: Web Server Public IP: 2.2.2.1/24 ,

Web Server Private IP: 192.168.1.10/24 . The security administrator configures the following two-zone U-

Turn NAT rule to allow users using 10.10.1.0/24 on the "Trust-L3" zone to access the web server using its

public IP address in the Untrust-L3 zone: Which statement is true in this situation? - ANSWER✔✔-The

traffic will be considered intra-zone based on the translated destination zone.


A company is deploying a pair of PA-5060 firewalls in an environment requiring support for asymmetric

routing. Which High Availability (HA) mode best supports this design requirement? - ANSWER✔✔-Active-

Active mode


A company policy dictates that logs must be retained in their original format for a period of time that

would exceed the space limitations of the Palo Alto Networks firewall's internal storage. Which two

options will allow the company to meet this requirement? (Choose two.) - ANSWER✔✔-Palo Alto

Networks Log Collector




Panorama Virtual Machine with NFS storage




Copyright ©Stuvia International BV 2010-2024 Page 2/12

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller OliviaWest. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $12.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

76799 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$12.49
  • (0)
  Add to cart