PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 62


An administrator has configured the Palo Alto Networks NGFW's management interface to connect to the internet through a dedicated path that does not traverse back through the NGFW itself.

Which configuration setting or step will allow the firewall to get automatic application signature updates?

Show Answer
Correct Answer: D

To allow the firewall to get automatic application signature updates when the management interface is configured to connect to the internet through a dedicated path, a service route will need to be configured. Without a specific service route, the updates may not be properly directed to the internet source, even if the management interface has internet access. This ensures that the correct path is used for reaching the update servers effectively.

Discussion

17 comments
Sign in to comment
Edu147Option: A
Jul 24, 2019

Correct Answer: A You don’t need a service route. Those are only used when you are using an interface OTHER THAN the MGMT interface.

PacketFairy
Nov 20, 2020

It clearly says the Mgmt interface has internet access, not through the firewall. The only thing to configure is the schedule for all dynamic updates.

NHANTONOption: A
Jan 16, 2022

A is correct. this is a good confusing question.

trashboatOption: A
Apr 29, 2021

A is the correct answer, see other comments. Updates will not happen automatically unless you schedule them: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/panorama-web-interface/panorama-device-deployment/schedule-dynamic-content-updates.html Also note that there are recommended update intervals (this probably won't be on the test): https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaECAS

YasserSaiedOption: A
Jun 15, 2021

A -- question has bad wording and unclear

joaoherbertOption: A
Sep 14, 2021

A is correct = https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/device/device-dynamic-updates.html#idef12a8e2-9abb-48cd-851f-77b13eca01bb

Abu_MuhammadOption: A
Apr 9, 2022

As mentioned by the other guys , service route is needed only if you will use a non-mgmt interface

UFanatOption: A
Jun 25, 2022

A You don't need to configure a service route for management interfaces by default. But you need to create a scheduler for automatic updates

PretorianOption: A
Aug 4, 2022

One more example (like most of the PCNSX questions) of a malicious PANW test question. The answer seems to be "A" but it's tricky AF

TAKUM1yOption: A
Sep 16, 2022

A:new document[ https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-dynamic-updates ]

rociohaOption: A
Apr 27, 2021

A is the right answer, you don't need a service route here. and tha others does not have any sense

evdwOption: A
May 5, 2021

Correct answer : A

yogininangpalOption: A
May 6, 2021

A is the correct answer as management interface has dedicated internet access!

ZabolOption: A
Jun 20, 2021

A is Correct

tururu1496Option: A
Mar 6, 2022

Answer: A

JMIBOption: A
Aug 8, 2022

A You don't need to configure a service route for management interfaces by default. But you need to create a scheduler for automatic updates

MarshpillowzOption: A
Jan 23, 2024

A is correct

hcirOption: A
Jun 15, 2024

for Application updates, you do not need a Threat Prevention license. C would have been the answer if updates for app and content were mentionned. So the only sensible answer is A