Exam PCNSE All QuestionsBrowse all questions from this exam
Question 195

A remote administrator needs access to the firewall on an untrust interface. Which three options would you configure on an Interface Management profile to secure management access? (Choose three.)

    Correct Answer: A, B, C

    To secure management access to the firewall on an untrust interface, you should configure Permitted IP Addresses to restrict which IP addresses can access the interface, SSH for secure encrypted command-line access, and HTTPS for secure encrypted web access. HTTP is not secure because it transmits data in cleartext, and User-ID is used for identifying users and their activities rather than securing management access.

Discussion
MarcyyOptions: ABC

It's ABC

Plato22Options: ABC

ABC, how is enabling HTTP securing your access?

AaronyukinOptions: ABC

By ovbious reasons it will be ABC. Others are insecure.

TAKUM1yOptions: ABC

https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/getting-started/best-practices-for-securing-administrative-access

Rloc20Options: BCD

BCD https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access.html

Mp84047

Its ABC, the doc you reference says that user-id is used to "Redistribute User Mappings and Authentication Timestamps"

Elvenking

D can't be an answer because: "... and never enable HTTP or Telnet access because those protocols transmit in cleartext." as it is stated on the question that you should "secure" access, not just permit it. Reference: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access

MarshpillowzOptions: ABC

A, B and C correct

Sammy3637Options: ABC

It's so obvious

UFanatOptions: ABC

ABC Do not use HTTP or Telnet for any management interface profile because those protocols transmit in cleartext. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/getting-started/best-practices-for-securing-administrative-access

AbuHussainOptions: ABC

It's ABC

ev333Options: ABC

Http is not secure

RamanJoshiOptions: ABC

A, B, C