Palo Alto Networks Certified Network Security Engineer

Here you have the best Palo Alto Networks PCNSE practice exam questions

  • You have 606 total questions to study from
  • Each page has 5 questions, making a total of 122 pages
  • You can navigate through the pages using the buttons at the bottom
  • This questions were last updated on December 13, 2024
Question 1 of 606

Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?

    Correct Answer: C

    The CLI command 'test' is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic. This command allows administrators to validate and troubleshoot network configurations by simulating how the firewall processes specific traffic scenarios.

Question 2 of 606

Refer to the exhibit.

An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN.

How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all the existing monitoring/security platforms?

    Correct Answer: A

    In the given scenario, the network team has reported excessive traffic on the corporate WAN due to the logs being sent from several remote firewalls to multiple monitoring and security management platforms. The best solution to reduce WAN traffic, while still supporting all existing platforms, is to centralize the log forwarding process. By forwarding logs from firewalls only to Panorama and then having Panorama forward logs to the other external services, you can significantly reduce the number of log streams traversing the WAN. This centralized approach minimizes the bandwidth consumption on the WAN link, as Panorama acts as an intermediate log aggregator and distributor. Additionally, it simplifies the log collection and forwarding architecture, leading to more efficient network resource usage and potentially improved overall system performance.

Question 3 of 606

A customer wants to set up a VLAN interface for a Layer 2 Ethernet port.

Which two mandatory options are used to configure a VLAN interface? (Choose two.)

    Correct Answer: A, B

    To configure a VLAN interface for a Layer 2 Ethernet port, the two mandatory options are 'Virtual router' and 'Security zone.' The virtual router is necessary to handle the routing of traffic entering and leaving the VLAN. The security zone assigns the VLAN interface to a specific zone, which is used to manage and control traffic based on security policies. Options such as ARP entries and Netflow Profile are not mandatory for the basic configuration of a VLAN interface.

Question 4 of 606

An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans.

Which Security Profile type will protect against worms and trojans?

    Correct Answer: D

    The correct Security Profile type to protect against worms and trojans is Antivirus. Antivirus profiles in Palo Alto Networks NGFW are designed to detect and prevent malware such as viruses, worms, and trojans from infiltrating the network. This profile scans for known malware signatures and can proactively block these harmful entities, ensuring the network remains secure.

Question 5 of 606

A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.

Which VPN configuration would adapt to changes when deployed to the future site?

    Correct Answer: A

    GlobalProtect Satellite is specifically designed to simplify the deployment and management of secure VPN tunnels from remote sites to multiple regional data centers. It allows for preconfiguration before deployment and automatically adapts to changes, including the addition of future regional data centers. This makes it the most appropriate choice for minimizing preconfiguration and ensuring scalability.