[Q158-Q173] Get instant access to PCNSA Practice Tests 2024 Free Updated Today!

Share

Get instant access to PCNSA Practice Tests 2024 Free Updated Today!

Welcome to download the newest PassLeader PCNSA PDF dumps ( 293 Q&As)

NEW QUESTION # 158
What is the minimum timeframe that can be set on the firewall to check for new WildFire signatures?

  • A. every 30 minutes
  • B. every 5 minutes
  • C. every 1 minute
  • D. once every 24 hours

Answer: B

Explanation:
Explanation
Firewalls with an active WildFire license can retrieve the latest WildFire signatures every five minutes. If you do not have a WildFire subscription, signatures are made available within 24-48 hours as part of the antivirus update for firewalls with an active Threat Prevention license.
https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-concepts/wildfire-sign


NEW QUESTION # 159
How often does WildFire release dynamic updates?

  • A. every 30 minutes
  • B. every 5 minutes
  • C. every 60 minutes
  • D. every 15 minutes

Answer: B

Explanation:
References:


NEW QUESTION # 160
An administrator has configured a Security policy where the matching condition includes a single application, and the action is deny.
If the application's default deny action is reset-both, what action does the firewall take?

  • A. It sends a TCP reset to the server-side device.
  • B. It silently drops the traffic and sends an ICMP unreachable code.
  • C. It silently drops the traffic.
  • D. It sends a TCP reset to the client-side and server-side devices.

Answer: C

Explanation:
Drop:
Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application.


NEW QUESTION # 161
Match the Cyber-Attack Lifecycle stage to its correct description.

Answer:

Explanation:


NEW QUESTION # 162
An administrator notices that protection is needed for traffic within the network due to malicious lateral movement activity. Based on the image shown, which traffic would the administrator need to monitor and block to mitigate the malicious activity?

  • A. perimeter traffic
  • B. east-west traffic
  • C. north-south traffic
  • D. branch office traffic

Answer: B


NEW QUESTION # 163
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)

  • A. antivirus profile applied to outbound security policies
  • B. vulnerability protection profile applied to outbound security policies
  • C. URL filtering profile applied to outbound security policies
  • D. anti-spyware profile applied to outbound security policies

Answer: A,D

Explanation:
Antivirus: Includes new and updated antivirus signatures, including WildFire signatures and automatically generated command-and-control (C2) signatures. WildFire signatures detect malware seen first by firewalls from around the world. You must have a Threat Prevention subscription to get these updates.
New antivirus signatures are published daily.
Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers, allowing you to detect malicious traffic leaving the network from infected clients. You can apply various levels of protection between zones.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles


NEW QUESTION # 164
Drag and Drop Question
Match the network device with the correct User-ID technology.

Answer:

Explanation:


NEW QUESTION # 165
Which statement is true regarding NAT rules?

  • A. Translation of the IP address and port occurs before security processing.
  • B. Static NAT rules have precedence over other forms of NAT.
  • C. Firewall supports NAT on Layer 3 interfaces only.
  • D. NAT rules are processed in order from top to bottom.

Answer: D

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview


NEW QUESTION # 166
Order the steps needed to create a new security zone with a Palo Alto Networks firewall.

Answer:

Explanation:


NEW QUESTION # 167
An administrator needs to allow users to use their own office applications. How should the administrator configure the firewall to allow multiple applications in a dynamic environment?

  • A. Create an Application Group and add Office 365, Evernote, Google Docs, and Libre Office An application filter is an object that dynamically groups applications based on application attributes that you define, including category, subcategory, technology, risk factor, and characteristic. This is useful when you want to safely enable access to applications that you do not explicitly sanction, but that you want users to be able to access. For example, you may want to enable employees to choose their own office programs (such as Evernote, Google Docs, or Microsoft Office 365) for business use. To safely enable these types of applications, you could create an application filter that matches on the Category business-systems and the Subcategory office-programs. As new applications office programs emerge and new App-IDs get created, these new applications will automatically match the filter you defined; you will not have to make any additional changes to your policy rulebase to safely enable any application that matches the attributes you defined for the filter.
  • B. Create an Application Filter and name it Office Programs, the filter it on the business-systems category, office-programs subcategory
  • C. Create an Application Group and add business-systems to it
  • D. Create an Application Filter and name it Office Programs, then filter it on the business-systems category

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/use-application-objects-in -policy/create-an-application-filter.html


NEW QUESTION # 168
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated?
(Choose two.)

  • A. antivirus profile applied to outbound security policies
  • B. URL filtering profile applied to outbound security policies
  • C. vulnerability protection profile applied to outbound security policies
  • D. anti-spyware profile applied to outbound security policies

Answer: B,D

Explanation:
Explanation/Reference:
Reference: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/policy/create-best-practice- security-profiles


NEW QUESTION # 169
In a File Blocking profile, which two actions should be taken to allow file types that support critical apps? (Choose two.)

  • A. Set the action to Continue.
  • B. Edit the Strict profile.
  • C. Clone and edit the Strict profile.
  • D. Use URL filtering to limit categories in which users can transfer files.

Answer: B,C


NEW QUESTION # 170
An internal host needs to connect through the firewall using source NAT to servers of the internet.
Which policy is required to enable source NAT on the firewall?

  • A. NAT policy with no internal or internet zone selected
  • B. post-NAT policy with external source and any destination address
  • C. NAT policy with internal zone and internet zone specified
  • D. pre-NAT policy with external source and any destination address

Answer: C


NEW QUESTION # 171
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.

Which Security policy rule will allow traffic to flow to the web server?

  • A. Untrust (any) to DMZ (10.1.1.100), web browsing -Allow
  • B. Untrust (any) to DMZ (1.1.1.100), web browsing - Allow
  • C. Untrust (any) to Untrust (1.1.1.100), web browsing - Allow
  • D. Untrust (any) to Untrust (10.1.1.100), web browsing -Allow

Answer: B


NEW QUESTION # 172
Match each feature to the DoS Protection Policy or the DoS Protection Profile.

Answer:

Explanation:


NEW QUESTION # 173
......

Jan-2024 Latest NewPassLeader PCNSA Exam Dumps with PDF and Exam Engine: https://pass4lead.newpassleader.com/Palo-Alto-Networks/PCNSA-exam-preparation-materials.html