Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 11.0

Total Questions : 177
Update Date : July 11, 2024
Palo-Alto-Networks PCNSE Sample Questions

Question # 1

A network security administrator wants to begin inspecting bulk user HTTPS traffic flowsegressing out of the internet edge firewall. Which certificate is the best choice to configureas an SSL Forward Trust certificate?

A. A self-signed Certificate Authority certificate generated by the firewall
B. A Machine Certificate for the firewall signed by the organization's PKI
C. A web server certificate signed by the organization's PKI
D. A subordinate Certificate Authority certificate signed by the organization's PKI

Question # 2

An organization conducts research on the benefits of leveraging the Web Proxy feature ofPAN-OS 11.0.What are two benefits of using an explicit proxy method versus a transparent proxymethod? (Choose two.)

A. No client configuration is required for explicit proxy, which simplifies the deployment complexity.
B. Explicit proxy supports interception of traffic using non-standard HTTPS ports.
C. It supports the X-Authenticated-User (XAU) header, which contains the authenticated username in the outgoing  request.
D. Explicit proxy allows for easier troubleshooting, since the client browser is aware of the existence of the proxy.

Question # 3

If a URL is in multiple custom URL categories with different actions, which action will take priority?

A. Allow
B. Override
C. Block
D. Alert

Question # 4

An administrator has configured OSPF with Advanced Routing enabled on a Palo AltoNetworks firewall running PAN-OS 10.2. After OSPF was configured, the administratornoticed that OSPF routes were not being learned.Which two actions could an administrator take to troubleshoot this issue? (Choose two.)

A. Run the CLI command show advanced-routing ospf neighbor
B. In the WebUI, view the Runtime Stats in the virtual router
C. Look for configuration problems in Network > virtual router > OSPF
D. In the WebUI, view Runtime Stats in the logical router

Question # 5

An engineer is tasked with deploying SSL Forward Proxy decryption for their organization.What should they review with their leadership before implementation?

A. Browser-supported cipher documentation
B. Cipher documentation supported by the endpoint operating system
C. URL risk-based category distinctions
D. Legal compliance regulations and acceptable usage policies

Question # 6

A company wants to add threat prevention to the network without redesigning the network routing.What are two best practice deployment modes for the firewall? (Choose two.)

A. VirtualWire
B. Layer3
D. Layer2

Question # 7

A network engineer has discovered that asymmetric routing is causing a Palo AltoNetworks firewall to drop traffic. The network architecture cannot be changed to correct this.Which two actions can be taken on the firewall to allow the dropped traffic permanently?(Choose two.)

A. Navigate to Network > Zone Protection Click AddSelect Packet Based Attack Protection > TCP/IP Drop Set "Reject Non-syn-TCP" to No Set"Asymmetric Path" to Bypass
B. > set session tcp-reject-non-syn no
C. Navigate to Network > Zone Protection Click AddSelect Packet Based Attack Protection > TCP/IP Drop Set "Reject Non-syn-TCP" to GlobalSet "Asymmetric Path" to Global
D. # set deviceconfig setting session tcp-reject-non-syn no

Question # 8

Which log type will help the engineer verify whether packet buffer protection was activated?

A. Data Filtering
B. Configuration
C. Threat
D. Traffic

Question # 9

Which three authentication types can be used to authenticate users? (Choose three.)

A. Local database authentication
B. PingID
C. Kerberos single sign-on
D. GlobalProtect client
E. Cloud authentication service