PCNSA Dumps

PCNSA Free Practice Test

Paloalto-Networks PCNSA: Palo Alto Networks Certified Network Security Administrator

QUESTION 71

Which type of security policy rule will match traffic that flows between the Outside zone and inside zone, but would not match traffic that flows within the zones?

Correct Answer: C
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/software-and-content- updates/dynamic- contentupdates.html#:~:text=WildFire signature updates are made,within a minute of availability

QUESTION 72

The CFO found a malware infected USB drive in the parking lot, which when inserted infected their corporate laptop the malware contacted a known command-and-control server which exfiltrating corporate data.
Which Security profile feature could have been used to prevent the communications with the command-and-control server?

Correct Answer: C

QUESTION 73

An administrator would like to determine the default deny action for the application dns- over-https
Which action would yield the information?

Correct Answer: D
PCNSA dumps exhibit

QUESTION 74

At which point in the app-ID update process can you determine if an existing policy rule is affected by an app-ID update?

Correct Answer: A
Reference:https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/device/device-dynamicupdates

QUESTION 75

Which statements is true regarding a Heatmap report?

Correct Answer: B
Reference:https://live.paloaltonetworks.com/t5/best-practice-assessment-blogs/the-best-practice-assessment-bpa-tool-for-ngfw-and-panorama/ba-p/248343