PCNSA Dumps

PCNSA Free Practice Test

Paloalto-Networks PCNSA: Palo Alto Networks Certified Network Security Administrator

QUESTION 36

An administrator would like to use App-ID's deny action for an application and would like that action updated with dynamic updates as new content becomes available.
Which security policy action causes this?

Correct Answer: C

QUESTION 37

Which DNS Query action is recommended for traffic that is allowed by Security policy and matches Palo Alto Networks Content DNS Signatures?

Correct Answer: B
To enable DNS sinkholing for domain queries using DNS security, you must activate your DNS Security subscription, create (or modify) an Anti-Spyware policy to reference the DNS Security service, configure the
log severity and policy settings for each DNS signature category, and then attach the profile to a security policy rule.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns-security/enable-dns-security

QUESTION 38

A server-admin in the USERS-zone requires SSH-access to all possible servers in all current and future Public Cloud environments. All other required connections have already been enabled between the USERS- and the OUTSIDE-zone. What configuration-changes should the Firewall-admin make?

Correct Answer: B

QUESTION 39

Which license must an Administrator acquire prior to downloading Antivirus Updates for use with the firewall?

Correct Answer: A

QUESTION 40

When HTTPS for management and GlobalProtect are enabled on the same interface, which TCP port is used for management access?

Correct Answer: C