Get Full Version of the Exam
http://www.EnsurePass.com/PCNSE.html
Question No.211
What are two prerequisites for configuring a pair of Palo Alto Networks firewalls in an active/passive High Availability (HA) pair? (Choose two.)
-
Thefirewalls must have the same set of licenses.
-
The management interfaces must to be on the same network.
-
The peer HA1 IP address must be the same on both firewalls.
-
HA1 should be connected to HA1. Either directly or with an intermediate Layer 2 device.
Correct Answer: AD
Question No.212
The IT department has received complaints abou VoIP call jitter when the sales staff is making or receiving calls. QoS is enabled on all firewall interfaces, but there is no QoS policy written in the rulebase. The IT manager wants to find out what traffic is causing the jitter in real time when a user reports the jitter. Which feature can be used to identify, in real time, the applications taking
up the most bandwidth?
-
QoS Statistics
-
Applications Report
-
Application Command Center (ACC)
-
QoS Log
Correct Answer: A
Question No.213
Which three fields can be included in a pcap filter? (Choose three)
-
Egress interface
-
Source IP
-
Rule number
-
Destination IP
-
Ingress interface
Correct Answer: BCD
Explanation:
https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Packet-Capture/ta-p/72069
Question No.214
Which client software can be used to connect remote Linux client into a Palo Alto Networks Infrastructure without sacrificing the ability to scan traffic and protect against threats?
-
X-Auth IPsec VPN
-
GlobalProtect Apple IOS
-
GlobalProtect SSL
-
GlobalProtect Linux
Correct Answer: A
Explanation:
http://blog.webernetz.net/2014/03/31/palo-alto-globalprotect-for-linux-with-vpnc/
Question No.215
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed tomultiple remote offices and the Network Administrator decides to use Panorama to deploy the configurations. How should this be accomplished?
-
Create a Template with the appropriate IKE Gateway settings
-
Create a Template with the appropriate IPSec tunnel settings
-
Create a Device Group with the appropriate IKE Gateway settings
-
Create a Device Group with the appropriate IPSec tunnel settings
Correct Answer: B
Question No.216
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination IP address and post. Which option when enabled withthe correction threshold would mitigate this attack without dropping legitirnate traffic to other hosts insides the network?
-
Zone Protection Policy with UDP Flood Protection
-
QoS Policy to throttle traffic below maximum limit
-
Security Policy ruleto deny trafic to the IP address and port that is under attack
-
Classified DoS Protection Policy using destination IP only with a Protect action
Correct Answer: D
Question No.217
Which Public Key infrastructure component is used to authenticate users for GlobalProtect whenthe Connect Method is set to pre-logon?
-
Certificate revocation list
-
Trusted root certificate
-
Machine certificate
-
Online Certificate Status Protocol
Correct Answer: C
Question No.218
Which setting allow a DOS protection profile to limit the maximum concurrent sessions from a source IP address?
-
Set the type to Aggregate, clear the session#39;s box and set the Maximum concurrent Sessions to 4000.
-
Set the type to Classified, clear the session#39;s box and set the Maximum concurrent Sessions to 4000.
-
Set the type Classified, check the Sessions box and set the Maximum concurrent Sessions to 4000.
-
Set the type to aggregate, check the Sessions box and set the Maximum concurrent Sessions to 4000.
Correct Answer: C
Question No.219
A network security engineer needs to configure a virtual router using IPv6 addresses. Which two routing options supportthese addresses? (Choose two)
-
BGP not sure
-
OSPFv3
-
RIP
-
Static Route
Correct Answer: BD
Explanation:
https://live.paloaltonetworks.com/t5/Management-Articles/Does-PAN-OS-Support-Dynamic- Routing-Protocols-OSPF-or-BGP-with/ta-p/62773
Question No.220
Which CLI command displays the current management plane memory utilization?
-
gt; debug management-server show
-
gt; show running resource-monitor
-
gt; show system info
-
gt; show system resources
Correct Answer: D
Explanation:
https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Interpret-show-system-resources/ta- p/59364
quot;The command show system resources gives a snapshot of Management Plane (MP) resource utilization including memory and CPU. This is similar to the `top#39; command in Linux.quot;
Get Full Version of the Exam
PCNSE Dumps
PCNSE VCE and PDF