Free PCNSE Exam Braindumps

Pass your Palo Alto Networks Certified Security Engineer (PCNSE)PAN-OS 9.0 exam with these free Questions and Answers

Page 11 of 18
QUESTION 46

What happens when an A/P firewall cluster synchronizes IPsec tunnel security associations (SAs)?

  1. A. Phase 1 and Phase 2 SAs are synchronized over HA3 links.
  2. B. Phase 1 SAs are synchronized over HA1 links.
  3. C. Phase 2 SAs are synchronized over HA2 links.
  4. D. Phase 1 and Phase 2 SAs are synchronized over HA2 links.

Correct Answer: C

QUESTION 47

An administrator wants to grant read-only access to all firewall settings, except administrator accounts, to a new-hire colleague in the IT department.
Which dynamic role does the administrator assign to the new-hire colleague?

  1. A. Device administrator (read-only)
  2. B. System administrator (read-only)
  3. C. Firewall administrator (read-only)
  4. D. Superuser (read-only)

Correct Answer: A

QUESTION 48

An administrator needs to optimize traffic to prefer business-critical applications over non-critical applications QoS natively integrates with which feature to provide service quality?

  1. A. certificate revocation
  2. B. Content-ID
  3. C. App-ID
  4. D. port inspection

Correct Answer: C

QUESTION 49

An engineer has been asked to limit which routes are shared by running two different areas within an OSPF implementation. However, the devices share a common link for communication. Which virtual router configuration supports running multiple instances of the OSPF protocol over a single link?

  1. A. ASBR
  2. B. ECMP
  3. C. OSPFv3
  4. D. OSPF

Correct Answer: C
Support for multiple instances per link—With OSPFv3, you can run multiple instances of the OSPF protocol over a single link. This is accomplished by assigning an OSPFv3 instance ID number. An interface that is assigned to an instance ID drops packets that contain a different ID.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/ospf/ospf-concepts/ospfv3

QUESTION 50

A user at an external system with the IP address 65.124.57.5 queries the DNS server at 4. 2.2.2 for the IP address of the web server, www,xyz.com. The DNS server returns an address of 172.16.15.1
In order to reach Ire web server, which Security rule and NAT rule must be configured on the firewall?
PCNSE dumps exhibit
A)
PCNSE dumps exhibit
B)
PCNSE dumps exhibit
C)
PCNSE dumps exhibit
D)
PCNSE dumps exhibit

  1. A. Option A
  2. B. Option B
  3. C. Option C
  4. D. Option D

Correct Answer: C

Page 11 of 18

Post your Comments and Discuss Paloalto-Networks PCNSE exam with other Community members: