PCNSA QUESTIONS AND ANSWERS
GRADED A+
Palo Alto NGFWs enable you to adopt security best practices to minimize opportunities for attack
by using the following *three* policy types... ✔✔Application, User, and Content ba
...
PCNSA QUESTIONS AND ANSWERS
GRADED A+
Palo Alto NGFWs enable you to adopt security best practices to minimize opportunities for attack
by using the following *three* policy types... ✔✔Application, User, and Content based policies.
T/F:
Palo Alto NGFWs allow you to automate workflows via integration with administrative tools such
as ticketing services, or any system with a RESTful API. ✔✔True
What are the *three* families of Palo Alto NGFWs? ✔✔1) VM Series
2) Prisma Access (Cloud Firewall SaaS)
3) Physical Firewalls
Name at least *three* of the physical Palo Alto NGFW models. ✔✔1) PA-220
2) PA800
3) PA-3200
4) PA-5200
5) PA-7000
Older models include: PA-200, PA-500, PA-3000 and PA-5000.
What capabilities does Palo Alto Traps *Advanced Endpoint Protection* provide? ✔✔Advanced
Endpoint Protection blocks: exploits, ransomware, malware, and fileless attacks to minimize
infected endpoints and servers.
What does *AutoFocus* provide? ✔✔AutoFocus provides instant access to community-based
threat data, enhanced with deep context and attribution from the Unit 42 threat research team,
saving analysts time and effort.How often is the WildFire cloud database updated? ✔✔Approximately every *5* minutes.
What is Palo Alto *WildFire*? ✔✔WildFire is a cloud based malware analysis and zero day
exploit detection feature.
What is Palo Alto *Threat Prevention*? ✔✔Threat Prevention is an IPS feature for detecting
network signatures.
What is Palo Alto *URL Filtering*? ✔✔URL Filtering is a feature for categorizing web traffic
and preventing phishing attempts.
What is Palo Alto *MineMeld*? ✔✔MineMeld is a threat intelligence aggregation tool for
gathering and applying IOCs at the firewall.
What is Palo Alto *Cortex Data Lake*? ✔✔Cortex Data Lake is a tool for collecting and managing
vast amounts of security logs.
What is Palo Alto *Cortex XDR*? ✔✔Cortex XDR is a machine learning *UBA tool*, for
detecting post-intrusion activities, such as risky behavior, data exfiltration, or anomalies.
The Palo Alto Networks Security Operating Platform is designed for which *three* purposes?
A) consume innovations quickly
B) ensure compliance
C) focus on what matters
D) prevent successful cyberattacks ✔✔*A)* consume innovations quickly
*C)* focus on what matters
*D)* prevent successful cyberattacksWhich item is not one of the six primary components of the Palo Alto Networks Security Operating
Platform?
A) applications (Palo Alto Networks applications, third-party applications, customer applications)
B) Cloud-Delivered Security Services
C) WildFire
D) Cortex and Cortex Data Lake
E) Network Security
F) Advanced Endpoint Protection
G) Cloud Security ✔✔*C)* WildFire
Which cloud-delivered security service provides instant access to community-based threat data?
A) Prisma SaaS
B) AutoFocus
C) Threat 42
D) Cortex XDR ✔✔B) AutoFocus
Which cloud-delivered security service provides security for branches and mobile users?
A) MineMeld
B) Cortex XDR
C) AutoFocus
D) Prisma Access ✔✔*D)* Prisma Access
Which Palo Alto Networks Security Operating Platform component provides *access to
applications* from Palo Alto Networks, third parties, and customers?
A) Cloud-Delivered Security Services
B) WildFire
C) CortexD) Network Security
E) Advanced Endpoint Protection ✔✔C) Cortex
Which Palo Alto Networks firewall feature provides all the following abilities?
• Stops malware, exploits, and ransomware before they can compromise endpoints
• Provides protection while endpoints are online and offline, on network and off
• Coordinates enforcement with network and cloud security to prevent successful attacks
• Detects threats and automates containment to minimize impact
• Includes WildFire cloud-based threat analysis service with your Cortex XDR subscription
• Integrates with the Palo Alto Networks Security Operating Platform
A) Cortex XDR
B) Prisma SaaS
C) URL Filtering
D) WildFire
E) GlobalProtect
F) AutoFocus ✔✔*A)* Cortex XDR
What architecture does Palo Alto use to reduce latency with processing packets? ✔✔Single-Pass
Parallel Processing (SP3) architecture.
What are the *two* components of Single-Pass Parallel Processing (SP3) architecture? ✔✔1)
Single-Pass Software
2) Parallel Processing Hardware
T/F:
Management and Data planes have dedicated hardware resources (CPU, RAM, and storage),
making them independent of each other. ✔✔True
T/F:When administrator is running a very processor-intensive report, he/she may notice the firewall
has decreased ability to process packets. ✔✔False
The firewall would not be affected by this reporting job, because there is separation of the data
and control (management) planes.
What are some of the *management features* the control plane provides the firewall with? ✔✔1)
Firewall configuration
2) Logging
3) Reporting
What are some of the *data processing* features the data plane provides the firewall with? ✔✔1)
Signature matching
2) Security processing
3) Network processing
Which plane is signature matching part of, and what are some of the things signature matching can
identify? ✔✔Signature matching is part of the data plane.
Signature matching can identify: exploits (IPS), viruses, spyware, CC#s, and SSNs.
Which plane is security processing part of, and what are some of the things security processing
handles? ✔✔Security processing is part of the data plane.
Security processing handles: App-ID, User-ID, URL match, policy match, app decoding,
SSL/IPSEC, and decompression.
Which plane is network processing part of, and what are some of the things network processing
handles? ✔✔Network processing is part of the data plane.Network processing handles: flow control, route lookup, MAC lookup, QoS, and NAT.
Which *three* management features does the control plane provide?
A) security processing
B) logging
C) reporting
D) firewall configuration
E) signature matching
F) network processing ✔✔*B)* logging
*C)* reporting
*D)* firewall configuration
Which *three* data processing features does the data plane provide?
A) network processing
B) security processing
C) signature matching
D) firewall configuration
E) logging
F) reporting ✔✔*A)* network processing
*B)* security processing
*C)* signature matching
Which *three* of the following components are part of the Network Processing module?
A) QoS
B) NAT
C) App-ID
D) flow control
E) url matchF) spyware ✔✔*A)* QoS
*B)* NAT
*D)* flow control
Which approach most accurately defines the Palo Alto Networks *SP3 architecture*?
A) prioritize first
B) sequential processing
C) scan it all, scan it once
D) zero trust segmentation platform ✔✔*C)* scan it all, scan it once
What is the result of using a stream-based design of architecture?
A) superior performance
B) increased latency
C) superior latency
D) increased functionality ✔✔*A)* superior performance
What is the *zero trust* security model? ✔✔Zero Trust is an alternative security model that
addresses the shortcomings of the traditional, perimeter-centric strategies.
Where is the blindspot in traditional *perimeter* security models? ✔✔Traditional perimeter
security models have a blindspot with monitoring lateral (east-west) traffic within the network.
Which security model does Palo Alto Networks recommend that you deploy?
A) separation-of-trust
B) zero trust
C) trust-then-verify
D) never trust ✔✔*B)* zero trustThe Zero Trust model is implemented to specifically inspect which type of traffic? ✔✔East-West
(Lateral)
What are the *three* main concepts of Zero Trust?
A) All resources are accessed in a secure manner, regardless of location.
B) Access control is on a "need-to-know" basis and is strictly enforced.
C) Credentials need to be verified.
D) All traffic is logged and inspected.
E) Internal users are trusted implicitly.
F) External users are trusted explicitly. ✔✔*A)* All resources are accessed in a secure manner,
regardless of location.
*B)* Access control is on a "need-to-know" basis and is strictly enforced.
*D)* All traffic is logged and inspected.
Which *three* Palo Alto Networks products secure your network?
A) MineMerge
B) Prisma SaaS
C) URL filtering
D) Containers
E) TrapContent
F) WildFire ✔✔*B)* Prisma SaaS
*C)* URL filtering
*F)* WildFire
According to Palo Alto, what are the *six* stages of the Cyber Attack Lifecycle? ✔✔1)
Reconnaissance
2) Weaponization & Delivery
3) Exploitation4) Installation
5) Command & Control
6) Actions on the Objective
How do network security zones assist the zero trust model? ✔✔Network security zones segment
traffic and allow for inspection between zones.
T/F:
Blocking just one stage in the Cyber-Attack Lifecycle is all that is needed to protect a company's
network from attack. ✔✔True
Which of the following are stages of the Cyber-Attack Lifecycle? (Choose two.)
A) weaponization and delivery
B) manipulation
C) extraction
D) command and control ✔✔*A)* weaponization and delivery
*D)* command and control
Command and control be prevented through which *two* methods?
A) exploitation
B) DNS Sinkholing
C) URL filtering
D) reconnaissance ✔✔*B)* DNS Sinkholing
*C)* URL filtering
Exploitation can be mitigated by which actions? (Choose two.)
A) keeping systems patched
B) using local accountsC) blocking known and unknown vulnerability exploits on the endpoint
D) providing admin credentials ✔✔*A)* keeping systems patched
*C)* blocking known and unknown vulnerability exploits on the endpoint
What are the *four* methods used to manage the Palo Alto Networks next-generation firewalls?
✔✔1) Web interface
2) CLI
3) Panorama
4) XML API
What is required to accomplish tasks like retrieving licenses and updating the threat and
application signatures on the firewall? ✔✔The firewall must be able to access the Internet via its
management (MGT) port.
To gain access to the firewall for the first time, what *four* pieces of information are needed for
the MGT port? ✔✔1) IP address
2) Netmask
3) Default gateway
4) At least one DNS server address
Note:
If the firewall is set up as a DHCP client, this information will be included automatically via
DHCP.
What is the default username and password for a Palo Alto Firewall? ✔✔Username: admin
Password: admin
What benefit does CLI access to the firewall offer admins? ✔✔Debug information.What CLI command allows you to access configuration mode while in operational mode?
✔✔*configure*
What are some basic networking commands available from the CLI, while in operational mode?
✔✔Ping, traceroute, etc.
Which mode enables you to display and modify the configuration parameters of the firewall, verify
candidate configuration, and commit the config? ✔✔Configuration Mode
What CLI command would show you both your system up-time and MAC address? ✔✔*show
system state*
What is the name of the Palo Alto Networks product that provides centralized web-based
management, reporting, and logging for multiple firewalls? ✔✔Panorama
How does the Palo Alto XML API work? ✔✔The XML API provides a representational state
transfer (REST)-based interface to access firewall configurations, operational status, reports, and
packet captures from the firewall.
What sort of tasks can the PAN-OS XML API be used to automate? ✔✔1) Create, update, and
modify firewall and Panorama configurations.
2) Execute operational mode commands, such as restarting the system or validating configurations.
3) Retrieve reports.
4) Manage users through User-ID.
5) Update dynamic objects without having to modify or commit new configurations.
What is the firewall dashboard? ✔✔*It is the home screen for the web management GUI.*The firewall Dashboard provides information in a condensed format, including general
information such as device name, MGT IP address, and licensing information. This page can be
augmented by adding, removing, or editing widgets.
What are the *three* categories of widgets that can be displayed on the firewall dashboard? ✔✔1)
Application Widgets
2) Log Widgets
3) System Widgets
What is the *ACC* tab used for? ✔✔*ACC* uses the firewall logs to graphically depict traffic
trends on your network.
What is the *Monitor* tab used for? ✔✔The *Monitor* tab provides logging visibility, the ability
to run packet captures, and report options.
What is the *Policies* tab used for? ✔✔*Policies* allows the creation of policies such as security
policy and NAT policy.
What is the *Objects* tab used for? ✔✔*Objects* allows the creation of objects such as Address
objects.
What is the *Network* tab used for? ✔✔*Network* allows the configuration of network
parameters such as interfaces and zones.
What is the *Device* tab used for? ✔✔*Device* allows the configuration of system information
such as the hostname or certificates.
What does the *task* icon in the bottom right of the GUI do? ✔✔It displays the tasks that you,
other administrators, or the PAN-OS software have initiated since the last firewall reboot (for
example, manual commits or automatic FQDN refreshes).What is the management interface used for? ✔✔The management interface is used to communicate
with servers and systems including: *DNS*, *Email*, *Palo Alto Servers*, *external dynamic
lists*, and Panorama.
What are service routes? ✔✔Service routes are used so that the communication between the
firewall management interface and various servers goes through the data ports on the data plane.
These data ports require appropriate security policy rules before external servers can be accessed.
What is the navigation path within the Palo Alto GUI, for customizing service routes? ✔✔Device
*>* Setup *>* Services *>* Service Route Configuration *>* Customize
Which *three* important *network services* do Palo Alto NGFWs integrate with? ✔✔1) DHCP
2) NTP
3) DNS
T/F:
Palo Alto NGFWs can operate without a primary DNS server configured. ✔✔False
What is the GUI path for configuring a DNS server or NTP server for the Palo Alto to use?
✔✔Device > Setup > Services > Services_gear_icon
What is the GUI path for configuring an IP address or default gateway for the Palo Alto
management interface? ✔✔Device > Setup > Interfaces
What are *two* firewall management methods?
A) CLI
B) RDP
C) VPND) XML API ✔✔*A)* CLI
*D)* XML API
Which *two* devices are used to connect a computer to the firewall for management purposes?
A) rollover cable
B) serial cable
C) RJ-45 Ethernet cable
D) USB cable ✔✔*B)* serial cable
*C)* RJ-45 Ethernet cable
What is the default IP address on the *MGT interface* of a Palo Alto Networks firewall?
A) 192.168.1.1
B) 192.168.1.254
C) 10.0.0.1
D) 10.0.0.254 ✔✔*A)* 192.168.1.1
What are the *two* default services that are available on the MGT interface?
A) HTTPS
B) SSH
C) HTTP
D) Telnet ✔✔*A)* HTTPS
*B)* SSH
T/F:
Service route traffic has Security policy rules applied against it. ✔✔True
Service routes may be used to forward which *two* traffic types out a data port?A) External Dynamic Lists
B) MineMeld
C) Skype
D) Palo Alto Networks updates ✔✔*A)* External Dynamic Lists
*D)* Palo Alto Networks updates
Where do candidate configurations reside? ✔✔Candidate configurations reside in memory on the
*control plane*.
Where do running configurations reside? ✔✔Running configurations reside in memory on the
*data plane*.
Which file format is used for importing and exporting candidate configurations? ✔✔*.xml*
How do you undo a candidate configuration? ✔✔Using the *revert to last saved configuration*
option.
What operation is necessary to write the candidate configuration to the running configuration?
✔✔*commit*
When firewall commits are queued, which commits does the firewall prioritize? ✔✔Commits that
the firewall initiates automatically, such as FQDN refreshes.
What is the GUI path for managing firewall configurations? ✔✔*Device > Setup > Operations*
What is the name of the file that stores the firewall's running configuration? ✔✔*runningconfig.xml*
What are the *five* configuration management options? ✔✔1) Revert2) Save
3) Load
4) Export
5) Import
T/F:
The firewall creates a timestamped version of the running configuration whenever a commit is
made. ✔✔True
Which command backs up configuration files to a remote network device?
A) import
B) load
C) copy
D) export ✔✔*D)* export
The command *load named configuration snapshot* overwrites the current candidate
configuration with which *three* items?
A) custom-named candidate configuration snapshot (instead of the default snapshot)
B) custom-named running configuration that you imported
C) snapshot.xml
D) current running configuration (running-config.xml)
E) Palo Alto Networks updates ✔✔*A)* custom-named candidate configuration snapshot (instead
of the default snapshot)
*B)* custom-named running configuration that you imported
*E)* Palo Alto Networks updates
What is the path used to download the latest firewall updates? ✔✔*Device > Dynamic Updates*
T/F:System updates do not require a firewall reboot. ✔✔False
Which *three* actions should you complete before you upgrade to a newer version of software?
A) Review the release notes to determine any impact of upgrading to a newer version of software.
B) Ensure the firewall is connected to a reliable power source.
C) Export the device state.
D) Create and externally store a backup before you upgrade. ✔✔*A)* Review the release notes to
determine any impact of upgrading to a newer version of software.
*B)* Ensure the firewall is connected to a reliable power source.
*D)* Create and externally store a backup before you upgrade.
Before you install the maintenance or feature release, which release is required to be installed?
✔✔The x.0 base release.
For example, to upgrade from 7.x.y to 8.x.y, download both 8.0 and 8.x.y. 8.0 automatically is
installed when you install 8.x.y.
What's a quick way to verify that the firewall is passing traffic, after finishing an upgrade?
✔✔Select *Monitor > Session Browser* and verify that you are seeing new sessions.
What is the *shortest* time interval that you can configure a Palo Alto Networks firewall to
download WildFire updates?
A) 1 minute
B) 5 minutes
C) 15 minutes
D) 60 minutes ✔✔*A)* 1 minuteWhat is the publishing interval for WildFire updates, with a valid WildFire license?
A) 1 minute
B) 5 minutes
C) 15 minutes
D) 60 minutes ✔✔*B)* 5 minutes
T/F:
A Palo Alto Networks firewall automatically provides a backup of the configuration during a
software upgrade. ✔✔True
If you have a Threat Prevention subscription but not a WildFire subscription, how long must you
wait for the WildFire signatures to be added into the antivirus update?
A) 1 to 2hours
B) 2 to 4hours
C) 10 to 12 hours
D) 12 to 48 hours ✔✔*D)* 12 to 48 hours
Which of the following is *not* a way to download software?
A) over the MGT interface on the control plane
B) over a data interface on the data plane
C) upload from a computer
D) from the Palo Alto Networks Customer Support Portal
E) from the PAN-DB database
F) from Panorama ✔✔*E)* from the PAN-DB databaseE) from the PAN-DB databaseHow can you tell whether a user account is local? ✔✔If the account has *no* authentication
profile, then it is a local account.
What are the *two* admin user role types? ✔✔1) Role Based
2) Dynamic
Where would you find the username, IP, and time for a past change made to the firewall?
✔✔*Configuration logs* display entries for changes to the firewall configuration.
Name at least *three* authentication types that PAN-OS software supports. ✔✔1) None
2) Local Database
3) RADIUS
4) LDAP
5) TACACS+
6) SAML
7) Kerberos
Which *two* statements are true about a Role Based Admin Role profile role?
A) It is a built-in role.
B) It can be used for CLI commands.
C) It can be used for XML API.
D) Superuser is an example. ✔✔*B)* It can be used for CLI commands.
*C)* It can be used for XML API.
Note: Role based profiles are customized, not default; and superuser is not one of them.
Which *two* Dynamic Admin Role types are available on the PAN-OS software?
A) superuserB) superadmin
C) deviceuser
D) device administrator (read-only) ✔✔*A)* superuser
*D)* device administrator (read-only)
Which type of profile does an Authentication Sequence include?
A) Security
B) Authorization
C) Admin
D) Authentication ✔✔*D)* Authentication
An Authentication Profile includes which other type of profile?
A) Server
B) Admin
C) Customized
D) Built-in ✔✔*A)* Server
T/F:
Dynamic Admin Roles are called "dynamic" because you can customize them. ✔✔False
What is used to override global Minimum Password Complexity Requirements?
A) Authentication Profile
B) Local Profile
C) Password Role
D) Password Profile ✔✔*D)* Password Profile
T/F:Zone names are not case sensitive. ✔✔False
What are the *two* requirements for creating zones? ✔✔1) Zone Name
2) Zone Type
What is *intrazone traffic*? ✔✔Intrazone traffic is traffic that flows between interfaces that exist
within the same zone.
For Example:
Traffic flowing from one server in the datacenter zon
[Show More]