Month End Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Legit PCNSE Exam Download

Page: 13 / 28
Total 374 questions

Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 11.0 Questions and Answers

Question 49

An engineer is configuring Packet Buffer Protection on ingress zones to protect from single-session DoS attacks.

Which sessions does Packet Buffer Protection apply to?

Options:

A.

It applies to existing sessions and is global.

B.

It applies to new sessions and is not global.

C.

It applies to existing sessions and is not global.

D.

It applies to new sessions and is global.

Question 50

In the following image from Panorama, why are some values shown in red?

Options:

A.

sg2 session count is the lowest compared to the other managed devices.

B.

us3 has a logging rate that deviates from the administrator-configured thresholds.

C.

uk3 has a logging rate that deviates from the seven-day calculated baseline.

D.

sg2 has misconfigured session thresholds.

Question 51

An engineer is monitoring an active/active high availability (HA) firewall pair.

Which HA firewall state describes the firewall that is currently processing traffic?

Options:

A.

Initial

B.

Passive

C.

Active

D.

Active-primary

Question 52

An administrator is building Security rules within a device group to block traffic to and from malicious locations.

How should those rules be configured to ensure that they are evaluated with a high priority?

Options:

A.

Create the appropriate rules with a Block action and apply them at the top ol the Security Pre-Rules.

B.

Create the appropriate rules with a Block action and apply them at the top of the Security Post-Rules.

C.

Create the appropriate rules with a Block action and apply them at the top of the local firewall Security rules.

D.

Create the appropriate rules with a Block action and apply them at the top of the Default Rules.

Page: 13 / 28
Total 374 questions