PCNSE PCNSE Palo Alto Networks Firewall Configuration 3 — Questions and Answers
Question 1: An administrator needs to configure the firewall to dynamically update security policies based on user identity obtained from Active Directory without installing an agent on every endpoint. Which feature should be used?
- User-ID with WMI Probing (Correct answer)
- GlobalProtect with HIP profiles
- Captive Portal authentication
- LDAP authentication profile
Correct answer: User-ID with WMI Probing
User-ID WMI Probing queries Windows Management Instrumentation on domain controllers to map IP addresses to usernames without requiring per-endpoint agents.
Question 2: Which PAN-OS object type allows an administrator to reference a dynamically updated list of IP addresses, URLs, or domains that is maintained externally and automatically refreshed by the firewall?
- Address Group
- External Dynamic List (EDL) (Correct answer)
- Dynamic Address Group (DAG)
- Custom URL Category
Correct answer: External Dynamic List (EDL)
External Dynamic Lists (EDLs) allow the firewall to pull and automatically refresh IP, URL, or domain lists from an external web server at configured intervals.
Question 3: When configuring a Site-to-Site VPN tunnel on a Palo Alto firewall, which IKE (Internet Key Exchange) parameter defines the lifetime of the Phase 1 (IKE) SA before it must be renegotiated?
- DH Group
- Key Lifetime (Correct answer)
- IKE Crypto Profile
- Authentication Algorithm
Correct answer: Key Lifetime
The Key Lifetime parameter in the IKE Crypto Profile specifies how long the Phase 1 IKE Security Association remains valid before renegotiation is required.
Question 4: A security engineer wants to prevent users from accessing newly registered domains that have been active for less than 30 days. Which PAN-OS feature directly enables this capability?
- DNS Security profile with sinkholing
- URL Filtering profile with 'newly registered domains' category (Correct answer)
- Anti-spyware profile with DNS signature
- Custom URL category with regex matching
Correct answer: URL Filtering profile with 'newly registered domains' category
URL Filtering profiles include a 'Newly Registered Domains' category that can be blocked to prevent access to domains registered within the past 32 days.
Question 5: In PAN-OS, what is the function of the 'Security Profile Group' object when applied to a security policy rule?
- It defines the source and destination zones for the rule
- It groups multiple security profiles (AV, IPS, URL filtering, etc.) into a single reusable object applied to matching traffic (Correct answer)
- It specifies user authentication requirements for the policy
- It controls QoS markings for traffic matching the rule
Correct answer: It groups multiple security profiles (AV, IPS, URL filtering, etc.) into a single reusable object applied to matching traffic
A Security Profile Group bundles Antivirus, Anti-spyware, Vulnerability Protection, URL Filtering, and other profiles into one object for simplified policy assignment.
Question 6: Which Palo Alto Networks technology identifies applications regardless of port, protocol, or encryption by using application signatures, behavioral analysis, and heuristics?
- Content-ID
- App-ID (Correct answer)
- User-ID
- WildFire
Correct answer: App-ID
App-ID uses multiple identification mechanisms including application signatures, decryption, protocol decoding, and heuristics to identify applications independent of port or protocol.
Question 7: An administrator configures a NAT policy on a Palo Alto firewall where the source IP is translated to an IP address from a pool. When the pool is exhausted, what happens to new connection attempts by default?
- Connections are dropped silently (Correct answer)
- The firewall falls back to the interface IP address
- Connections are queued until a pool address becomes available
- The firewall logs a warning and continues with the original IP
Correct answer: Connections are dropped silently
When a dynamic IP NAT pool is exhausted, new connections that require translation are dropped because no available translation address exists.
An administrator needs to configure the firewall to dynamically update security policies based on user identity obtained from Active Directory without installing an agent on every endpoint.
Which feature should be used?