Palo-alto-networks

PCNSA practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 356-question bank.

Provider
Palo-alto-networks
Question bank
356
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for PCNSA, a certification listed under Palo-alto-networks. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Palo-alto-networks. The certification credential is issued by Palo-alto-networks, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which two statements are correct about App-ID content updates? (Choose two.)

    Choose all answers that apply.

    • Updated application content might change how Security policy rules are enforced.
    • After an application content update, new applications must be manually classified prior to use.
    • Existing security policy rules are not affected by application content updates.
    • After an application content update, new applications are automatically identified and classified.
  2. Question 2 · 1

    Which type of administrator account cannot be used to authenticate user traffic flowing through the firewall's data plane?

    Choose one answer.

    • Kerberos user
    • SAML user
    • local database user
    • local user
  3. Question 3 · 1

    How frequently can WildFire updates be made available to firewalls?

    Choose one answer.

    • every 15 minutes
    • every 30 minutes
    • every 60 minutes
    • every 5 minutes
  4. Question 4 · 1

    Starting with PAN-OS version 9.1, which new type of object is supported for use within the User field of a Security policy rule?

    Choose one answer.

    • remote username
    • dynamic user group
    • static user group
    • local username
  5. Question 5 · 1

    Which link in the web interface enables a security administrator to view the Security policy rules that match new application signatures?

    Choose one answer.

    • Review App Matches
    • Review Apps
    • Pre-analyze
    • Review Policies
  6. Question 6 · 1

    Based on the shown security policy, which Security policy rule would match all FTP traffic from the inside zone to the outside zone?

    Choose one answer.

    Question illustration 1
    • interzone-default
    • internal-inside-dmz
    • inside-portal
    • egress-outside
  7. Question 7 · 1

    Which type of firewall configuration contains in-progress configuration changes?

    Choose one answer.

    • backup
    • candidate
    • running
    • committed
  8. Question 8 · 1

    What is an advantage for using application tags?

    Choose one answer.

    • They are helpful during the creation of new zones.
    • They help content updates automate policy updates.
    • They help with the creation of interfaces.
    • They help with the design of IP address allocations in DHCP.
  9. Question 9 · 1

    At which point in the App-ID update process can you determine if an existing policy rule is affected by an App-ID update?

    Choose one answer.

    • after clicking Check Now in the Dynamic Update window
    • after committing the firewall configuration
    • after installing the update
    • after downloading the update
  10. Question 10 · 1

    You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact a command-and-control server. Which Security Profile detects and prevents this threat from establishing a command-and-control connection?

    Choose one answer.

    • Vulnerability Protection Profile applied to outbound Security policy rules.
    • Anti-Spyware Profile applied to outbound security policies.
    • Antivirus Profile applied to outbound Security policy rules
    • Data Filtering Profile applied to outbound Security policy rules.
  11. Question 11 · 1

    Which User-ID mapping method should be used for an environment with users that do not authenticate to Active Directory?

    Choose one answer.

    • Windows session monitoring
    • passive server monitoring using the Windows-based agent
    • Captive Portal
    • passive server monitoring using a PAN-OS integrated User-ID agent
  12. Question 12 · 1

    Which statement is true regarding a Best Practice Assessment?

    Choose one answer.

    • It runs only on firewalls.
    • It shows how current configuration compares to Palo Alto Networks recommendations.
    • When guided by an authorized sales engineer, it helps determine the areas of greatest risk where you should focus prevention activities.
    • It provides a set of questionnaires that help uncover security risk prevention gaps across all areas of network and security architecture.
  13. Question 13 · 1

    Which Palo Alto Networks service protects cloud-based applications such as Dropbox and Salesforce by monitoring permissions and shares and scanning files for sensitive information?

    Choose one answer.

    • Prisma SaaS
    • AutoFocus
    • Panorama
    • GlobalProtect
  14. Question 14 · 1

    Based on the Security policy rules shown, SSH will be allowed on which port?

    Choose one answer.

    Question illustration 1
    • the default port
    • only ephemeral ports
    • any port
    • same port as ssl and snmpv3
  15. Question 15 · 1

    You receive notification about new malware that is being used to attack hosts. The malware exploits a software bug in common application. Which Security Profile detects and blocks access to this threat after you update the firewall's threat signature database?

    Choose one answer.

    • Data Filtering Profile applied to outbound Security policy rules
    • Antivirus Profile applied to outbound Security policy rules
    • Data Filtering Profile applied to inbound Security policy rules
    • Vulnerability Protection Profile applied to inbound Security policy rules

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free