PCNSA Dumps

PCNSA Free Practice Test

Paloalto-Networks PCNSA: Palo Alto Networks Certified Network Security Administrator

QUESTION 1

What are two valid selections within an Antivirus profile? (Choose two.)

Correct Answer: BC

QUESTION 2

An administrator has configured a Security policy where the matching condition includes a single application and the action is deny
If the application s default deny action is reset-both what action does the firewall take*?

Correct Answer: A

QUESTION 3

What are three factors that can be used in domain generation algorithms? (Choose three.)

Correct Answer: ABC
Domain generation algorithms (DGAs) are used to auto-generate domains, typically in large numbers within the context of establishing a malicious command-and-control (C2) communications channel. DGA-based
malware (such as Pushdo, BankPatch, and CryptoLocker) limit the number of domains from being blocked by hiding the location of their active C2 servers within a large number of possible suspects, and can be algorithmically generated based on factors such as time of day, cryptographic keys, or other unique values.
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/dns-security/domain-generation-a

QUESTION 4

Based on the show security policy rule would match all FTP traffic from the inside zone to the outside zone?
PCNSA dumps exhibit

Correct Answer: B

QUESTION 5

You receive notification about a new malware that infects hosts An infection results in the infected host attempting to contact a command-and-control server Which Security Profile when applied to outbound Security policy rules detects and prevents this threat from establishing a command-and-control connection?

Correct Answer: D
Anti-Spyware Security Profiles block spyware on compromised hosts from trying to communicate with external command-and-control (C2) servers, thus enabling you to detect malicious traffic leaving the network from infected clients.