PCNSE PCNSE Firewall Technology and Architecture 5 — Questions and Answers
Question 1: Which Palo Alto Networks firewall feature prevents SYN flood attacks by using SYN cookies?
- Zone Protection profile (Correct answer)
- DoS Protection policy
- Vulnerability Protection profile
- Anti-Spyware profile
Correct answer: Zone Protection profile
Zone Protection profiles include flood protection settings including SYN cookies that defend against SYN flood attacks at the zone level.
Question 2: In Palo Alto Networks Panorama, what is a 'Device Group' used for?
- Grouping firewalls for shared policy and object management (Correct answer)
- Grouping interfaces on a single firewall
- Grouping administrators by role
- Grouping log collectors for load balancing
Correct answer: Grouping firewalls for shared policy and object management
Device Groups in Panorama allow administrators to push shared security policies and objects to groups of managed firewalls.
Question 3: What occurs when a Palo Alto Networks firewall encounters an application that is identified mid-session after initial traffic is classified as 'unknown'?
- The session is immediately terminated and re-established
- The firewall re-evaluates the session against security policy with the updated App-ID (Correct answer)
- The session continues with the original unknown classification
- The traffic is sent to WildFire for analysis
Correct answer: The firewall re-evaluates the session against security policy with the updated App-ID
When App-ID identifies an application mid-session, the firewall re-evaluates the session against security policies to enforce the correct application-based rule.
Question 4: Which type of NAT on Palo Alto Networks firewalls allows multiple internal hosts to share a single public IP address using port translation?
- Static NAT
- Dynamic IP NAT
- Dynamic IP and Port (DIPP) NAT (Correct answer)
- Destination NAT
Correct answer: Dynamic IP and Port (DIPP) NAT
Dynamic IP and Port (DIPP) NAT, also called PAT or overload NAT, translates many-to-one by using unique port numbers to track each internal session.
Question 5: In Palo Alto Networks firewalls, what is the purpose of configuring a 'Null' route or 'discard' interface?
- To drop traffic matching specific routes without generating ICMP unreachable messages (Correct answer)
- To redirect traffic to the management plane for inspection
- To load balance traffic across multiple ISP links
- To create a dedicated interface for out-of-band management
Correct answer: To drop traffic matching specific routes without generating ICMP unreachable messages
A discard (null) route is used to drop traffic destined for specific prefixes silently, commonly used to prevent routing loops or block RFC1918 space from being forwarded to the internet.
Question 6: Which Palo Alto Networks feature enables automatic security policy recommendations based on application usage observed in your environment?
- Expedition
- Security Policy Optimizer (Correct answer)
- AutoFocus
- Cortex XDR
Correct answer: Security Policy Optimizer
Security Policy Optimizer analyzes traffic logs to recommend converting overly permissive port-based rules into precise application-based rules.
Question 7: What is the effect of enabling 'Log at Session Start' in a Palo Alto Networks Security policy rule?
- Logs are generated when the session is first established, before it completes (Correct answer)
- Logs are only generated at session end regardless of this setting
- Logs are generated for every packet in the session
- Session start logging replaces session end logging
Correct answer: Logs are generated when the session is first established, before it completes
When 'Log at Session Start' is enabled, a log entry is created when the session is first established, providing visibility into connections that may be long-lived.
Which Palo Alto Networks firewall feature prevents SYN flood attacks by using SYN cookies?