We provide real pcnse6 study guide exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Paloalto Networks pcnse6 study guide Exam quickly & easily. The pcnse6 dumps PDF type is available for reading and printing. You can print more and practice many times. With the help of our Paloalto Networks pcnse6 pdf dumps pdf and vce product and material, you can easily pass the pcnse6 exam exam.
Q1. What is the name of the debug save file for IPSec VPN tunnels?
A. set vpn all up
B. test vpn ike-sa
C. request vpn IPsec-sa test
D. Ikemgr.pcap
Answer: D
Q2. HOTSPOT
Within a Zone Protection Profile, under the Reconnaissance Protection tab, there are several possible values for Action:
Match each Reconnaissance Protection Action to its description. Answer options may be used more than once or not at all.
Answer:
Q3. Where in the firewall GUI can an administrator see how many sessions of web-browsing traffic have occurred in the last day?
A. Monitor->Session Browser
B. Monitor->App Scope->Summary
C. Objects->Applications->web-browsing
D. ACC->Application
Answer: D
Explanation:
Reference: http://www.newnet66.org/Support/Resources/Using-The-ACC.pdf
Q4. When employing the Brightcloud URL filtering database on the Palo Alto Networks firewalls, the order of checking within a profile is:
A. Block List, Allow List, Custom Categories, Cache Files, Predefined Categories, Dynamic URL Filtering
B. Block List, Allow List, Cache Files, Custom Categories, Predefined Categories, Dynamic URL Filtering
C. Dynamic URL Filtering, Block List, Allow List, Cache Files, Custom Categories, Predefined Categories
D. None of the above
Answer: A
Q5. Which link is used by an Active-Passive cluster to synchronize session information?
A. The Data Link
B. The Control Link
C. The Uplink
D. The Management Link
Answer: A
Q6. Which Security Policy rule configuration option disables antivirus and anti-spyware scanning of server-to-client flows only?
A. Apply an Application Override Policy
B. Disable Server Response Inspection
C. Add server IP to Security Policy exception
D. Disable HIP Profile
Answer: B
Explanation:
Reference: https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/getting-started/set-up-basic-security-policies.html
Q7. After pushing a security policy from Panorama to a PA-3020 firewall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs.
What could be the problem?
A. The firewall is not licensed for logging to this Panorama device.
B. Panorama is not licensed to receive logs from this particular firewall.
C. None of the firewall’s policies have been assigned a Log Forwarding profile.
D. A Server Profile has not been configured for logging to this Panorama device.
Answer: C
Q8. In PAN-OS 5.0, which of the following features is supported with regards to IPv6?
A. OSPF
B. NAT64
C. IPSec VPN tunnels
D. None of the above
Answer: B