00:00

QUESTION 46

An administrator has 750 firewalls. The administrator's central-management Panorama instance deploys dynamic updates to the firewalls. The administrator notices that the dynamic updates from Panorama do not appear on some of the firewalls.
If Panorama pushes the configuration of a dynamic update schedule to managed firewalls, but the configuration does not appear, what is the root cause?

Correct Answer: D

QUESTION 47

Which three firewall multi-factor authentication factors are supported by PAN-OS? (Choose three)

Correct Answer: BDE
According to Palo Alto Networks documentation123, multi-factor authentication (MFA) is a method of verifying a user’s identity using two or more factors, such as something they know, something they have, or something they are.
The firewall supports MFA for administrative access, GlobalProtect VPN access, and Captive Portal access. The firewall can integrate with external MFA providers such as RSA SecurID, Duo Security, or Okta Verify.
The three firewall MFA factors that are supported by PAN-OS are:
PCNSE dumps exhibit User logon: This is something the user knows, such as a username and password.
PCNSE dumps exhibit One-Time Password: This is something the user has, such as a code generated by an app or sent by email or SMS.
PCNSE dumps exhibit Push: This is something the user is, such as a biometric verification or a device approval.

QUESTION 48

An engineer discovers the management interface is not routable to the User-ID agent What configuration is needed to allow the firewall to communicate to the User-ID agent?

Correct Answer: C
To allow the firewall to communicate with the User-ID agent, you need to configure a custom service route f the UID Agent23. A custom service route allows you to specify which interface and source IP address the firewall uses to connect to a specific destination service. By default, the firewall uses its management interface for services such as User-ID, but you can override this behavior by creating a custom service route.
To configure a custom service route for the UID Agent, you need to do the following steps:
PCNSE dumps exhibit Go to Device > Setup > Services and click Service Route Configuration.
PCNSE dumps exhibit In the Service column, select User-ID Agent from the drop-down list.
PCNSE dumps exhibit In the Interface column, select an interface that can reach the User-ID agent server from the drop-down list.
PCNSE dumps exhibit In the Source Address column, select an IP address that belongs to that interface from the drop-down list.
PCNSE dumps exhibit Click OK and Commit your changes.
The correct answer is C. Create a custom service route for UID Agent

QUESTION 49

The firewall identifies a popular application as an unKnown-tcp.
Which two options are available to identify the application? (Choose two.)

Correct Answer: AB

QUESTION 50

A network security engineer wants to prevent resource-consumption issues on the firewall. Which strategy is consistent with decryption best practices to ensure consistent performance?

Correct Answer: B