PCNSE Questions and Answers

Question # 1

Based on the screenshots above, and with no configuration inside the Template Stack itself, what access will the device permit on its Management port?


The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1.


The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-2.


The firewall will allow HTTP, Telnet, SNMP, HTTPS, SSH and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.


The firewall will allow HTTP, Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.View Answer

Question # 2

A company has recently migrated their branch office’s PA-220S to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices All device group and template configuration is managed solely within Panorama

They notice that commit times have drastically increased for the PA-220S after the migration

What can they do to reduce commit times?


Disable “Share Unused Address and Service Objects with Devices” in Panorama Settings.


Update the apps and threat version using device-deployment


Perform a device group push using the “merge with device candidate config” opt

Question # 3

After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall After troubleshooting the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports

What can the engineer do to solve the VoIP traffic issue?


Disable ALG under H.323 application


Increase the TCP timeout under H.323 application


Increase the TCP timeout under SIP application


Disable ALG under SIP application