What is the Palo Alto Networks Certified Network Security Administrator (PCNSA)?
The Palo Alto Networks Certified Network Security Administrator (PCNSA)
... [Show More] is a new customer targeted certification, created to help customers on their learning journey and the ultimate road to Palo Alto Networks Certified Network Security Engineer (PCNSE). The target audience for the PCNSA is customers who have taken the Firewall 8.1 Essentials: Configuration and Management (EDU-210 or EDU-110) courses. A certified PCNSA can operate Palo Alto Networks next-generation firewalls to protect networks from cutting edge cyber threats.
What is the format of the PCNSA exam?
Certification Name: Palo Alto Networks Certified Network Security Administrator
Delivered through Pearson VUE
Exam Series: PCNSA
Total Seat Time: 90 minutes
Time for Exam Items: 80 minutes
Number of items: 50
Format: Multiple choice, scenarios with graphics, and matching
Language: English
Which topics does the PCNSA exam cover?
PCNSA is a formal, industry-recognized certification program that validates detailed knowledge of core features and functions of Palo Alto Networks next-generation firewalls. This certification covers the following topics:
Next-Generation Security Platform and Architecture
Firewall Configuration
Security and NAT Policies
App-ID
Content-ID
User-ID
URL Filtering
Monitoring and Reporting
Security Best Practices
Which firewall plane provides configuration, logging, and reporting functions on a separate processor?
A. control
B. network processing
C. data
D. security processing
Answer: A
A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days. Based on the information, how is the SuperApp traffic affected after the 30 days have passed?
A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
B. No impact because the apps were automatically downloaded and installed
C. No impact because the firewall automatically adds the rules to the App-ID interface
D. All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
Answer: C
How many zones can an interface be assigned with a Palo Alto Networks firewall?
A. two
B. three
C. four
D. one
Answer: D
Which option shows the attributes that are selectable when setting up application filters?
A. Category, Subcategory, Technology, and Characteristic
B. Category, Subcategory, Technology, Risk, and Characteristic
C. Name, Category, Technology, Risk, and Characteristic
D. Category, Subcategory, Risk, Standard Ports, and Technology
Answer: B [Show Less]