Palo Alto Networks PCNSE日本語テストエンジン問題集トレーニングには840問あります
PCNSE日本語問題一発合格させる問題集はPCNSE認定
質問 # 159
User-ID ユーザー マッピングを収集するための最も信頼できるソースはどれですか?
- A. Syslog Listener
- B. Microsoft Exchange
- C. GlobalProtect
- D. Microsoft Active Directory
正解:C
解説:
Explanation
User-ID is a feature that enables you to identify and control users on your network based on their usernames instead of their IP addresses1. User mapping is the process of mapping IP addresses to usernames using various sources of information1.
The most reliable source for collecting User-ID user mapping is GlobalProtect2. GlobalProtect is a solution that provides secure access to your network and resources from anywhere. GlobalProtect agents on endpoints send user mapping information directly to the firewall or Panorama, which eliminates the need for probing other sources2. GlobalProtect also supports dynamic IP address changes and roaming users2.
質問 # 160
ファイアウォールの構成をいくつか変更した後、管理者はアプリケーションの識別が失敗し始めたことを発見しました。管理者はさらに調査を進め、アプリケーションが不明 tcp として表示され、多数のセッションが破棄状態になりつつあることに気付きました。
この問題の原因として考えられるファイアウォールの変更はどれですか?
- A. ファイアウォールでジャンボ フレームが無効になったため、アウトオブオーダーとアプリケーション識別専用のキュー サイズが減少しました。
- B. ファイアウォールでジャンボ フレームが有効になったため、App-ID キュー サイズと使用可能なパケット バッファーの数が減少しました。
- C. [デバイス] > [セットアップ] > [コンテンツ ID] > [コンテンツ ID 設定] で、TCP App-ID 検査キューを超える転送セグメントを有効にします。
- D. [デバイス] > [セットアップ] > [コンテンツ ID] > [コンテンツ ID 設定] で TCP コンテンツ検査キューを超える転送セグメントを有効にします。
正解:C
解説:
Disable this option to prevent the firewall from forwarding TCP segments and skipping App-ID inspection when the App-ID inspection queue is full.
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/device/device-setup- content-id
質問 # 161
管理者は、Palo AltoNetworksNGFWを最新バージョンのPAN-OSソフトウェアにアップグレードする必要があります。ファイアウォールにはイーサネットインターフェイスを介したインターネット接続がありますが、管理インターフェイスからのインターネット接続はありません。セキュリティポリシーには、デフォルトのセキュリティルールと、任意のゾーンから任意のゾーンへのすべてのWebブラウジングトラフィックを許可するルールがあります。PAN-OSソフトウェアをアップグレードできるように、管理者は何を構成する必要がありますか?
- A. セキュリティポリシールール
- B. スケジューラ
- C. サービスルート
- D. CRL
正解:A
質問 # 162
エンジニアは、内部ユーザーのトラフィックがファイアウォールを後退しているときに、そのトラフィックをより可視化するために、SSL 復号化を構成します。
SSL フォワード プロキシをサポートする 3 種類のインターフェイスはどれですか? (3つ選んでください。)
- A. Layer 3
- B. Layer
- C. Tap
- D. Virtual Wire
- E. High availability (HA)
正解:A、B、D
解説:
SSL Forward Proxy is a feature that allows the firewall to decrypt and inspect outbound SSL traffic from internal users to external servers1. The firewall acts as a proxy (MITM) generating a new certificate for the accessed URL and presenting it to the client during SSL handshake2.
SSL Forward Proxy can be configured on any interface type that supports security policies, which are Layer 2, Virtual Wire, and Layer 3 interfaces1. These interface types allow the firewall to apply security profiles and URL filtering on the decrypted SSL traffic.
質問 # 163
管理者は、すべての非ネイティブMFAプラットフォームをPAN-OSソフトウェアに統合するためにどの方法を使用しますか?
- A. PingID
- B. DUO
- C. RADIUS
- D. オクタ
正解:C
解説:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/authentication-types/multi-factor-auth For end-user authentication via Authentication Policy, the firewall directly integrates with several MFA platforms (Duo v2, Okta Adaptive, PingID, and RSA SecurID), as well as integrating through RADIUS or SAML for all other MFA platforms.
質問 # 164
付属書類を参照してください。.
どの証明書をForwarded Trust証明書として使用できますか?
- A. デフォルトの信頼認証局からの証明書
- B. Forward_Trust
- C. Domain Sub-CA
- D. Domain-Root-Cert
正解:C
解説:
The SSL Forward Proxy certificate must be a trusted CA certificate with private key. In order to use this cert as a Forward Proxy certificate, you must open the certificate and select the checkbox to enable it as a Forward Trust Certificate. See the following doc, Step 2 number 5: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/configure-ssl-forward-proxy.html
質問 # 165 
- A. Packet forwarding process
- B. Packet egress process
- C. SSL Proxy re-encrypt
- D. IPsec tunnel encryption
正解:A
質問 # 166 
アクティブ ファイアウォールが HA ピアとの通信を失ったときに、パッシブ ファイアウォールが引き継ぐまでに待機する時間を決定するのはいつですか?
- A. 落下保持時間の監視
- B. プロモーション保留時間
- C. ハートビート間隔
- D. 追加のマスター待機時間
正解:C
質問 # 167
エンジニアは SSL 復号化の実装を計画しています
次のステートメントのうち、SSL 復号化のベスト プラクティスはどれですか?
- A. 公的に信頼されたルート CA から、前方信頼証明書用の証明書を取得します。
- B. ネットワーク内のすべてのファイアウォールで同じ前方信頼証明書を使用します。
- C. Forward Untrust 証明書にエンタープライズ CA 署名付き証明書を使用します。
- D. 前方信頼証明書のエンタープライズ CA 署名付き証明書を取得します。
正解:D
解説:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward-proxy (Best Practice) Enterprise CA-signed Certificates-An enterprise CA can issue a signing certificate that the firewall can use to sign the certificates for sites which require SSL decryption. When the firewall trusts the CA that signed the certificate of the destination server, the firewall can send a copy of the destination server certificate to the client, signed by the enterprise CA. This is a best practice because usually all network devices already trust the Enterprise CA (it is usually already installed in the devices' CA Trust storage), so you don't need to deploy the certificate on the endpoints, so the rollout process is smoother. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-forward-proxy.html
質問 # 168
組織は最近、インフラストラクチャと構成をNGFWに移行しました。NGFWでは、Panoramaがデバイスを管理します。組織はL2-L4ファイアウォールベンダーから来ていますが、不要になったポリシーを特定しながらApp-IDを使用したいと考えています。どのPanoramaツールが役立つかこの組織?
- A. テストポリシーの一致
- B. 構成監査
- C. アプリケーショングループ
- D. ポリシーオプティマイザー
正解:D
解説:
This new feature identifies port-based rules so you can convert them to application-based rules that allow the traffic or add applications to existing rules without compromising application availability.
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/app-id-features/policy- optimizer.html
質問 # 169
証明書の失効ステータスを検証するために設定できる2つの方法はどれですか。 (2つ選んでください。)
- A. Cert-Validation-Profile
- B. SSL/TLS Service Profile
- C. CRT
- D. OCSP
- E. CRL
正解:D、E
解説:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/certificate-management/set- up-verification-for-certificate-revocation-status
質問 # 170
エンジニアは復号化ブローカー機能を構成する必要があります。エンジニアは、復号化ブローカーのセキュリティ チェーンで使用される復号化転送インターフェイスをどのルーターに割り当てる必要がありますか?
- A. データ タイプのトラフィックを渡すための追加インターフェイスがなく、セキュリティ チェーンに使用されるルート以外に設定されたルートも持たない仮想ルーター。
- B. 復号化ブローカーのセキュリティ チェーンが検査するトラフィックをルーティングする仮想ルーター。
- C. デフォルトの仮想ルーター。デフォルトの仮想ルーターがない場合、エンジニアはセットアップ中に仮想ルーターを作成する必要があります。
- D. 少なくとも 1 つの動的ルーティング プロトコルで構成され、RIB に少なくとも 1 つのエントリを持つ仮想ルーター
正解:B
解説:
Decryption Broker is a feature that allows you to use a Palo Alto Networks firewall as a decryption broker for other security devices in your network. It works by decrypting traffic on one interface and forwarding it to another interface where it can be inspected by other devices before being re- encrypted and sent to its destination. The firewall acts as a transparent bridge between the two interfaces and does not change the source or destination IP addresses of the traffic. To configure Decryption Broker, you need to assign decryption forwarding interfaces (DFIs) to the virtual router that routes the traffic that you want to inspect. The DFIs are used to forward decrypted traffic from one interface to another in a security chain. A security chain is a set of devices that perform different security functions on the same traffic flow. You can have multiple security chains for different types of traffic or different segments of your network. The reason why you need to assign DFIs to the virtual router that routes the traffic is because Decryption Broker uses routing tables to determine which DFI belongs to which security chain and how to forward traffic between them. If you assign DFIs to a different virtual router than the one that routes the traffic, Decryption Broker will not be able to find them or forward traffic correctly.
質問 # 171
スーパー ユーザーは、3 人の請負業者の管理者アカウントを作成する任務を負っています。コンプライアンスの目的で、3 つの請負業者はすべて、階層内の異なるデバイス グループを使用して、ポリシーとオブジェクトを展開します。
このプロジェクトに最も適した役割ベースのアクセスのタイプはどれですか?
- A. デバイス グループとテンプレート管理者を作成します。
- B. カスタム パノラマ管理者を作成します。
- C. パノラマ管理者ロールを持つ動的管理者を作成します。
- D. 動的読み取り専用スーパーユーザーを作成する
正解:A
解説:
A Device Group and Template Admin is a type of role-based access that allows the administrator to assign different privileges for different device groups and templates. This is useful for managing multiple firewalls with different configuration needs. For example, the administrator can create a Device Group and Template Admin role that allows the contractors to deploy policies and objects only to their assigned device groups and templates1. The other options are not suitable for this project. A Dynamic Admin with the Panorama Administrator role has full access to all device groups and templates2. A Custom Panorama Admin can have limited access to device groups and templates, but cannot have different privileges for different device groups and templates3. A Dynamic Read only superuser can only view the configuration and logs, but cannot deploy policies and objects. Reference: 1: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/role-based-access-control/administrative-roles/device-group-and-template-admin 2: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/role-based-access-control/administrative-roles/dynamic-admin 3: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/role-based-access-control/administrative-roles/custom-panorama-admin : https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/panorama-overview/role-based-access-control/administrative-roles/dynamic-read-only-superuser
質問 # 172
お客様は、従来のリモートアクセスVPNソリューションを置き換えています。現在のソリューションは、インターネットの出力を保護し、接続されたクライアントのメインデータセンターにあるリソースへのアクセスを提供するために用意されています。
Prisma Accessは、現在のリモートアクセスVPNソリューションに代わるものとして選択されました。オンボーディング中に、次のオプションとライセンスが選択され、有効になりました
データセンター内のリソースへの接続を提供するには、Prisma Accessで何を構成する必要がありますか?
- A. データセンターへの接続を提供するように動的ルーティングを構成します
- B. データセンターへの接続を有効にするために、データセンターに最も近いリージョンでモバイルユーザーゲートウェイを構成します
- C. データセンターへの接続を提供するようにサービス接続を構成します
- D. データセンターへの接続を提供するようにリモートネットワークを構成します
正解:D
質問 # 173
どの2つのタイプの展開でアクティブ/アクティブHA構成がサポートされていますか? (2つを選択してください)
- A. TAP mode
- B. Virtual Wire mode
- C. Layer 2 mode
- D. Layer 3 mode
正解:B、D
解説:
Active/Active- Both firewalls in the pair are active and processing traffic and work synchronously to handle session setup and session ownership. Both firewalls individually maintain session tables and routing tables and synchronize to each other. Active/active HA is supported in virtual wire and Layer 3 deployments. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/ha-modes
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/ha-modes#:~:text=Active%2Fpassive%20HA%20is%20supported,such%20as%20IPSec%20security%20associations.
質問 # 174
管理者が稼働時間、PAN-OSバージョン、シリアル番号などのファイアウォールに関する詳細を表示できるようにするCLIコマンドはどれですか。
- A. システムの詳細を表示
- B. デバッグシステムの詳細
- C. システム情報を表示
- D. セッション情報を表示
正解:C
解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZuCAK
質問 # 175 
- A. Option C
- B. Option A
- C. Option B
- D. Option D
正解:B
質問 # 176
ネットワーク管理者は、ピアデバイスがイニシエーターとして機能するサイト間VPNトンネルを構成しました。ピアアドレスは不明です。管理者は、VPN接続を確立するために何を構成できますか1。
- A. 動的IPアドレスタイプを使用する
- B. ピアアドレスをFQDNとして構成します
- C. パッシブモードを有効にする
- D. 証明書認証を設定します
正解:A
質問 # 177
管理者は、PAN-OS 10.2 を実行しているパロ アルト ネットワーク ファイアウォール上で、アドバンスト ルーティングを有効にして OSPF を構成しました。OSPF を設定した後、管理者は OSPF ルートが学習されていないことに気付きました。
この問題をトラブルシューティングするために管理者が実行できるアクションを 2 つ選択してください。(2つお選びください。)
- A. CLI コマンド show Advanced-routing ospf neighbors を実行します。
- B. WebUI で、仮想ルーターのランタイム統計を表示します。
- C. WebUI で、論理ルーターの実行時統計を表示します。
- D. [ネットワーク] > [仮想ルーター] > [OSPF] で構成の問題を探します。
正解:A、C
解説:
It says the Advanced routing is enabled, which means that Logical routers not Virtual Routers.
質問 # 178
コミットが完了する前に、管理者が誤ってコミット ウィンドウ/画面を閉じました。そのコミット タスクの進行状況または成功を確認するために管理者が使用できる 2 つのオプションはどれですか? (2つ選んでください。)
- A. トラフィック ログ
- B. 構成ログ
- C. タスク マネージャー
- D. システムログ
正解:C、D
解説:
1. System Logs: The system logs contain information about various events that occur on the firewall, including the commit process. The administrator can review the system logs to verify whether the commit completed successfully or whether there were any errors or warnings during the commit process.
2. Task Manager: The task manager displays a list of all active tasks on the firewall, including the commit task. The administrator can use the task manager to check the status of the commit task, including whether it is in progress, completed successfully, or failed.
質問 # 179
A/P ファイアウォール クラスターが IPsec トンネル セキュリティ アソシエーション (SA) を同期すると何が起こりますか?
- A. フェーズ 2 SA は HA2 リンクを介して同期されます。
- B. フェーズ 1 およびフェーズ 2 SA は HA2 リンクを介して同期されます。
- C. フェーズ 1 およびフェーズ 2 SA は HA3 リンクを介して同期されます。
- D. フェーズ 1 SA は HA1 リンクを介して同期されます。
正解:A
解説:
From the Palo Alto documentation below, "when a VPN is terminated on a Palo Alto firewall HA pair, not all IPSEC related information is synchronized between the firewalls... This is an expected behavior. IKE phase 1 SA information is NOT synchronized between the HA firewalls." And from the second link, "Data link (HA2) is used to sync sessions, forwarding tables, IPSec security associations, and ARP tables between firewalls in the HA pair. Data flow on the HA2 link is always unidirectional (except for the HA2 keep-alive). It flows from the active firewall to the passive firewall."
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuZCAW&lang
=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCS ArticleDetail
https://help.aryaka.com/display/public/KNOW/Palo+Alto+Networks+NFV+Technical+Brief
質問 # 180
事前設定されたファイアウォール設定を Panorama にインポートした後、ローカル設定を複製せずにコミット/プッシュが成功するようにするには、どのような手順が必要ですか?
- A. 最初にデバイス グループをプッシュし、次にテンプレートを新しく管理されたファイアウォールにプッシュします。
- B. エクスポートを実行するか、デバイス構成バンドルを新しく管理されたファイアウォールにプッシュします。
- C. 最初にテンプレートをプッシュし、次にデバイス グループを新しく管理されたファイアウォールにプッシュします。
- D. 構成をプッシュするときに、テンプレート値の強制がチェックされていることを確認します。
正解:B
解説:
When importing a pre-configured firewall configuration to Panorama, you need to perform the following steps:
Add the serial number of the firewall under Panorama > Managed Devices In Panorama, import the firewall's configuration bundle under Panorama > Setup > Operations > Import device configuration to Panorama Make changes to the imported firewall configuration within Panorama Commit the changes you made to Panorama Perform an Export or push Device Config Bundle operation under Panorama > Setup > Operations The Export or push Device Config Bundle operation allows you to push a complete configuration bundle from Panorama to a managed firewall without duplicating local configurations. This operation ensures that any local settings on the firewall are preserved and merged with the settings from Panorama.
質問 # 181
VPN のフェーズ 2 では接続は確立されません。ピアはポリシーベースの VPN 構成を使用しています。
エンジニアは構成のどの部分を検証する必要がありますか?
- A. PAN-OS のバージョン
- B. セキュリティポリシー
- C. プロキシ ID
- D. IKE 暗号プロファイル
正解:C
解説:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbXCAS https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/td-p/424789
質問 # 182 
- A. Option B
- B. Option A
- C. Option C
- D. Option D
正解:C
質問 # 183
......
PCNSE日本語練習テストPDF試験材料:https://jp.fast2test.com/PCNSE-JPN-premium-file.html