Exam Code: PCNSE6
Exam Name: Palo Alto Networks Certified Network Security
PCNSE6 PDF VCE Total Q&A: 60 Questions and Answers
Last Update: 2015-11-16

NO.1 Two firewalls are configured in an Active/Passive High Availability (HA) pair with the following
election settings:
Firewall 5050-B is presently in the "Active" state and 5050-A is presently in the "Passive" state.
Firewall 5050-B reboots causing 5050-A to become Active.
Which firewall will be in the "Active" state after firewall 5050-B has completed its reboot and is back
A. Both firewalls are active (split brain)
B. Firewall 5050-B
C. Firewall 5050-A
D. It could be either firewall
Answer: B

Match the components with their role in preventing threats.
Answer options may be used more than once or not at all.
Panorama - Dynamically updates firewall policy with VM context for NSX
Physical Firewall - Inspects North-South traffic for threats Wildfire -Generates zero-day threat
signatures VM series firewall- Inspects east-west traffic for threats

NO.3 A company hosts a publicly-accessible web server behind their Palo Alto Networks firewall, with
this configuration information:
-Users outside the company are in the "Untrust-L3" zone.
-The web server physically resides in the "Trust-L3" zone.
-Web server public IP address:
-Web server private IP address:
Which NAT Policy rule will allow users outside the company to access the web server?
A. Option A
B. Option B
C. Option C
D. Option D
Answer: B

NO.4 Which two interface types provide support for network address translation (NAT)? Choose 2
B. Tap
C. Layer3
D. Virtual Wire
E. Layer2
Answer: C,D

NO.5 Where can the maximum concurrent SSL VPN Tunnels be set for Vsys2 when provisioning a Palo
Alto Networks firewall for multiple virtual systems?
A. In the GUI under Network->Global Protect->Gateway->Vsys2
B. In the GUI under Device->Setup->Session->Session Settings
C. In the GUI under Device->Virtual Systems->Vsys2->Resource
D. In the GUI under Network->Global Protect->Portal->Vsys2
Answer: C

NO.6 Which authentication method can provide role-based administrative access to firewalls running
B. Certificate-based authentication
C. Kerberos
D. RADIUS with Vendor Specific Attributes
Answer: D

