PCNSE Exam Question 256

What happens, by default, when the GlobalProtect app fails to establish an IPSec tunnel to the GlobalProtect gateway?
  • PCNSE Exam Question 257

    A web server is hosted in the DMZ, and the server is configured to listen for incoming connections only on TCP port 8080. A Security policy rule allowing access from the Trust zone to the DMZ zone need to be configured to enable we browsing access to the server.
    Which application and service need to be configured to allow only cleartext web-browsing traffic to thins server on tcp/8080.
  • PCNSE Exam Question 258

    A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama.
    Which configuration is necessary to retrieve groups from Panorama?
  • PCNSE Exam Question 259

    A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed to multiple remote offices and the Network Administrator decides to use Panorama to deploy the configurations.
    How should this be accomplished?
  • PCNSE Exam Question 260

    An administrator wants to configure the Palo Alto Networks Windows User-ID agent to map IP addresses to usernames.
    The company uses four Microsoft Active Directory servers and two Microsoft Exchange servers, which can provide logs for login events.
    All six servers have IP addresses assigned from the following subnet: 192.168.28.32/27.
    The Microsoft Active Directory servers reside in 192.168.28.32/28, and the Microsoft Exchange servers reside in 192.168.28.48/28.
    What information does the administrator need to provide in the User Identification > Discovery section?