exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 317 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 317
Topic #: 1
[All PCNSA Questions]

Which three management interface settings must be configured for functional dynamic updates and administrative access on a Palo Alto Networks firewall? (Choose three.)

  • A. NTP
  • B. IP address
  • C. MTU
  • D. DNS server
  • E. service routes
Show Suggested Answer Hide Answer
Suggested Answer: ABD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 1 month ago
Selected Answer: ABD
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/service-routes
upvoted 7 times
...
JakaP
Highly Voted 2 years, 2 months ago
Selected Answer: BDE
It is : B,D,E
upvoted 6 times
[Removed]
2 years, 1 month ago
The management interface does not require a service route. This is only if you a re doing management through the data plane. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/service-routes
upvoted 8 times
cert111
1 year, 11 months ago
Correct that they don't REQUIRE service routes, but service routes are needed for updates...NTP isn't.
upvoted 2 times
...
...
...
dragossky
Most Recent 8 months, 1 week ago
Selected Answer: ABD
service route you configure it only if you want to use a Layer 3 interface, not the MGMT.
upvoted 1 times
...
scanossa
10 months, 2 weeks ago
Selected Answer: ABD
This indicates that is solely on the management interface. Therefore, it doesn't require a service route A B, and D
upvoted 3 times
...
[Removed]
11 months ago
Options ABD
upvoted 1 times
...
cjace
11 months, 2 weeks ago
IP address1: The IP address of the management interface is crucial for network communication1. DNS server1: The DNS server is needed to resolve domain names for dynamic updates and other services1. Service routes12: Service routes determine the source IP and interface used by the firewall to access external services, such as dynamic updates12.
upvoted 2 times
...
[Removed]
12 months ago
Selected Answer: BDE
I was thinking on ABD, but then I decided to test on the FW and after delete the NTP configuration I still was able to download the dynamic updates... and knowing that service routes are a "must" when using a data interface, the answer should be BDE https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/service-routes
upvoted 1 times
...
MoSayel
1 year, 1 month ago
Selected Answer: ABD
For a Palo Alto Networks firewall to perform dynamic updates and provide administrative access, it crucially needs to have NTP, an IP address, and a DNS server correctly configured. Explanation: The three management interface settings that must be configured for functional dynamic updates and administrative access on a Palo Alto Networks firewall are: NTP (Network Time Protocol): Ensures that the firewall has the correct time, which is crucial for logging, reporting, and synchronization with other devices for security functions. IP address: Necessary for the management interface to be reachable for administrative tasks and to establish communication with external servers for updates. DNS server: Required to resolve hostnames for update servers and other administrative functions, facilitating dynamic updates. While MTU (Maximum Transmission Unit) and service routes are also important settings, they are not as critical as NTP, IP address, and DNS server for the specific functions of dynamic updates and administrative access.
upvoted 3 times
...
Notimig
1 year, 1 month ago
Selected Answer: BDE
the time can be manually configured to be able to make https requests, no need for NTP
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: ABD
ABD is correct
upvoted 1 times
...
redgi0
1 year, 3 months ago
Selected Answer: ABD
ABD ! FACT : if you do not configure NTP then you cannot do HTTPS because time will be wrong. CONSEQUENCE : and thus, you will not be able to connect to remote secured update PA network update server. end of discussion.
upvoted 4 times
...
DlaEdu_Ex
1 year, 10 months ago
Selected Answer: BDE
Some management tasks, such as retrieving licenses and updating the threat and application signatures on the firewall, require access to the internet, typically via the MGT port. If you do not want to enable external access via the MGT port, you can set up an in-band data port on the data plane to provide access to the required external services by using the service routes.
upvoted 2 times
...
Enc0d3d
1 year, 11 months ago
We all agree on IP and DNS. because it's here: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network/perform-initial-configuration Having a MGT interface doesn't mean you have internet connectivity because the MGT interface could simply be connected to PC for managing. You will need to setup a service route to hardcode the path to the net.
upvoted 2 times
Enc0d3d
1 year, 11 months ago
BDE - is my answer. NTP is not required here.
upvoted 2 times
...
...
stxc
1 year, 11 months ago
Let us take a moment here. The question includes the word "must" and the question says also “management interface” i.e. management interface can be “MGT” which it is the default and it can be also a data port (if you decide to use it as a management interface. We also know that NTP is an optional (it is recommended) but it is not a must. We also know that a service route is a must if you need to use a data port as management interface. Therefore, I would go with the answer: IP Address (must) DNS Server (must) Service route (must if you use a data port as a management interface instead using the default MGT). Thanks!
upvoted 2 times
stxc
1 year, 11 months ago
I would go now with the answer ABD since the question mentions the word that says "Functional Update" so stick with NTP, IP address and DNS server.
upvoted 1 times
...
...
baccalacca
2 years, 1 month ago
ABD https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK
upvoted 5 times
mariooiram87
1 year, 6 months ago
Bro why would you share a link that does not support your answer? I'm gonna have to say RTFM...
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago