Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Paloalto Networks PCSFE Dumps

Page: 1 / 7
Total 65 questions

Palo Alto Networks Certified Software Firewall Engineer (PCSFE) Questions and Answers

Question 1

What must be enabled when using Terraform templates with a Cloud next-generation firewall (NGFW) for Amazon Web Services (AWS)?

Options:

A.

AWS CloudWatch logging

B.

Access to the Cloud NGFW for AWS console

C.

Access to the Palo Alto Networks Customer Support Portal

D.

AWS Firewall Manager console access

Question 2

Which component scans for threats in allowed traffic?

Options:

A.

Intelligent Traffic Offload

B.

TLS decryption

C.

Security profiles

D.

NAT

Question 3

With which two private cloud environments does Palo Alto Networks have deep integrations? (Choose two.)

Options:

A.

VMware NSX-T

B.

Cisco ACI

C.

Dell APEX

D.

Nutanix

Question 4

What is the appropriate file format for Kubernetes applications?

Options:

A.

.yaml

B.

.exe

C.

.json

D.

.xml

Question 5

How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?

Options:

A.

It must be deployed as a member of a device cluster

B.

It must use a Layer 3 underlay network

C.

It must receive all forwarding lookups from the network controller

D.

It must be identified as a default gateway

Question 6

Which two valid components are used in installation of a VM-Series firewall in an OpenStack environment? (Choose two.)

Options:

A.

OpenStack heat template in JSON format

B.

OpenStack heat template in YAML Ain't Markup Language (YAML) format

C.

VM-Series VHD image

D.

VM-Series qcow2 image

Question 7

When implementing active-active high availability (HA), which feature must be configured to allow the HA pair to share a single IP address that may be used as the network's gateway IP address?

Options:

A.

ARP load sharing

B.

Floating IP address

C.

HSRP

D.

VRRP

Question 8

How are CN-Series firewalls licensed?

Options:

A.

Data-plane vCPU

B.

Service-plane vCPU

C.

Management-plane vCPU

D.

Control-plane vCPU

Question 9

Which two mechanisms could trigger a high availability (HA) failover event? (Choose two.)

Options:

A.

Heartbeat polling

B.

Ping monitoring

C.

Session polling

D.

Link monitoring

Question 10

What is a benefit of network runtime security?

Options:

A.

It more narrowly focuses on one security area and requires careful customization integration and maintenance

B.

It removes vulnerabilities that have been baked into containers.

C.

It is siloed to enhance workload security.

D.

It identifies unknown vulnerabilities that cannot be identified by known Common Vulnerability and Exposure (CVE) lists.

Question 11

How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

Options:

A.

By using contracts between endpoint groups that send traffic to the firewall using a shared policy

B.

Through a virtual machine (VM) monitor domain

C.

Through a policy-based redirect

D.

By creating an access policy

Question 12

Which software firewall would assist a prospect who is interested in securing extensive DevOps deployments?

Options:

A.

CN-Series

B.

Ion-Series

C.

Cloud next-generation firewall

D.

VM-Series

Question 13

Which service, when enabled, provides inbound traffic protection?

Options:

A.

Advanced URL Filtering (AURLF)

B.

Threat Prevention

C.

Data loss prevention (DLP)

D.

DNS Security

Question 14

Which two elements of the Palo Alto Networks platform architecture enable security orchestration in a software-defined network (SDN)? (Choose two.)

Options:

A.

Full set of APIs enabling programmatic control of policy and configuration

B.

VXLAN support for network-layer abstraction

C.

Dynamic Address Groups to adapt Security policies dynamically

D.

NVGRE support for advanced VLAN integration

Question 15

Which two actions can be performed for VM-Series firewall licensing by an orchestration system? (Choose two.)

Options:

A.

Creating a license

B.

Renewing a license

C.

Registering an authorization code

D.

Downloading a content update

Question 16

Which feature provides real-time analysis using machine learning (ML) to defend against new and unknown threats?

Options:

A.

Advanced URL Filtering (AURLF)

B.

Cortex Data Lake

C.

DNS Security

D.

Panorama VM-Series plugin

Question 17

Why are containers uniquely suitable for runtime security based on allow lists?

Options:

A.

Containers have only a few defined processes that should ever be executed.

B.

Developers define the processes used in containers within the Dockerfile.

C.

Docker has a built-in runtime analysis capability to aid in allow listing.

D.

Operations teams know which processes are used within a container.

Question 18

What can software next-generation firewall (NGFW) credits be used to provision?

Options:

A.

Remote browser isolation

B.

Virtual Panorama appliances

C.

Migrating NGFWs from hardware to VMs

D.

Enablement of DNS security

Question 19

What are two requirements for automating service deployment of a VM-Series firewall from an NSX Manager? (Choose two.)

Options:

A.

vCenter has been given Palo Alto Networks subscription licenses for VM-Series firewalls.

B.

Panorama has been configured to recognize both the NSX Manager and vCenter.

C.

The deployed VM-Series firewall can establish communications with Panorama.

D.

Panorama can establish communications to the public Palo Alto Networks update servers.

Page: 1 / 7
Total 65 questions