Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Paloalto Networks PSE-SWFW-Pro-24 Dumps

Palo Alto Networks SystemsEngineer Professional - Software Firewall Questions and Answers

Question 1

Which three resources are deployment options for Cloud NGFW for Azure or AWS? (Choose three.)

Options:

A.

Azure CLI or Azure Terraform Provider

B.

Azure Portal

C.

AWS Firewall Manager

D.

Panorama AWS and Azure plugins

E.

Palo Alto Networks Ansible playbooks

Question 2

Which three statements describe common characteristics of Cloud NGFW and VM-Seriesofferings? (Choose three.)

Options:

A.

In Azure, both offerings can be integrated directly into Virtual WAN hubs.

B.

In Azure and AWS, both offerings can be managed by Panorama.

C.

In AWS, both offerings can be managed by AWS Firewall Manager.

D.

In Azure, inbound destination NAT configuration also requires source NAT to maintain flow symmetry.

E.

In Azure and AWS, internal (east-west) flows can be inspected without any NAT.

Question 3

Which statement correctly describes behavior when using Ansible to automate configuration changes on a PAN-OS firewall or in Panorama?

Options:

A.

Ansible can only be used to automate configuration changes on physical firewalls but not virtual firewalls.

B.

Ansible requires direct access to the firewall’s CLI to make changes.

C.

Ansible uses the XML API to make configuration changes to PAN-OS.

D.

Ansible requires the use of Python to create playbooks.

Question 4

Which three tools or methods automate VM-Series firewall deployment? (Choose three.)

Options:

A.

Panorama Software Firewall License plugin

B.

Palo Alto Networks GitHub repository

C.

Bootstrap the VM-Series firewall

D.

Shared Disk Software Library folder

E.

Panorama Software Library image

Question 5

Which element protects and hides an internal network in an outbound flow?

Options:

A.

DNS sinkholing

B.

User-ID

C.

App-ID

D.

NAT

Question 6

Which two statements accurately describe cloud-native load balancing with Palo Alto Networks VM-Series firewalls and/or Cloud NGFW in public cloud environments? (Choose two.)

Options:

A.

Cloud NGFW’s distributed architecture model requires deployment of a single centralized firewall and will force all traffic to the firewall across pre-built VPN tunnels.

B.

VM-Series firewall deployments in the public cloud will require the deployment of a cloud-native load balancer if high availability (HA) or redundancy is needed.

C.

Cloud NGFW in AWS or Azure has load balancing built into the underlying solution and does not require the deployment of a separate load balancer.

D.

VM-Series firewall load balancing is automated and is handled by the internal mechanics of the NGFW software without the need for a load balancer.

Question 7

When using VM-Series firewall bootstrapping, which three methods can be used to install licensed content, including antivirus, applications, and threats? (Choose three.)

Options:

A.

Panorama 10.2 or later to use the content auto push feature

B.

Complete bootstrapping and either Azure Blob storage or Amazon S3 bucket

C.

Content-Security-Policy update URL in the init-cfg.txt file

D.

Custom-AMI or Azure VM image, with content preloaded

E.

Panorama software licensing plugin

Question 8

Which three statements describe functionality of NGFW inline placement for Layer 2/3 implementation? (Choose three.)

Options:

A.

VMs on VMware ESXi hypervisors can be segregated from one another on the network by the VM-Series NGFW by IP addressing and Layer 3 gateways.

B.

VMs on VMware ESXi hypervisors can be segregated from each other by the VM-Series NGFW using VLAN tags while preserving existing Layer 3 gateways.

C.

VM-Series next-generation firewalls cannot be positioned between the physical datacenter network and guest VM workloads.

D.

VM-Series next-generation firewalls do not support VMware vMotion or guest VM workloads.

E.

A next-generation firewall VLAN interface can function as a Layer 3 interface.

Question 9

What are three benefits of using Palo Alto Networks software firewalls in public cloud, private cloud, and hybrid cloud environments? (Choose three.)

Options:

A.

They allow for centralized management of all firewalls, regardless of where or how they are deployed.

B.

They allow for complex management of per-use case security needs through multiple point products.

C.

They provide consistent policy enforcement across all architectures, whether on-premises or in the cloud.

D.

They allow management of underlying public cloud architecture without needing to leave the firewall itself.

E.

They create a simplified consumption and deployment model throughout the production environment.

Question 10

A partner has successfully showcased and validated the efficacy of the Palo Alto Networks software firewall to a customer.

Which two additional partner-delivered or Palo Alto Networks-delivered common options can the sales team offer to the customer before the sale is completed? (Choose two.)

Options:

A.

Hardware collection and recycling services by Palo Alto Networks or by an approved NextWave Partner for the customer’s existing firewall infrastructure

B.

Professional services delivered by Palo Alto Networks or by an approved Certified Professional Services Partner (CPSP) for deployment assistance or QuickStart

C.

Network encryption services (NES) delivered by an approved NES partner to ensure none of the data traversed is readable by third-party entities

D.

Managed services delivered by an approved Managed Security Services Program (MSSP) partner for day-to-day management of the environment

Question 11

Which three solutions does Strata Cloud Manager (SCM) support? (Choose three.)

Options:

A.

Prisma Cloud

B.

CN-Series firewalls

C.

Prisma Access

D.

PA-Series firewalls

E.

VM-Series firewalls

Question 12

Which three statements describe restrictions or characteristics of Firewall flex credit profiles of a credit pool in the Palo Alto Networks customer support portal? (Choose three.)

Options:

A.

The number of licensed cores must match the number of provisioned CPU cores per instance.

B.

Allocate credits for use with Cloud NGFW for AWS and Azure.

C.

Each VM-Series firewall deployment profile is either fixed or flexible.

D.

All firewalls activated to a deployment profile will have the same Cloud-Delivered Security Services (CDSS).

E.

Each deployment profile is either CN-Series firewall or VM-Series firewall.

Question 13

Per reference architecture, which default PAN-OS configuration should be overridden to make VM-Series firewall deployments in the public cloud more secure?

Options:

A.

Intrazone-default rule action and logging

B.

Interzone-default rule service

C.

Interzone-default rule action and logging

D.

Intrazone-default rule service

Question 14

What are two benefits of credit-based flexible licensing for software firewalls? (Choose two.)

Options:

A.

Create virtual Panoramas.

B.

Add Cloud-Delivered Security Services (CDSS) subscriptions to CN-Series firewalls.

C.

Create Cloud NGFWs.

D.

Add Cloud-Delivered Security Services (CDSS) subscriptions to PA-Series firewalls.

Question 15

A company has purchased Palo Alto Networks Software NGFW credits and wants to run PAN-OS 11.x virtual machines (VMs).

Which two types of VMs can be selected when creating the deployment profile? (Choose two.)

Options:

A.

VM-100

B.

Fixed vCPU models

C.

Flexible model of working memory

D.

Flexible vCPUs

Question 16

CN-Series firewalls offer threat protection for which three use cases? (Choose three.)

Options:

A.

Prevention of sensitive data exfiltration from Kubernetes environments

B.

All Kubernetes workloads in the public and private cloud

C.

Inbound, outbound, and east-west traffic between containers

D.

All workloads deployed on-premises or in the public cloud

E.

Enforcement of segmentation policies that prevent lateral movement of threats

Question 17

What are two methods or tools to directly automate the deployment of VM-Series NGFWs into supported public clouds? (Choose two.)

Options:

A.

GitHub PaloAltoNetworks Terraform SWFW modules

B.

Deployment configuration in the public cloud Panorama plugins

C.

paloaltonetworks.panos Ansible collection

D.

panos Terraform provider

Question 18

What can a firewall use to automatically update Security policies with new IP address information for a virtual machine (VM) when it has moved from host-A to host-B because host-A is down or undergoing periodic maintenance?

Options:

A.

Dynamic Address Groups

B.

Dynamic User Groups

C.

Dynamic Host Groups

D.

Dynamic IP Groups

Page: 1 / 6
Total 60 questions