Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Paloalto Networks PSE-SoftwareFirewall Dumps

Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Questions and Answers

Question 1

What is the appropriate file format for Kubernetes applications?

Options:

A.

.yaml

B.

.exe

C.

Json

D.

.xml

Question 2

Which two design options address split brain when configuring high availability (HA)? (Choose two.)

Options:

A.

Bundling multiple interfaces in an aggregated interface group and assigning HA2

B.

Using the heartbeat backup

C.

Sending heartbeats across the HA2 interfaces

D.

Adding a backup HA1 interface

Question 3

What can software next-generation firewall (NGFW) credits be used to provision?

Options:

A.

Enablement of DNS security

B.

Virtual Panorama appliances

C.

Remote browser isolation

D.

Migrating NGFWs from hardware to VMs

Question 4

Which two public cloud platforms does the VM-Series plugin support? (Choose two.)

Options:

A.

IBM Cloud

B.

OCI

C.

Amazon Web Services (AWS)

D.

Azure

Question 5

Which two valid components are used in installation of a VM-Series firewall in an OpenStack environment? (Choose two.)

Options:

A.

VM-Series VHD image

B.

OpenStack heat template in JSON format

C.

VM-Series qcow2 image

D.

OpenStack heat template in YAML Ain’t Markup Language (YAML) format

Question 6

Which two features of CN-Series firewalls protect east-west traffic between pods in different trust zones? (Choose two.)

Options:

A.

Intrusion prevention system (IPS)

B.

Communication with Panorama

C.

External load balancer (ELB)

D.

Layer 7 visibility

Question 7

Which PAN-OS feature allows for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment?

Options:

A.

Dynamic Address Group

B.

Hypervisor integration

C.

Bootstrapping

D.

Boundary automation

Question 8

Which two methods of Zero Trust implementation can benefit an organization? (Choose two.)

Options:

A.

Boundaries are established.

B.

Security automation is seamlessly integrated.

C.

Compliance is validated.

D.

Access controls are enforced.

Question 9

What must be enabled when using Terraform templates with a Cloud next-generation firewall (NGFW) for Amazon Web Services (AWS)?

Options:

A.

Access to the Cloud NGFW for AWS console

B.

AWS Firewall Manager console access

C.

AWS CloudWatch logging

D.

Access to the Palo Alto Networks Customer Support Portal

Question 10

How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?

Options:

A.

It must be deployed as a member of a device cluster.

B.

It must be identified as a default gateway.

C.

It must receive all forwarding lookups from the network controller.

D.

It must use a Layer 3 underlay network.

Question 11

How does Prisma Cloud Compute offer workload security at runtime?

Options:

A.

It quarantines containers that demonstrate increased CPU and memory usage.

B.

It automatically patches vulnerabilities and compliance issues for every container and service.

C.

It works with the identity provider (IdP) to identify overprivileged containers and services, and it restricts network access.

D.

It automatically builds an allow-list security model for every container and service.

Question 12

Which two steps are involved in deployment of a VM-Series firewall on NSX? (Choose two.)

Options:

A.

Create a virtual data center (vDC) and a vApp that includes the VM-Series firewall.

B.

Enable communication between Panorama and the NSX Manager.

C.

Register the VM-Series firewall as a service.

D.

Obtain the Amazon Machine Images (AMIs) from marketplace.

Question 13

What do tags allow a VM-Series firewall to do in a virtual environment?

Options:

A.

Integrate with security information and event management (SIEM) solutions.

B.

Enable machine learning (ML).

C.

Provide adaptive reporting.

D.

Adapt Security policy rules dynamically.

Question 14

Which feature provides real-time analysis using machine learning (ML) to defend against new and unknown threats?

Options:

A.

Cortex Data Lake

B.

DNS Security

C.

Panorama VM-Series plugin

D.

Advanced URL Filtering (AURLF)

Question 15

Which three NSX features can be pushed from Panorama in PAN-OS? (Choose three.)

Options:

A.

Multiple authorization codes

B.

User IP mappings

C.

Steering rules

D.

Security group assignment of virtual machines (VMs)

E.

Security groups

Question 16

When implementing active-active high availability (HA), which feature must be configured to allow the HA pair to share a single IP address that may be used as the network's gateway IP address?

Options:

A.

Floating IP address

B.

VRRP

C.

ARP load sharing

D.

HSRP

Question 17

What helps avoid split brain in active-passive high availability (HA) pair deployment?

Options:

A.

Enabling preemption on both firewalls in the HA pair

B.

Using a standard traffic interface as the HA2 backup

C.

Using a standard traffic interface as the HA3 link

D.

Using the management interface as the HA1 backup link

Question 18

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

Options:

A.

Threat Prevention

B.

SD-WAN

C.

Intelligent Traffic Offload

D.

WildFire

Question 19

Which service, when enabled, provides inbound traffic protection?

Options:

A.

Data loss prevention (DLP)

B.

Advanced URL Filtering (AURLF)

C.

DNS Security

D.

Threat Prevention

Page: 1 / 7
Total 65 questions