New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks PSE-SWFW-Pro-24 Palo Alto Networks SystemsEngineer Professional - Software Firewall Exam Practice Test

Page: 1 / 6
Total 60 questions

Palo Alto Networks SystemsEngineer Professional - Software Firewall Questions and Answers

Question 1

Per reference architecture, which default PAN-OS configuration should be overridden to make VM-Series firewall deployments in the public cloud more secure?

Options:

A.

Intrazone-default rule action and logging

B.

Interzone-default rule service

C.

Interzone-default rule action and logging

D.

Intrazone-default rule service

Question 2

What are three benefits of using Palo Alto Networks software firewalls in public cloud, private cloud, and hybrid cloud environments? (Choose three.)

Options:

A.

They allow for centralized management of all firewalls, regardless of where or how they are deployed.

B.

They allow for complex management of per-use case security needs through multiple point products.

C.

They provide consistent policy enforcement across all architectures, whether on-premises or in the cloud.

D.

They allow management of underlying public cloud architecture without needing to leave the firewall itself.

E.

They create a simplified consumption and deployment model throughout the production environment.

Question 3

Which two statements accurately describe cloud-native load balancing with Palo Alto Networks VM-Series firewalls and/or Cloud NGFW in public cloud environments? (Choose two.)

Options:

A.

Cloud NGFW’s distributed architecture model requires deployment of a single centralized firewall and will force all traffic to the firewall across pre-built VPN tunnels.

B.

VM-Series firewall deployments in the public cloud will require the deployment of a cloud-native load balancer if high availability (HA) or redundancy is needed.

C.

Cloud NGFW in AWS or Azure has load balancing built into the underlying solution and does not require the deployment of a separate load balancer.

D.

VM-Series firewall load balancing is automated and is handled by the internal mechanics of the NGFW software without the need for a load balancer.

Question 4

Which three resources can help conduct planning and implementation of Palo Alto Networks NGFW solutions? (Choose three.)

Options:

A.

Technical assistance center (TAC)

B.

Partners / systems Integrators

C.

Professional services

D.

Proof of Concept Labs

E.

QuickStart services

Question 5

A company has purchased Palo Alto Networks Software NGFW credits and wants to run PAN-OS 11.x virtual machines (VMs).

Which two types of VMs can be selected when creating the deployment profile? (Choose two.)

Options:

A.

VM-100

B.

Fixed vCPU models

C.

Flexible model of working memory

D.

Flexible vCPUs

Question 6

Which statement applies when identifying the appropriate Palo Alto Networks firewall platform for virtualized as well as cloud environments?

Options:

A.

VM-Series firewalls cannot be used to protect container environments.

B.

All NGFW platforms support API integration.

C.

Panorama is the only unified management console for all NGFWs.

D.

CN-Series firewalls are used to protect virtualized environments.

Question 7

What are three components of Cloud NGFW for AWS? (Choose three.)

Options:

A.

Cloud NGFW Resource

B.

Local or Global Rulestacks

C.

Cloud NGFW Inspector

D.

Amazon S3 bucket

E.

Cloud NGFW Tenant

Question 8

Which three presales methods will help secure the technical win of software firewalls? (Choose three.)

Options:

A.

Provide link to PAYG Cloud NGFW in the Azure Marketplace

B.

Unsolicited proposals that disregard customer needs

C.

Network Security Design workshops

D.

Proof of Value (POV) product evaluations

Question 9

A company that purchased software NGFW credits from Palo Alto Networks has made a decision on the number of virtual machines (VMs) and licenses they wish to deploy in AWS cloud.

How are the VM licenses created?

Options:

A.

Access the AWS Marketplace and use the software NGFW credits to purchase the VMs.

B.

Access the Palo Alto Networks Application Hub and create a new VM profile.

C.

Access the Palo Alto Networks Customer Support Portal and request the creation of a new software NGFW serial number.

D.

Access the Palo Alto Networks Customer Support Portal and create a software NGFW credits deployment profile.

Question 10

Which two software firewall types can protect egress traffic from workloads attached to an Azure vWAN hub? (Choose two.)

Options:

A.

Cloud NGFW

B.

PA-Series

C.

CN-Series

D.

VM-Series

Question 11

Tags can be created for which three objects? (Choose three.)

Options:

A.

Address groups

B.

Dynamic NAT objects

C.

External dynamic lists

D.

Address objects

E.

Service groups

Question 12

Which two deployment models does Cloud NGFW for AWS support? (Choose two.)

Options:

A.

Hierarchical

B.

Centralized

C.

Distributed

D.

Linear

Question 13

Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)

Options:

A.

Its update requires "Commit" to enforce membership mapping.

B.

It allows creation and enforcement of consistent Security policy across multiple cloud environments.

C.

Tags cannot be defined statically on the firewall.

D.

It uses tags as filtering criteria to determine IP address mapping to a group.

E.

Its maximum number of registered IP addresses is dependent on the firewall platform.

Question 14

Which two products are deployed with Terraform for high levels of automation and integration? (Choose two.)

Options:

A.

Cloud NGFW

B.

VM-Series firewall

C.

Cortex XSOAR

D.

Prisma Access

Question 15

Which three tools or methods automate VM-Series firewall deployment? (Choose three.)

Options:

A.

Panorama Software Firewall License plugin

B.

Palo Alto Networks GitHub repository

C.

Bootstrap the VM-Series firewall

D.

Shared Disk Software Library folder

E.

Panorama Software Library image

Question 16

A Cloud NGFW for Azure can be deployed to which two environments? (Choose two.)

Options:

A.

Azure Kubernetes Service (AKS)

B.

Azure Virtual WAN

C.

Azure DevOps

D.

Azure VNET

Question 17

Which three features are supported by CN-Series firewalls? (Choose three.)

Options:

A.

App-ID

B.

Decryption

C.

GlobalProtect

D.

Content-ID

E.

IPSec

Question 18

Which three capabilities and characteristics are shared by the deployments of Cloud NGFW for Azure and VM-Series firewalls? (Choose three.)

Options:

A.

Panorama management

B.

Inter-VNet inspection through Virtual WAN hub

C.

Transparent inspection of private-to-private east-west traffic that preserves client source IP address

D.

Inter-VNet inspection through a transit VNet

E.

Use of routing intent policies to apply security policies

Page: 1 / 6
Total 60 questions