New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks PSE-SoftwareFirewall Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Exam Practice Test

Page: 1 / 7
Total 65 questions

Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Questions and Answers

Question 1

Which service, when enabled, provides inbound traffic protection?

Options:

A.

Data loss prevention (DLP)

B.

Advanced URL Filtering (AURLF)

C.

DNS Security

D.

Threat Prevention

Question 2

Auto scaling templates for which type of firewall enable deployment of a single auto scaling group (ASG) of VM-Series firewalls to secure inbound traffic from the internet to Amazon Web Services (AWS) application workloads?

Options:

A.

HA-Series

B.

VM-Series

C.

PA-Series

D.

CN-Series

Question 3

How does Prisma Cloud Compute offer workload security at runtime?

Options:

A.

It quarantines containers that demonstrate increased CPU and memory usage.

B.

It automatically patches vulnerabilities and compliance issues for every container and service.

C.

It works with the identity provider (IdP) to identify overprivileged containers and services, and it restricts network access.

D.

It automatically builds an allow-list security model for every container and service.

Question 4

What is a design consideration for a prospect who wants to deploy VM-Series firewalls in an Amazon Web Services (AWS) environment?

Options:

A.

Resources are shared within the cluster.

B.

Only active-passive high availability (HA) is supported.

C.

High availability (HA) clusters are limited to fewer than 8 virtual appliances.

D.

Special AWS plugins are needed for load balancing.

Question 5

Which component allows the flexibility to add network resources but does not require making changes to existing policies and rules?

Options:

A.

Content-ID

B.

External dynamic list (EDL)

C.

Dynamic address group

D.

App-ID 

Question 6

Which two methods of Zero Trust implementation can benefit an organization? (Choose two.)

Options:

A.

Boundaries are established.

B.

Security automation is seamlessly integrated.

C.

Compliance is validated.

D.

Access controls are enforced.

Question 7

Why are VM-Series firewalls and hardware firewalls that are external to the Kubernetes cluster problematic for protecting containerized workloads?

Options:

A.

They function differently based on whether they are located inside or outside of the cluster.

B.

They are located outside the cluster and have no visibility into application-level cluster traffic.

C.

They are managed by another entity when located inside the cluster.

D.

They do not scale independently of the Kubernetes cluster.

Question 8

Which offering inspects encrypted outbound traffic?

Options:

A.

TLS decryption

B.

Content-ID

C.

Advanced URL Filtering (AURLF)

D.

WildFire

Question 9

Which two factors lead to improved return on investment for prospects interested in Palo Alto Networks virtualized next-generation firewalls (NGFWs)? (Choose two.)

Options:

A.

Reduced operational expenditures

B.

Decreased likelihood of data breach

C.

Reduced insurance premiums

D.

Reduced time to deploy

Question 10

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

Options:

A.

Threat Prevention

B.

SD-WAN

C.

Intelligent Traffic Offload

D.

WildFire

Question 11

What can software next-generation firewall (NGFW) credits be used to provision?

Options:

A.

Enablement of DNS security

B.

Virtual Panorama appliances

C.

Remote browser isolation

D.

Migrating NGFWs from hardware to VMs

Question 12

What are two requirements for automating service deployment of a VM-Series firewall from an NSX Manager? (Choose two.)

Options:

A.

Panorama has been configured to recognize both the NSX Manager and vCenter.

B.

vCenter has been given Palo Alto Networks subscription licenses for VM-Series firewalls.

C.

The deployed VM-Series firewall can establish communications with Panorama.

D.

Panorama can establish communications to the public Palo Alto Networks update servers.

Question 13

How are Palo Alto Networks Next-Generation Firewalls (NGFWs) deployed within a Cisco ACI architecture?

Options:

A.

Traffic can be automatically redirected using static address objects.

B.

VXLAN or NVGRE traffic is terminated and inspected for translation to VLANs.

C.

Service graphs are configured to allow their deployment.

D.

SDN code hooks can help detonate malicious file samples designed to detect virtual environments.

Question 14

Which protocol is used for communicating between VM-Series firewalls and a gateway load balancer in Amazon Web Services (AWS)?

Options:

A.

Geneve

B.

VRLAN

C.

VMLAN

D.

GRE

Question 15

Which element protects and hides an internal network in an outbound flow?

Options:

A.

DNS sinkholing

B.

NAT

C.

User-ID

D.

App-ID

Question 16

What do tags allow a VM-Series firewall to do in a virtual environment?

Options:

A.

Integrate with security information and event management (SIEM) solutions.

B.

Enable machine learning (ML).

C.

Provide adaptive reporting.

D.

Adapt Security policy rules dynamically.

Question 17

Which software firewall would help a prospect interested in securing an environment with Kubernetes?

Options:

A.

ML-Series

B.

CN-Series

C.

KN-Series

D.

VM-Series

Question 18

What is required to integrate a Palo Alto Networks VM-Series firewall with Azure Orchestration?

Options:

A.

Client-ID

B.

API Key

C.

Dynamic Address Groups

D.

Aperture orchestration engine

Question 19

Which two actions can be performed for VM-Series firewall licensing by an orchestration system? (Choose two.)

Options:

A.

Registering an authorization code

B.

Creating a license

C.

Downloading a content update

D.

Renewing a license

Page: 1 / 7
Total 65 questions