Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks PSE-SoftwareFirewall Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Exam Practice Test

Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Questions and Answers

Question 1

Which of the following can provide application-level security for a web-server instance on Amazon Web Services (AWS)?

Options:

A.

VM-Series firewalls

B.

Hardware firewalls

C.

Terraform templates

D.

Security groups

Question 2

Which feature provides real-time analysis using machine learning (ML) to defend against new and unknown threats?

Options:

A.

Cortex Data Lake

B.

DNS Security

C.

Panorama VM-Series plugin

D.

Advanced URL Filtering (AURLF)

Question 3

What is required to integrate a Palo Alto Networks VM-Series firewall with Azure Orchestration?

Options:

A.

Client-ID

B.

API Key

C.

Dynamic Address Groups

D.

Aperture orchestration engine

Question 4

What is the appropriate file format for Kubernetes applications?

Options:

A.

.yaml

B.

.exe

C.

Json

D.

.xml

Question 5

What is a design consideration for a prospect who wants to deploy VM-Series firewalls in an Amazon Web Services (AWS) environment?

Options:

A.

Resources are shared within the cluster.

B.

Only active-passive high availability (HA) is supported.

C.

High availability (HA) clusters are limited to fewer than 8 virtual appliances.

D.

Special AWS plugins are needed for load balancing.

Question 6

What are two environments supported by the CN-Series firewall? (Choose two.)

Options:

A.

OpenShift

B.

Positive K

C.

Native K8

D.

OpenStack

Question 7

Which two steps are involved in deployment of a VM-Series firewall on NSX? (Choose two.)

Options:

A.

Create a virtual data center (vDC) and a vApp that includes the VM-Series firewall.

B.

Enable communication between Panorama and the NSX Manager.

C.

Register the VM-Series firewall as a service.

D.

Obtain the Amazon Machine Images (AMIs) from marketplace.

Question 8

Which software firewall would help a prospect interested in securing an environment with Kubernetes?

Options:

A.

ML-Series

B.

CN-Series

C.

KN-Series

D.

VM-Series

Question 9

What do tags allow a VM-Series firewall to do in a virtual environment?

Options:

A.

Integrate with security information and event management (SIEM) solutions.

B.

Enable machine learning (ML).

C.

Provide adaptive reporting.

D.

Adapt Security policy rules dynamically.

Question 10

Which offering inspects encrypted outbound traffic?

Options:

A.

TLS decryption

B.

Content-ID

C.

Advanced URL Filtering (AURLF)

D.

WildFire

Question 11

Which two valid components are used in installation of a VM-Series firewall in an OpenStack environment? (Choose two.)

Options:

A.

VM-Series VHD image

B.

OpenStack heat template in JSON format

C.

VM-Series qcow2 image

D.

OpenStack heat template in YAML Ain’t Markup Language (YAML) format

Question 12

What helps avoid split brain in active-passive high availability (HA) pair deployment?

Options:

A.

Enabling preemption on both firewalls in the HA pair

B.

Using a standard traffic interface as the HA2 backup

C.

Using a standard traffic interface as the HA3 link

D.

Using the management interface as the HA1 backup link

Question 13

Why are containers uniquely suitable for runtime security based on allow lists?

Options:

A.

Containers have only a few defined processes that should ever be executed.

B.

Docker has a built-in runtime analysis capability to aid in allow listing.

C.

Operations teams know which processes are used within a container.

D.

Developers define the processes used in containers within the Dockerfile.

Question 14

Where do CN-Series devices obtain a VM-Series authorization key?

Options:

A.

Panorama

B.

Local installation

C.

GitHub

D.

Customer Support Portal

Question 15

A CN-Series firewall can secure traffic between which elements?

Options:

A.

Host containers

B.

Containers

C.

Pods

D.

Source applications

Question 16

What is a design consideration for a prospect who wants to deploy VM-Series firewalls in an Amazon Web Services (AWS) environment?

Options:

A.

Resources are shared within the cluster.

B.

Only active-passive high availability (HA) is supported.

C.

High availability (HA) clusters are limited to fewer than 8 virtual appliances.

D.

Special AWS plugins are needed for load balancing.

Question 17

Which component scans for threats in allowed traffic?

Options:

A.

Security profiles

B.

NAT

C.

Intelligent Traffic Offload

D.

TLS decryption

Question 18

What can be implemented in a CN-Series to protect communications between Dockers?

Options:

A.

Data loss prevention (DLP)

B.

Firewalling

C.

Runtime security

D.

Vulnerability management

Question 19

How does a CN-Series firewall prevent exfiltration?

Options:

A.

It distributes incoming virtual private cloud (VPC) traffic across the pool of VM-Series firewalls.

B.

It inspects outbound traffic content and blocks suspicious activity.

C.

It provides a license deactivation API key.

D.

It employs custom-built signatures based on hash.