New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks PSE-SWFW-Pro-24 Palo Alto Networks SystemsEngineer Professional - Software Firewall Exam Practice Test

Demo: 18 questions
Total 60 questions

Palo Alto Networks SystemsEngineer Professional - Software Firewall Questions and Answers

Question 1

Tags can be created for which three objects? (Choose three.)

Options:

A.

Address groups

B.

Dynamic NAT objects

C.

External dynamic lists

D.

Address objects

E.

Service groups

Question 2

Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)

Options:

A.

Its update requires "Commit" to enforce membership mapping.

B.

It allows creation and enforcement of consistent Security policy across multiple cloud environments.

C.

Tags cannot be defined statically on the firewall.

D.

It uses tags as filtering criteria to determine IP address mapping to a group.

E.

Its maximum number of registered IP addresses is dependent on the firewall platform.

Question 3

Which three statements describe the functionality of Dynamic Address Groups and tags? (Choose three.)

Options:

A.

Static tags are part of the configuration on the firewall, while dynamic tags are part of the runtime configuration.

B.

Dynamic Address Groups that are referenced in Security policies must be committed on the firewall.

C.

To dynamically register tags, use either the XML API or the VM Monitoring agent on the firewall or on the User-ID agent.

D.

IP-Tag registrations to Dynamic Address Groups must be committed on the firewall after each change.

E.

Dynamic Address Groups use tags as filtering criteria to determine their members, and filters do not use logical operators.

Question 4

What are three valid methods that use firewall flex credits to activate VM-Series firewall licenses by specifying authcode? (Choose three.)

Options:

A.

/config/bootstrap.xml file of complete bootstrapping package

B.

/license/authcodes file of complete bootstrap package

C.

Panorama device group in Panorama SW Licensing Plugin

D.

authcodes= key value pair of Azure Vault configuration

E.

authcodes= key value pair of basic bootstrapping configuration

Question 5

Which three statements describe common characteristics of Cloud NGFW and VM-Seriesofferings? (Choose three.)

Options:

A.

In Azure, both offerings can be integrated directly into Virtual WAN hubs.

B.

In Azure and AWS, both offerings can be managed by Panorama.

C.

In AWS, both offerings can be managed by AWS Firewall Manager.

D.

In Azure, inbound destination NAT configuration also requires source NAT to maintain flow symmetry.

E.

In Azure and AWS, internal (east-west) flows can be inspected without any NAT.

Question 6

Which three resources are deployment options for Cloud NGFW for Azure or AWS? (Choose three.)

Options:

A.

Azure CLI or Azure Terraform Provider

B.

Azure Portal

C.

AWS Firewall Manager

D.

Panorama AWS and Azure plugins

E.

Palo Alto Networks Ansible playbooks

Question 7

Which two products are deployed with Terraform for high levels of automation and integration? (Choose two.)

Options:

A.

Cloud NGFW

B.

VM-Series firewall

C.

Cortex XSOAR

D.

Prisma Access

Question 8

Which use case is valid for Strata Cloud Manager (SCM)?

Options:

A.

Provisioning and licensing new CN-Series firewall deployments

B.

Providing AI-Powered ADEM for all Prisma Access users

C.

Supporting pre PAN-OS 10.1 SD-WAN migrations to SCM

D.

Providing API-driven plugin framework for integration with third-party ecosystems

Question 9

Which three statements describe benefits of Palo Alto Networks Cloud-Delivered Security Services (CDSS) over other vendor solutions? (Choose three.)

Options:

A.

Individually targeted products provide better security than platform solutions.

B.

Multi-vendor best-of-breed products provide security coverage on a per-use-case basis.

C.

It requires no additional performance overhead when enabling additional features.

D.

It provides simplified management through fewer consoles for more effective security coverage.

E.

It significantly reduces the total cost of ownership for the customer.

Question 10

Which public cloud provider requires the creation of subnets that are dedicated to Cloud NGFW endpoints?

Options:

A.

Google Cloud Platform (GCP)

B.

Alibaba Cloud

C.

Amazon Web Services (AWS)

D.

 Microsoft Azure

Question 11

What are three benefits of using Palo Alto Networks software firewalls in public cloud, private cloud, and hybrid cloud environments? (Choose three.)

Options:

A.

They allow for centralized management of all firewalls, regardless of where or how they are deployed.

B.

They allow for complex management of per-use case security needs through multiple point products.

C.

They provide consistent policy enforcement across all architectures, whether on-premises or in the cloud.

D.

They allow management of underlying public cloud architecture without needing to leave the firewall itself.

E.

They create a simplified consumption and deployment model throughout the production environment.

Question 12

Which element protects and hides an internal network in an outbound flow?

Options:

A.

DNS sinkholing

B.

User-ID

C.

App-ID

D.

NAT

Question 13

Which two public cloud service provider (CSP) environments offer, through their marketplace, a Cloud NGFW under the CSP's own brand name? (Choose two.)

Options:

A.

Oracle Cloud Infrastructure (OCI)

B.

IBM Cloud (previously Softlayer)

C.

Alibaba Cloud

D.

Google Cloud Platform (GCP)

Question 14

Which three tools or methods automate VM-Series firewall deployment? (Choose three.)

Options:

A.

Panorama Software Firewall License plugin

B.

Palo Alto Networks GitHub repository

C.

Bootstrap the VM-Series firewall

D.

Shared Disk Software Library folder

E.

Panorama Software Library image

Question 15

A systems engineer (SE) is informed by the primary contact at a bank of an unused balance of 15,000 software NGFW flexible credits the bank does not want to lose when they expire in 1.5 years. The SE is told that the bank's new risk and compliance officer is concerned that its operation is too permissive when allowing its servers to send traffic to SaaS vendors. Currently, its AWS and Azure VM-Series firewalls only use Advanced Threat Prevention.

What should the SE recommend to address the customer's concerns?

Options:

A.

Activate Advanced WildFire within the software NGFW deployment profiles, starting with the largest vCPU models and working down to the smallest to protect their biggest workloads.

B.

Subscribe to DNS Security, Advanced URL Filtering, and Advanced WildFire across all software NGFW deployment profiles until all the credits are used.

C.

Verify conformance to standards and regulations, the risk of failure, and the criticality of each workload to be protected, then determine which deployment profile subscriptions address the needs.

D.

Activate Advanced WildFire within the software NGFW deployment profiles, starting with the smallest vCPU models and working up to the largest to provide coverage for more VPCs and VNets with their current credit balance.

Question 16

What is the primary purpose of the pan-os-python SDK?

Options:

A.

To create a Python-based firewall that is compatible with the latest PAN-OS

B.

To replace the PAN-OS web interface with a Python-based interface

C.

To automate the deployment of PAN-OS firewalls by using Python

D.

To provide a Python interface to interact with PAN-OS firewalls and Panorama

Question 17

Which three resources can help conduct planning and implementation of Palo Alto Networks NGFW solutions? (Choose three.)

Options:

A.

Technical assistance center (TAC)

B.

Partners / systems Integrators

C.

Professional services

D.

Proof of Concept Labs

E.

QuickStart services

Question 18

Which two statements accurately describe cloud-native load balancing with Palo Alto Networks VM-Series firewalls and/or Cloud NGFW in public cloud environments? (Choose two.)

Options:

A.

Cloud NGFW’s distributed architecture model requires deployment of a single centralized firewall and will force all traffic to the firewall across pre-built VPN tunnels.

B.

VM-Series firewall deployments in the public cloud will require the deployment of a cloud-native load balancer if high availability (HA) or redundancy is needed.

C.

Cloud NGFW in AWS or Azure has load balancing built into the underlying solution and does not require the deployment of a separate load balancer.

D.

VM-Series firewall load balancing is automated and is handled by the internal mechanics of the NGFW software without the need for a load balancer.

Demo: 18 questions
Total 60 questions