
Jan 20, 2022 Step by Step Guide to Prepare for PSE-Strata Exam BrainDumps
Palo Alto Networks Systems Engineer PSE-Strata Real Exam Questions and Answers FREE Updated on 2022
NEW QUESTION 45
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to secure data center traffic? (Choose two.)
- A. It can provide the Automated Correlation Engine functionality, which the virtual firewalls do not support.
- B. It can monitor the virtual firewalls' physical hosts and Vmotion them as necessary
- C. It can automatically create address groups for use with KVM.
- D. It can bootstrap the virtual firewalls for dynamic deployment scenarios.
Answer: A,D
NEW QUESTION 46
XYZ Corporation has a legacy environment with asymmetric routing. The customer understands that Palo Alto Networks firewalls can support asymmetric routing with redundancy. Which two features must be enabled to meet the customer's requirements? (Choose two.)
- A. Virtual systems
- B. HA active/active
- C. HA active/passive
- D. Policy-based forwarding
Answer: B,D
Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability/route-based-redundancy
NEW QUESTION 47
What is the basis for purchasing Cortex XDR licensing?
- A. volume of logs being processed based on Datalake purchased
- B. number of nodes and endpoints providing logs
- C. number of NGFWs
- D. unlimited licenses
Answer: B
NEW QUESTION 48
Which two components must be configured within User-ID on a new firewall that has been implemented? (Choose two.)
- A. Group Mapping
- B. Proxy Authentication
- C. 802.1X Authentication
- D. User Mapping
Answer: A,D
NEW QUESTION 49
What are three sources of malware sample data for the Threat Intelligence Cloud? (Choose three)
- A. Palo Alto Networks non-firewall products such as Traps and Prisma SaaS
- B. Third-party data feeds such as partnership with ProofPomt and the Cyber Threat Alliance
- C. Next-generation firewalls deployed with WildFire Analysis Security Profiles
- D. WF-500 configured as private clouds for privacy concerns
- E. Correlation Objects generated by AutoFocus
Answer: A,B,E
NEW QUESTION 50
A customer is seeing an increase in the number of malicious files coming in from undetectable sources in their network. These files include doc and .pdf file types.
The customer uses a firewall with User-ID enabled
Which feature must also be enabled to prevent these attacks?
- A. WildFire
- B. App-ID
- C. Content Filtering
- D. Custom App-ID rules
Answer: A
NEW QUESTION 51
The firewall includes predefined reports, custom reports can be built for specific data and actionable tasks, or predefined and custom reports can be combined to compile information needed to monitor network security.
The firewall provides which three types of reports? (Choose three.)
- A. PDF Summary Reports
- B. Netflow Reports
- C. Botnet Reports
- D. SNMP Reports
- E. User or Group Activity Reports
Answer: B,C,E
NEW QUESTION 52
Which two types of security chains are supported by the Decryption Broker? (Choose two.)
- A. Layer 3
- B. virtual wire
- C. transparent bridge
- D. Layer 2
Answer: A,C
Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-broker/decryption-broker-concepts/decryption-broker-security-chains-multiple.html
NEW QUESTION 53
Which two tabs in Panorama can be used to identify templates to define a common base configuration? (Choose two.)
- A. Objects Tab
- B. Device Tab
- C. Policies Tab
- D. Network Tab
Answer: B,D
NEW QUESTION 54
A customer requests that a known spyware threat signature be triggered based on a rate of occurrence, for example, 10 hits in 5 seconds.
How is this goal accomplished?
- A. Submit a request to Palo Alto Networks to change the behavior at the next update
- B. Add a correlation object that tracks the occurrences and triggers above the desired threshold
- C. Create a custom spyware signature matching the known signature with the time attribute
- D. Configure the Anti-Spyware profile with the number of rule counts to match the occurrence frequency
Answer: C
NEW QUESTION 55
Which two tabs in Panorama can be used to identify templates to define a common base configuration? (Choose two.)
- A. Objects Tab
- B. Device Tab
- C. Policies Tab
- D. Network Tab
Answer: B,D
Explanation:
https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/panorama-web-interface/panorama-templates/template-stacks
NEW QUESTION 56
Which selection must be configured on PAN-OS External Dynamic Lists to support MineMeld indicators?
- A. Feed Base URL
- B. Inputs
- C. Prototype
- D. Class
Answer: A
NEW QUESTION 57
In an HA pair running Active/Passive mode, over which interface do the dataplanes communicate?
- A. HA1
- B. HA3
- C. HA2
- D. HA4
Answer: C
NEW QUESTION 58
A customer is concerned about zero-day targeted attacks against its intellectual property.
Which solution informs a customer whether an attack is specifically targeted at them?
- A. Panorama Correlation Report
- B. Firewall Botnet Report
- C. Traps TMS
- D. AutoFocus
Answer: B
NEW QUESTION 59
What action would address the sub-optimal traffic path shown in the figure?
Key:
RN - Remote Network
SC - Service Connection
MU GW - Mobile User Gateway
- A. Onboard a Service Connection in the Americas region
- B. Onboard a Remote Network location in the EMEA region
- C. Remove the Service Connection in the EMEA region
- D. Onboard a Service Connection in the APAC region
Answer: D
NEW QUESTION 60
What are two advantages of the DNS Sinkholing feature? (Choose two.)
- A. It can work upstream from the internal DNS server.
- B. It can be deployed independently of an Anti-Spyware Profile.
- C. It monitors DNS requests passively for malware domains.
- D. It forges DNS replies to known malicious domains.
Answer: A,D
Explanation:
Explanation
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/threat-prevention/dns-sinkholing
NEW QUESTION 61
A price-sensitive customer wants to prevent attacks on a Windows Virtual Server. The server will max out at
100Mbps but needs to have 45.000 sessions to connect to multiple hosts within a data center Which VM instance should be used to secure the network by this customer?
- A. VM-100
- B. VM-300
- C. VM-200
- D. VM-50
Answer: D
NEW QUESTION 62
When log sizing is factored for the Cortex Data Lake on the NGFW, what is the average log size used in calculation?
- A. depends on the Cortex Data Lake tier purchased
- B. 1500 bytes
- C. 8MB
- D. 18 bytes
Answer: B
Explanation:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVMCA0
NEW QUESTION 63
What are two core values of the Palo Alto Network Security Operating Platform? (Choose two.}
- A. safe enablement of all applications
- B. defense against threats with static security solution
- C. prevention of cyber attacks
- D. threat remediation
Answer: C,D
NEW QUESTION 64
Which two steps are required to configure the Decryption Broker? (Choose two.)
- A. activate the Decryption Broker license
- B. reboot the firewall to activate the license
- C. enable a pair of virtual wire interfaces to forward decrypted traffic
- D. enable SSL Forward Proxy decryption
Answer: A,C
NEW QUESTION 65
Which selection must be configured on PAN-OS External Dynamic Lists to support MineMeld indicators?
- A. Feed Base URL
- B. Inputs
- C. Prototype
- D. Class
Answer: A
Explanation:
https://live.paloaltonetworks.com/t5/minemeld-articles/connecting-pan-os-to-minemeld-using-external-dynamic-lists/ta-p/190414
NEW QUESTION 66
How often are the databases for Anti-virus. Application, Threats, and WildFire subscription updated?
- A. Anti-virus (weekly): Application (daily). Threats (weekly), WildFire (5 minutes)
- B. Anti-virus (daily), Application (weekly), Threats (weekly), WildFire (5 minutes)
- C. Anti-virus (weekly), Application (daily), Threats (daily), WildFire (5 minutes)
- D. Anti-virus (daily), Application (weekly), Threats (daily), WildFire (5 minutes)
Answer: B
NEW QUESTION 67
Which three considerations should be made prior to installing a decryption policy on the NGFW? (Choose three.)
- A. Deploy decryption setting all at one time
- B. Inability to access websites
- C. Exclude certain types of traffic in decryption policy
- D. Ensure throughput is not an issue
- E. Include all traffic types in decryption policy
Answer: B,C,E
NEW QUESTION 68
Which three methods used to map users to IP addresses are supported in Palo Alto Networks firewalls? (Choose three.)
- A. TACACS
- B. SNMP server
- C. Client Probing
- D. eDirectory monitoring
- E. Active Directory monitoring
- F. RADIUS
- G. Lotus Domino
Answer: A,C,F
Explanation:
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/user-id-concepts/user-mapping
NEW QUESTION 69
......
Ultimate Guide to Prepare PSE-Strata Certification Exam for Palo Alto Networks Systems Engineer: https://www.getvalidtest.com/PSE-Strata-exam.html
PSE-Strata Ultimate Study Guide: https://drive.google.com/open?id=1OWOoZduppPbnKVapLqaaZHonRJTgDlzL