PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 1 of 7.
- Question #1Platform Implementation and Migration
What are the three benefits of the Palo Alto Networks migration tool? (Choose three.)
migration toolfirewall policy conversionNGFW migrationPOC to production - Question #2Threat Prevention
Palo Alto Networks publishes updated Command and Control signatures. How frequently should the related signatures schedule be set?
C&C signaturesdynamic updatesthreat preventionupdate schedule - Question #3Platform Architecture and Hardware Sizing
A service provider has acquired a pair of PA-7080s for its data center to secure its customer base's traffic. The server provider's traffic is largely generated by smart phones and...
PA-7080NPC selectionconcurrent sessionshardware sizing - Question #4Threat Prevention and Endpoint Security
A customer is worried about unknown attacks, but due to privacy and regulatory issues, won't implement SSL decrypt. How can the platform still address this customer's concern?
unknown attacksSSL decryptionTrapsendpoint protection - Question #5Security Policy Management
Where are three tuning considerations when building a security policy to protect against modern day attacks? (Choose three)
security policy tuningSSL decryptionWildFire profilevulnerability protection - Question #7Monitoring and Reporting
Which three network events are highlighted through correlation objects as a potential security risks? (Choose three.)
correlation objectsC&C activitysuspicious trafficthreat detection - Question #8Cloud and SaaS Security
A customer is adopting Microsoft Office 365 but is concerned about the potential security exposure that such a move could mean. The security analyst suggests using Aperture and the...
ApertureSaaS securityOffice 365data in transit - Question #9Platform Licensing and Subscriptions
Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?
licensingThreat Preventioncorrelation objectsPanorama - Question #10Threat Prevention
What two advantages of the DNS Sinkholing feature? (Choose two)
DNS sinkholingmalicious domainsanti-spywareDNS security - Question #11Remote Access and Policy Enforcement
Which Palo Alto Networks security platform component should an administrator use to extend policies to remote users are not connecting to the internet from behind a firewall?
remote usersDynamic Address Groupspolicy enforcementAutoFocus - Question #13Threat Intelligence and AutoFocus
How do Highly Suspicious artifacts in-AutoFocus help identify when an unknown, potential zero-day, targeted attack occur to allow one to adjust the security posture?
AutoFocushighly suspicious artifactszero-daythreat intelligence - Question #14Threat Prevention
DNS sinkholing helps identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the fi...
DNS sinkholinginfected host identificationtraffic logsDNS security - Question #15Threat Prevention and Platform Integration
A customer is targeted by a true zero-day, targeted attack. However, the customer is protected by the Palo Alto Networks security platform. The attack leverages a previously unknow...
zero-day attackWildFireunknown malwareplatform defense-in-depth - Question #16Monitoring and Reporting
An SE is preparing an SLR report for a school and wants to emphasize URL filtering capabilities because the school is concerned that its students are accessing inappropriate websit...
SLR reportURL filteringsecurity lifecycle reviewreporting - Question #18Endpoint Security
A customer is concerned about malicious activity occurring directly on their endpoints and not visible to their firewalls. Which three actions does Traps execute during a security...
Trapsendpoint forensicsESMsecurity event response - Question #19High Availability and Hardware
What is the HA limitation specific to the PA-200 appliance?
PA-200high availabilitysession synchronizationHA limitations - Question #20PAN-OS Features
How many recursion levels are supported for compressed files in PAN-OS 8.0?
PAN-OS 8.0compressed filesrecursion levelsfile analysis - Question #21Threat Prevention
A customer is seeing an increase in the number of malicious files coming in from undetectable sources in their network. These files include doc and .pdf file types. The customer be...
WildFiremalicious filesemail attachmentsfile-based threats - Question #22User-ID and Authentication
Which two components must to be configured within User-ID on a new firewall that has been implemented? (Choose two.)
User-IDgroup mappinguser mappingidentity configuration - Question #23Monitoring and Reporting
When a customer creates a new SLR report, what is the first step in generating a proper SLR report once logged in to the Partner Portal?
SLR reportPartner Portalsecurity lifecycle reviewreporting process - Question #24Threat Prevention
Which three items contain information about Command and Control (C&C) hosts? (Choose three.)
Command and ControlBotnet reportsWildFire analysisthreat logs - Question #25Panorama Administration
Which option is required to activate/retrieve a Device Management License on the M.100 Appliance after the Auth Codes have been activated on the Palo Alto Networks Support Site?
PanoramaM-100 applianceDevice Management Licenselicense activation - Question #26User-ID Deployment
What are three considerations when deploying User-ID. (Choose three.)
User-IDWMI probingzone configurationservice account - Question #27Platform Architecture
A price sensitive customer wants to prevent attacks on a windows 2008 Virtual Server. The server will max out at 100Mbps but needs to have 45,000 sessions to connect to multiple ho...
VM-Series sizingsession capacitythroughputVM-50 - Question #28WildFire
Which variable is used to regulate the rate of file submission to WildFire?
WildFirefile submissionrate limitingsubmission quota - Question #29Security Platform Architecture
Which four steps of the cyberattack lifecycle dose the Palo Alto Networks platform present? (Choose four)
cyberattack lifecyclekill chainlateral movementdata exfiltration - Question #30Decryption
Which certificate can be used to ensure that traffic coming from a specific server remains encrypted?
SSL decryptionSSL exclude certificatecertificate managementtraffic encryption - Question #31URL Filtering
A client chooses to not block uncategorized websites. Which two additions should be made to help provide some protection? (Choose two.)
URL filteringuncategorized websitescontinue actionfile blocking - Question #32Threat Prevention
Which configuration creates the most comprehensive "best-practice" Anti Spyware profile to prevent command and Control traffic?
Anti-SpywareDNS SinkholingPassive DNS MonitoringC&C prevention - Question #33User-ID Deployment
Given the following network diagram, an administrator is considering the use of Windows Log Forwarding and Global Catalog servers for User-ID implementation. What are two potential...
User-IDWindows Log ForwardingGlobal CatalogDomain Controllers - Question #34Security Policy
What is a best practice when configuring a security policy to completely block a specific application?
security policyApp-IDservice configurationapplication blocking - Question #35Content Updates
What is the recommended way to ensure that firewalls have the most current set of signatures for up-to-date protection?
dynamic updatessignature updatesupdate schedulecontent management - Question #36High Availability
XYZ Corporation has a legacy environment with asymmetric routing. The customer understands that Palo Alto Networks firewalls can support asymmetric routing with redundancy. Which t...
asymmetric routingHA active/activepolicy-based forwardinghigh availability - Question #37Threat Prevention
Which four actions can be configured in an Anti-Spyware profile to address command-and- control traffic from compromised hosts? (Choose four.)
Anti-SpywareC&C trafficsecurity profile actionsthreat response - Question #38Content Updates
How often are regularly scheduled update for the Anti-virus Application, Threats, and Wildfire subscription databases made available by Palo Alto Networks in PAN-OS 8.0?
content update scheduleWildFire updatesAnti-VirusPAN-OS 8.0 - Question #39Threat Prevention
Which three signature-based Threat Prevention features of the firewall are informed by intelligence from the Threat Intelligence Cloud? (Choose three.)
Threat Intelligence CloudVulnerability ProtectionAnti-Spywaresignature-based detection - Question #40Panorama Architecture
In which two cases should the Hardware offering of Panorama be chosen over the Virtual Offering? (Choose two)
Panorama hardwareM-Series appliancededicated logger modelog capacity - Question #41User-ID Deployment
Which three methods used to map users to IP addresses are supported in Palo Alto Networks firewalls? (Choose three.)
User-IDIP-to-user mappingClient Probingauthentication integration - Question #42Panorama
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to secure data center traffic? (Choose two.)
PanoramaVM-Series bootstrappingAutomated Correlation Enginevirtual firewall management - Question #43Decryption
Because of regulatory compliance a customer cannot decrypt specific types of traffic. Which license should an SE recommend to the customer who will be decrypting traffic on the Pal...
SSL decryptionURL filtering licensedecryption policyregulatory compliance - Question #45Network Security - Decryption
Which three policies or certificates must be configured for SSL Forward Proxy decryption? (Choose three.)
SSL Forward Proxydecryption policyforward trust certificateforward untrust certificate - Question #46Platform Architecture and Value
What are two core values of the Palo Alto Network Security Platform? (Choose two)
security platformpreventionplatform value proposition - Question #47Network Security - Platform Architecture
Which design objective could be satisfied by vsys functionality?
virtual systemsvsysadministrative separationmulti-tenancy - Question #48Advanced Threat Prevention
Which functionality is available to firewall users with an active Threat Prevention subscription, but no WildFire license?
Threat PreventionWildFiresubscription licensingsignature updates - Question #49Network Security - Decryption
How does SSL Forward Proxy decryption work?
SSL Forward ProxySSL/TLS inspectioncertificate handlingdecryption - Question #50Proof of Value
Which three actions should be taken before deploying a firewall evaluation unit in the customer's environment? (Choose three.)
POC deploymentTAP modePanorama connectivityevaluation unit - Question #51Advanced Threat Prevention
What are three sources of malware sample data for the Palo Alto Networks Threat Intelligence Cloud? (Choose three.)
Threat Intelligence CloudWildFireAutoFocusthreat data sources - Question #52Proof of Value
What are three best practices for running an Ultimate Test Drive (UTD)? (Choose three.)
Ultimate Test DriveUTDproof of valuebest practices - Question #53Advanced Threat Prevention
An endpoint, inside an organization, is infected with known malware. The malware attempts to make a command and control connection to a C&C server via the destination IP address. W...
DNS SinkholingC&C preventionbotnetcommand and control - Question #54Advanced Threat Prevention
A prospective customer was the victim of a zero-day attack that compromised specific employees, who then became unwitting attack vectors. The customer does not want that to happen...
zero-day protectionTrapsWildFireendpoint security