PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 2 of 7.
- Question #55Panorama Management
Which two tabs in Panorama can be used to identify templates to define a common base configuration? (Choose two)
Panoramatemplatesbase configurationdevice management - Question #56Network Security - Security Policy
Which profile or policy should be applied to protect against port scans from the internet?
zone protection profileport scan preventionDoS protectionsecurity zones - Question #57Network Security - Security Policy
Which three application options can be selected in the security policy rule? (Choose three.)
security policyApp-IDapplication groupsapplication filters - Question #58Panorama Management
A network covers three geographical areas: Americas, Europe (EMEA), and Asia (APAC). The APAC segment of the network consists of nine HA pairs of PA-3060 firewalls, generating a co...
log collectorM-500 appliancePanorama architecturelog retention planning - Question #59Reporting and Visibility
The botnet report displays a confidence score of 1 to 5 indicating the likelihood of a botnet infection. Which three sources are used by the firewall as the basis of this score? (C...
botnet reportconfidence scoreApp-IDthreat detection - Question #61Network Security - Security Policy
A company.com wants to enable Application Override. Given the following screenshot: Which two statements are true if Source and Destination traffic match the Application Override p...
Application OverrideApp-ID bypassContent-ID bypasscustom application - Question #62Troubleshooting and Diagnostics
Which three fields can be included in a pcap filter? (Choose three)
packet capturepcapfilter fieldstroubleshooting - Question #63Advanced Threat Prevention
What are three possible verdicts that WildFire can provide for an analyzed sample? (Choose three)
WildFiremalware analysisverdictsgrayware - Question #64Panorama Management
A logging infrastructure may need to handle more than 10,000 logs per second. Which two options support a dedicated log collector function? (Choose two)
log collectorM-100 appliancePanorama applianceshigh-volume logging - Question #65User-ID and Authentication
What are three valid method of user mapping? (Choose three)
User-IDuser mappingSyslogServer Monitoring - Question #66Network Interface Configuration
A host attached to ethernet1/3 cannot access the internet. The default gateway is attached to ethernet1/4. After troubleshooting. It is determined that traffic cannot pass from the...
interface modesLayer 2Layer 3troubleshooting - Question #67QoS and Traffic Management
The IT department has received complaints abou VoIP call jitter when the sales staff is making or receiving calls. QoS is enabled on all firewall interfaces, but there is no QoS po...
QoSNetwork Activitytraffic monitoringVoIP - Question #69WildFire Threat Analysis
Which three options does the WF-500 appliance support for local analysis? (Choose three)
WildFireWF-500local analysisfile types - Question #70Application Identification and Content Inspection
Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application...
App-IDcustom applicationContent-IDapplication signatures - Question #71Panorama and Centralized Logging
After pushing a security policy from Panorama to a PA-3020 firewall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic l...
Panoramalog forwardingsecurity policylogging - Question #72Threat Prevention
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermo...
DNS sinkholeAnti-Spywarebotnetcommand-and-control - Question #73Initial Device Configuration
Which two statements are correct for the out-of-box configuration for Palo Alto Networks NGFWs? (Choose two)
default configurationmanagement interfaceout-of-boxvirtual wire - Question #74Device Management and Panorama
A network security engineer is asked to perform a Return Merchandise Authorization (RMA) on a firewall Which part of files needs to be imported back into the replacement firewall t...
RMAPanoramadevice statefirewall replacement - Question #75Routing and Network Troubleshooting
A network engineer has revived a report of problems reaching 98.139.183.24 through vr1 on the firewall. The routing table on this firewall is extensive and complex. Which CLI comma...
CLIroutingFIB lookuptroubleshooting - Question #76High Availability
Which two mechanisms help prevent a spilt brain scenario an Active/Passive High Availability (HA) pair? (Choose two)
High Availabilitysplit-brainHA1 backupActive/Passive HA - Question #77Security Profiles and Content Inspection
What are three valid actions in a File Blocking Profile? (Choose three)
File Blockingsecurity profilescontent inspectionprofile actions - Question #78VPN Configuration and Troubleshooting
An Administrator is configuring an IPSec VPN toa Cisco ASA at the administrator's home and experiencing issues completing the connection. The following is th output from the comman...
IPSec VPNIKEtroubleshootingCisco ASA interoperability - Question #79Network Interface Configuration
Which interface configuration will accept specific VLAN IDs?
VLANsubinterfaceinterface configurationLayer 3 - Question #80Threat Prevention
Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)
malicious domainsdynamic databaseZone ProtectionDoS Protection - Question #82Security Zones and Network Configuration
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192....
security zonesinterface configurationtroubleshootingzone assignment - Question #83VPN Configuration and Troubleshooting
A VPN connection is set up between Site-A and Site-B, but no traffic is passing in the system log of Site-A, there is an event logged as like-nego-p1-fail-psk. What action will bri...
IKEVPNpre-shared keyphase 1 negotiation - Question #84Firewall Troubleshooting and Diagnostics
A firewall administrator is troubleshooting problems with traffic passing through the Palo Alto Networks firewall. Which method shows the global counters associated with the traffi...
CLIglobal counterspacket filtertraffic troubleshooting - Question #86Virtualization and VM-Series Deployment
Which Palo Alto Networks VM-Series firewall is supported for VMware NSX?
VM-SeriesVMware NSXvirtualizationVM-1000-HV - Question #87Network Configuration and High Availability
A client is deploying a pair of PA-5000 series firewalls using High Availability (HA) in Active/Passive mode. Which statement is true about this deployment?
High AvailabilityActive/Passive HAHA control linkPA-5000 series - Question #88Security Policy and NAT Configuration
What must be used in Security Policy Rule that contain addresses where NAT policy applies?
NAT policySecurity policyPre-NAT addressingZone mapping - Question #89Security Policy Configuration
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following securi...
Security policy rulesApplication classificationLog forwardingSecurity profiles - Question #90Network Services Configuration
How are IPV6 DNS queries configured to user interface ethernet1/3?
IPv6 DNSService route configurationInterface servicesDNS resolution - Question #91Threat Prevention and DoS Mitigation
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination...
DoS protectionNTP amplificationClassified DoS policyUDP flood - Question #92Threat Prevention
Which Security Policy Rule configuration option disables antivirus and anti-spyware scanning of server-to-client flows only?
Disable Server Response InspectionAntivirus scanningAnti-spywareSecurity profile options - Question #93Threat Prevention
Which three options are available when creating a security profile? (Choose three)
Security profilesThreat PreventionAntivirusProfile configuration - Question #95Security Policy and NAT Configuration
A company hosts a publically accessible web server behind a Palo Alto Networks next generation firewall with the following configuration information. - Users outside the company ar...
Destination NATSecurity zonesNAT policyPublic IP translation - Question #96GlobalProtect VPN
Which two interface types can be used when configuring GlobalProtect Portal?(Choose two)
GlobalProtect portalInterface typesLoopback interfaceLayer 3 interface - Question #97Troubleshooting and Diagnostics
What can missing SSL packets when performing a packet capture on dataplane interfaces?
Packet captureHardware offloadDataplane processingSSL traffic - Question #98Threat Prevention
A network Administrator needs to view the default action for a specific spyware signature. The administrator follows the tabs and menus through Objects> Security Profiles> Anti-Spy...
Anti-spyware profileSignature exceptionsDefault actionsSecurity profile navigation - Question #99Panorama Management
How does Panorama handle incoming logs when it reaches the maximum storage capacity?
PanoramaLog storageLog managementStorage capacity - Question #100Firewall Architecture and Components
Which three function are found on the dataplane of a PA-5050? (Choose three)
PA-5050 architectureDataplane functionsManagement planeSignature matching - Question #101SSL/TLS Decryption
How is the Forward Untrust Certificate used?
SSL decryptionForward untrust certificateCertificate trustSSL inspection - Question #102Firewall Administration and Troubleshooting
A firewall administrator has completed most of the steps required to provision a standalone Palo Alto Networks Next-Generation Firewall. As a final step, the administrator wants to...
CLI commandsSecurity policy testingPolicy match testTroubleshooting - Question #103Security Policy and NAT Configuration
The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is c...
Destination NATPort translationPre-NAT zonesSecurity policy zones - Question #104High Availability and Monitoring
A company has a pair of Palo Alto Networks firewalls configured as an Acitve/Passive High Availability (HA) pair. What allows the firewall administrator to determine the last date...
High AvailabilityHA failoverSystem log filteringHA event monitoring - Question #105Panorama Management
A network administrator uses Panorama to push security polices to managed firewalls at branch offices. Which policy type should be configured on Panorama if the administrators at t...
Panorama post-rulesPre-rulesPolicy overrideCentralized management - Question #106GlobalProtect VPN
Which client software can be used to connect remote Linux client into a Palo Alto Networks Infrastructure without sacrificing the ability to scan traffic and protect against threat...
GlobalProtectLinux clientRemote access VPNThreat scanning - Question #107Application Identification and Control
Only two Trust to Untrust allow rules have been created in the Security policy - Rule1 allows google-base - Rule2 allows youtube-base The youtube-base App-ID depends on google-base...
App-ID dependenciesApplication identificationDNS applicationSecurity policy - Question #108GlobalProtect Configuration
The GlobalProtect Portal interface and IP address have been configured. Which other value needs to be defined to complete the network settings configuration of GlobalPortect Portal...
GlobalProtect PortalServer CertificateNetwork SettingsPKI - Question #109Network Security Policy
Which command can be used to validate a Captive Portal policy?
Captive PortalCLI CommandsPolicy ValidationTroubleshooting