PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 3 of 7.
- Question #110Device Management and Software Maintenance
A company is upgrading its existing Palo Alto Networks firewall from version 7.0.1 to 7.0.4. Which three methods can the firewall administrator use to install PAN- OS 7.0.4 across...
PAN-OS UpgradeSoftware ManagementPanoramaFirewall Administration - Question #111GlobalProtect and Authentication
Which Public Key infrastructure component is used to authenticate users for GlobalProtect when the Connect Method is set to pre-logon?
GlobalProtectPre-logonMachine CertificatePKI - Question #112Panorama Management and Troubleshooting
The company's Panorama server (IP 10.10.10.5) is not able to manage a firewall that was recently deployed. The firewall's dedicated management port is being used to connect to the...
PanoramaManagement ConnectivityCLI TroubleshootingNetwork Diagnostics - Question #113Logging and Monitoring
Which three log-forwarding destinations require a server profile to be configured? (Choose three)
Log ForwardingServer ProfileSNMP TrapSyslog - Question #114Threat Prevention and DoS Protection
Which setting allow a DOS protection profile to limit the maximum concurrent sessions from a source IP address?
DoS Protection ProfileClassified TypeSession LimitingSecurity Profiles - Question #115Network Address Translation
A company has a web server behind a Palo Alto Networks next-generation firewall that it wants to make accessible to the public at 1.1.1.1. The company has decided to configure a de...
Destination NATNAT PolicyZone ConfigurationOriginal Packet - Question #116Panorama Log Collection
Which two options are required on an M-100 appliance to configure it as a Log Collector? (Choose two)
M-100 ApplianceLog CollectorPanoramaSystem Mode Configuration - Question #117Monitoring and Reporting
Click the Exhibit button. An administrator has noticed a large increase in bittorrent activity. The administrator wants to determine where the traffic is going on the company. What...
Application Command CenterACCTraffic InvestigationBitTorrent - Question #118Authentication and User-ID
Support for which authentication method was added in PAN-OS 7.0?
TACACS+Authentication MethodsPAN-OS 7.0New Features - Question #119Network Routing and Policy-Based Forwarding
Click the Exhibit button below, A firewall has three PBF rules and a default route with a next hop of 172.20.10.1 that is configured in the default VR. A user named Will has a PC w...
Policy-Based ForwardingPBF RulesNext HopTraffic Routing - Question #120VPN and Troubleshooting
What is the name of the debug save file for IPSec VPN tunnels?
IPSec VPNIKE ManagerDebug FileTroubleshooting - Question #122Network Configuration and Routing
In order to route traffic between layer 3 interfaces on the PAN firewall you need:
Virtual RouterLayer 3 InterfacesRoutingNetwork Configuration - Question #123Threat Prevention and WildFire
Wildfire may be used for identifying which of the following types of traffic?
WildFireMalware DetectionThreat PreventionFile Analysis - Question #124App-ID and Application Identification
What is the URL for the full list of applications recognized by Palo Alto Networks?
App-IDApplipediaApplication RecognitionPalo Alto Resources - Question #125App-ID and Application Identification
What does App-ID inspect to identify an application?
App-IDPayload InspectionApplication IdentificationDeep Packet Inspection - Question #126Threat Prevention and Security Concepts
If malware is detected on the internet perimeter, what other places in the network might be affected?
MalwareThreat PropagationNetwork SecurityBreach Prevention - Question #127Threat Prevention and WildFire
What are the major families of file types now supported by Wildfire in PAN-OS 7.0?
WildFireFile TypesPAN-OS 7.0Malware Analysis - Question #128NGFW Concepts and Security Architecture
Which of the following are critical features of a Next Generation Firewall that provide Breach prevention? Choose two.
Next-Generation FirewallBreach PreventionApp-IDTraffic Inspection - Question #129NGFW Architecture and Technology
True or False: One of the advantages of Single Pass Parallel Processing (SP3) is that traffic can be scanned as it crosses the firewall with minimum amount of buffering, which in t...
SP3single pass parallel processingthreat preventionmalware scanning - Question #130Platform Sizing and Hardware Selection
Which hardware platform should I consider if the customer needs at least 1 Gbps of Threat Prevention throughput and the ability to handle at least 250K sessions?
hardware sizingthreat prevention throughputsession capacityPA-3000 series - Question #131NGFW Architecture and Technology
True or False: DSRI degrades the performance of a firewall?
DSRIserver response inspectionfirewall performance - Question #132Security Subscriptions and Services
How quickly are Wildfire updates about previously unknown files now being delivered from the cloud to customers with a WildFire subscription (as of version 6.1)?
WildFire subscriptionsecurity subscriptionsupdate deliverythreat prevention - Question #134Platform Hardware Specifications
Which hardware firewall platforms include both built-in front-to-back airflow and redundant power supplies?
hardware specificationsPA-3060redundant power suppliesairflow design - Question #135WildFire and Threat Prevention
Select all the platform components that Wildfire automatically updates after finding malicious activity in previously unknown files, URLs and APKs?
WildFireanti-virus signaturesURL filteringC2 signatures - Question #136NGFW Value Proposition
What are five benefits of Palo Alto Networks NGFWs (Next Generation Firewalls)? (Select the five correct answers.)
NGFW benefitsthreat intelligence cloudsecurity subscriptionsplatform scalability - Question #137Sales Methodology and Demo Skills
What are the three key components of a successful Three Tab Demo? (Select the three correct answers.)
demo methodologyApp-ID visibilityuser application controlthreat blocking - Question #138WildFire and Threat Prevention
What are the main benefits of WildFire? (Select the three correct answers.)
WildFiresandboxingmalware signaturesglobal signature distribution - Question #139Security Operations and Monitoring
The automated Correlation Engine uses correlation objects to analyze the logs for patterns. When a match occurs:
Correlation Enginelog analysissecurity eventsautomated threat detection - Question #140Platform Sizing and Hardware Selection
Which one of these is not a factor impacting sizing decisions?
firewall sizingsession capacitydecryptionapplication count - Question #141NGFW Value Proposition
TRUE or FALSE: Many customers purchase Palo Alto Networks NGFWs (Next Generation Firewalls) just to gain previously unavailable levels of visibility into their traffic flows.
NGFW visibilitytraffic visibilityvalue proposition - Question #142PAN-OS Administration
A spike in dangerous traffic is observed. Which of the following PanOS tabs would an administrator utilize to identify culpable users.
ACCuser identificationtraffic analysisPAN-OS interface - Question #143WildFire and Threat Prevention
True or False: PAN-DB is a service that aligns URLs with category types and is fed to the WildFire threat cloud.
PAN-DBURL categorizationWildFirecloud threat services - Question #144Troubleshooting and Diagnostics
Firewall administrators cannot authenticate to a firewall GUI. Which two logs on that firewall will contain authentication-related information useful in troubleshooting this issue?...
authentication troubleshootingsystem logfirewall logsGUI access - Question #145Network Routing
Which option is an IPv6 routing protocol?
IPv6OSPFv3routing protocols - Question #146Network Address Translation
A network security engineer has a requirement to allow an external server to access an internal web server. The internal web server must also initiate connections with the external...
NAT policybidirectional NATsource NATpolicy configuration - Question #147PAN-OS Configuration and Management
A network design change requires an existing firewall to start accessing Palo Alto Updates from a data plane interface address instead of the management interface. Which configurat...
service routemanagement interfacedata plane interfaceupdate configuration - Question #148VPN and GlobalProtect
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed...
GlobalProtect Satellitelarge scale VPNPanorama templatesIPSec tunnel - Question #149PAN-OS CLI and Administration
Which CLI command displays the current management plan memory utilization?
CLI commandsmanagement planememory utilizationsystem resources - Question #150Security Policies and Profiles
Which URL Filtering Security Profile action logs the URL Filtering category to the URL Filtering log?
URL FilteringSecurity ProfilesAlert actionURL Filtering log - Question #151High Availability
What are two prerequisites for configuring a pair of Palo Alto Networks firewalls in an active/passive High Availability (HA) pair? (Choose two.)
High AvailabilityHA pairHA1 linkActive/Passive HA - Question #152Panorama
Which three rule types are available when defining policies in Panorama? (Choose three.)
PanoramaPolicy rule typesPre RulesPost Rules - Question #153Networking and Interface Configuration
A network design calls for a "router on a stick" implementation with a PA-5060 performing inter-VLAN routing All VLAN-tagged traffic will be forwarded to the PA- 5060 through a sin...
Layer 3 subinterfaceVLAN taggingdot1q trunkInter-VLAN routing - Question #154Logging and Reporting
Which Panorama feature allows for logs generated by Panorama to be forwarded to an external Security Information and Event Management(SIEM) system?
PanoramaLog ForwardingSIEM integrationLog Settings - Question #155Security Policies and Profiles
Which URL Filtering Security Profile action togs the URL Filtering category to the URL Filtering log?
URL FilteringSecurity ProfilesAlert actionURL Filtering log - Question #156Routing
Several offices are connected with VPNs using static IPV4 routes. An administrator has been tasked with implementing OSPF to replace static routing. Which step is required to accou...
OSPFVPNDynamic RoutingStatic route replacement - Question #158Routing
Several offices are connected with VPNs using static IPv4 routes. An administrator has been tasked with implementing OSPF to replace static routing. Which step is required to accom...
OSPFVPN tunnel interfacesDynamic RoutingArea ID - Question #159Quality of Service
People are having intermittent quality issues during a live meeting via web application.
QoSQoS ProfileQoS ClassesQoS Policy - Question #160Device Management
When is it necessary to activate a license when provisioning a new Palo Alto Networks firewall?
LicensingDynamic UpdatesAntivirusProvisioning - Question #161Device Management
A network design change requires an existing firewall to start accessing Palo Alto Updates from a dataplane interface address instead of the management interface. Which configurati...
Service RoutesDataplane interfaceManagement interfaceUpdate server access - Question #162Routing
A network security engineer needs to configure a virtual router using IPv6 addresses. Which two routing options support these addresses? (Choose two.)
IPv6 routingOSPFv3Static RoutesVirtual Router