PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 4 of 7.
- Question #163VPN and GlobalProtect
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed...
GlobalProtect SatelliteLarge Scale VPNPanorama TemplatesIPSec tunnel - Question #164Quality of Service
People are having intermittent quality issues during a live meeting via a web application. How can the performance of this application be improved?
QoSQoS ProfileQoS ClassesQoS Policy - Question #165Device Management
When is it necessary to activate a license when provisioning a new Palo Alto Networks firewall?
LicensingDynamic UpdatesAntivirusProvisioning - Question #166Security Policies and Profiles
A file sharing application is being permitted and no one knows what this application is used for. How should this application be blocked?
File Blocking ProfileApplication ControlSecurity ProfilesUnknown applications - Question #167Quality of Service
YouTube videos are consuming too much bandwidth on the network, causing delays in mission-critical traffic. The administrator wants to throttle YouTube traffic. The following inter...
QoSBandwidth throttlingQoS ClassesInbound/Outbound profile - Question #168Security Policies and Profiles
Which field is optional when creating a new Security Police rule?
Security PolicyRule configurationOptional fields - Question #169Threat Prevention
When using the predefined default antivirus profile, the policy will inspect for viruses on the decoders. Match each decoder with its default action. Answer options may be used mor...
Antivirus ProfileProtocol decodersDefault actionsSecurity Profiles - Question #170Threat Prevention
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinkhole enabled, generating a traffic log. What...
DNS SinkholeAnti-SpywareC2 trafficTraffic logs - Question #171Logging and Reporting
How can a Palo Alto Networks firewall be configured to send syslog messages in a format compatible with non-standard syslog servers?
sysloglog forwardingcustom log formatserver profile - Question #172High Availability
What are two prerequisites for configuring a pair of Palo Alto Networks firewalls in an active/passive High Availability (HA) pair? (Choose two.)
High Availabilityactive/passive HAHA1 interfacelicensing - Question #173Panorama Management
Which device Group option is assigned by default in Panorama whenever a new device group is created to manage a Firewall?
Panoramadevice groupsSharedconfiguration hierarchy - Question #174Network Troubleshooting
When performing the "ping" test shown in this CLI output: What will be the source address in the ICMP packet?
CLIpingsource addresstroubleshooting - Question #175Routing
Site-A and Site- have a site-to-site VPN set up between them. OSPF is configured to dynamically create the routes between the sites. The OSPF configuration in Site- is configured p...
OSPFtunnel interfacelink typep2p - Question #177High Availability
Which two virtualized environments support Active/Active High Availability (HA) in PAN-OS 7.0? (Choose two.)
Active/Active HAvirtualizationVMware ESXKVM - Question #178Panorama Management
Which Panorama feature allows for logs generated by Panorama to be forwarded to an external Security Information and Event Management (SIEM) system?
Panoramalog forwardingSIEMlog settings - Question #179Authentication and Authorization
In an enterprise deployment, a network security engineer wants to assign rights to a group of administrators without creating local administrator accounts on the firewall. Which au...
administrator authenticationLDAPRADIUSrole-based access - Question #181Security Policies and Profiles
Which URL Filtering Security Profile action logs the URL Filtering category to the URL Filtering log?
URL Filteringsecurity profilealert actionURL filtering log - Question #182User-ID
Which authentication source requires the installation of Palo Alto Networks software, other than PAN-OS 7x, to obtain username-to-IP-address mapping?
User-IDTerminal Services Agentusername-to-IP mappingadditional software - Question #183User-ID
Which two actions are required to make Microsoft Active Directory users appear in a firewall traffic log? (Choose two.)
User-IDActive Directoryzone configurationevent log viewer - Question #184Logging and Reporting
Firewall administrators cannot authenticate to a firewall GUI. Which two logs on that firewall will contain authentication-related information useful in troubleshooting this issue?...
authentication troubleshootingsystem logsadmin accessfirewall GUI - Question #186Routing
Several offices are connected with VPNs using static IPv4 routes. An administrator has been tasked with implementing OSPF to replace static routing. Which step is required to accom...
OSPFtunnel interfaceIP addressingVPN routing - Question #187System Monitoring and Troubleshooting
Which CLI command displays the current management plane memory utilization?
CLIsystem resourcesmanagement planememory utilization - Question #188Panorama Management
A distributed log collection deployment has dedicated Log Collectors. A developer needs a device to send logs to Panorama instead of sending logs to the Collector Group. What shoul...
PanoramaLog CollectorCollector Groupdistributed logging - Question #189VPN
Site-A and Site-B need to use IKEv2 to establish a VPN connection. Site-A connects directly to the internet using a public IP address. Site-B uses a private IP address behind an IS...
IKEv2NAT Traversalsite-to-site VPNprivate IP - Question #190NAT
A network security engineer has a requirement to allow an external server to access an internal web server. The internal web server must also initiate connections with the external...
NAT policybidirectional NATsource NATdestination NAT - Question #191Threat Prevention
What happens when the traffic log shows an internal host attempting to open a session to a properly configured sinkhole address?
DNS sinkholethreat preventionmalicious domainUser-ID - Question #192Licensing and Subscriptions
PAS-OS 7.0 introduced an automated correlation engine that analyzes log patterns and generates correlation events visible in the new Application Command Center (ACC). Which license...
correlation engineACCThreat Prevention licenselog analysis - Question #193Networking and Routing
Site-A and Site-have a site-to-site VPN set up between them. OSPF is configured to dynamically create the routes between the sites. The OSPF configuration in Site-is configured pro...
OSPF Link TypeSite-to-Site VPNTunnel InterfaceDynamic Routing - Question #194Troubleshooting and Monitoring
A network security engineer for a large company has just installed a PA-5060 Firewall to isolate the company's PCI environment from its production network. The company's network en...
Interface TroubleshootingCLI DiagnosticsPA-5060Network Interfaces - Question #195Monitoring and Reporting
On March 10, 2016, between 11:00 am and 11:30 am, users reported that web-browsing traffic to the IP address 1.1.1.1 failed. Which filter can be applied to the traffic logs to show...
Traffic Log FilteringLog Query SyntaxLog AnalysisTime-Based Filtering - Question #196Application Identification and Control
Server Message Block (SMB), a common file-sharing application, is slow when passing through a Palo Alto Networks firewall. The Network Security Administrator created an application...
Application OverrideLayer 7 ProcessingSMB PerformanceCustom Application - Question #197Security Policy Configuration
What are three valid options when creating a new security policy? (Choose three.)
Security PolicyApplication Layer GatewaySIP ALGPolicy Actions - Question #199Threat Prevention
Which two statements accurately describe how DoS Protection Profiles and Policies mitigate attacks? (Choose two.)
DoS Protection ProfileSession LimitsRandom Early DropFlood Mitigation - Question #201Security Policy Configuration
What are the three Security Policy Rule Type classifications supported in PAN-OS 7.0? (Choose three.)
Security Policy Rule TypesUniversalIntrazoneInterzone - Question #202Certificate Management and PKI
What is the default behavior when a Certificate Profile is configured to use both CRL and OCSP?
Certificate ProfileOCSPCRLPKI - Question #203Network Interface Configuration
Ethernet1/1 has been configured with the following subinterfaces: The following security policy rule is applied: The Interface Management Profile permits the following: What will b...
SubinterfacesManagement ProfileVLANInterface Configuration - Question #204Networking and Routing
Given the following diagram: A VPN connection has been created to allow traffic from the Trust-L3 zone of Site A to reach the Trust-L3 zone of Site B. Each site is using tunnel.1 i...
Static RoutingSite-to-Site VPNVirtual RouterTunnel Interface - Question #205Palo Alto Networks Firewall Architecture
For which two functions is the management plane responsible? (Choose two.)
Management PlaneData PlanePAN-OS ArchitectureLog Forwarding - Question #206Threat Prevention
A company has started utilizing WildFire in its network. Which three file types are supported? (Choose three.)
WildFireFile Type SupportMalware AnalysisThreat Prevention - Question #208User Identification and Authentication
Which Captive Portal mode must be configured to support MFA authentication?
Captive PortalMFA AuthenticationRedirect ModeUser-ID - Question #209Threat Prevention
Which protection feature is available only in a Zone Protection Profile?
Zone Protection ProfilePort Scan ProtectionDoS ProtectionReconnaissance Protection - Question #210User Identification and Authentication
Which User-ID method maps IP addresses to usernames for users connecting through an 802.1x-enabled wireless network device that has no native integration with PAN-OS?software?
User-ID802.1x WirelessXML APIIP-to-Username Mapping - Question #212Troubleshooting and Monitoring
An administrator needs to determine why users on the trust zone cannot reach certain websites. The only information available is shown on the following image. Which configuration c...
Security Policy TroubleshootingTrust ZoneTraffic AnalysisPolicy Debugging - Question #213User Identification and Authentication
An administrator has users accessing network resources through Citrix XenApp 7 x. Which User-ID mapping solution will map multiple users who are using Citrix to connect to the netw...
User-IDCitrix XenAppTerminal Services AgentMulti-User Mapping - Question #214Application Identification and Control
An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW. The update contains an...
App-IDCustom ApplicationDynamic Content UpdatesSignature Precedence - Question #215Panorama Management
How can a candidate or running configuration be copied to a host external from Panorama?
PanoramaConfiguration ExportNamed Configuration SnapshotConfiguration Management - Question #216Network Security - GlobalProtect VPN
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to mu...
GlobalProtect satelliteLSVPNVPN auto-discoveryremote site deployment - Question #217Network Security - User-ID
A global corporate office has a large-scale network with only one User-ID agent, which creates a bottleneck near the User-ID agent server. Which solution in PAN- OS?software would...
User-ID redistributionuser mappingUser-ID agent scalabilitybottleneck resolution - Question #218Platform Administration
Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by t...
CLI test commandtraffic simulationsecurity policy testingNAT testing - Question #219Threat Prevention - Credential Phishing
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
credential phishing preventionDomain Credential FilterIP-to-user mappingcredential theft detection