PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 5 of 7.
- Question #220Network Security - Security Policy and App-ID
Which Security policy rule will allow an admin to block facebook chat but allow Facebook in general?
App-IDsecurity policy orderingapplication dependencyfacebook-chat blocking - Question #221Threat Prevention - Credential Phishing
Which feature prevents the submission of corporate login information into website forms?
credential phishing preventioncorporate credentialsURL filteringform submission protection - Question #222Platform Administration - Performance Optimization
Which three steps will reduce the CPU utilization on the management plane? (Choose three.)
management plane CPUSNMP optimizationapplication overrideperformance tuning - Question #223Virtualization - VM-Series Deployment
Which two virtualization platforms officially support the deployment of Palo Alto Networks VM-Series firewalls? (Choose two.)
VM-SeriesKVMHyper-Vsupported virtualization platforms - Question #224Platform Administration - AutoFocus Integration
To connect the Palo Alto Networks firewall to AutoFocus, which setting must be enabled?
AutoFocusdevice management settingsthreat intelligence integrationmanagement plane configuration - Question #225Network Security - App-ID
Which event will happen if an administrator uses an Application Override Policy?
Application OverrideApp-ID processingLayer 4 bypasstraffic classification - Question #226Network Security - NAT
An administrator wants multiple web servers in the DMZ to receive connections initiated from the internet. Traffic destined for 206.15.22.9 port 80/TCP needs to be forwarded to the...
destination NATDMZ web serversport forwardingNAT rule ordering - Question #227High Availability
Which three options are supported in HA Lite? (Choose three.)
HA Liteactive/passive HAIPsec SA synchronizationconfiguration synchronization - Question #229Centralized Management - Panorama
An administrator is using Panorama and multiple Palo Alto Networks NGFWs. After upgrading all devices to the latest PAN-OS?software, the administrator enables log forwarding from t...
Panorama log forwardingpre-existing logslog migrationPanorama management - Question #230Centralized Management - Panorama
An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panora...
PanoramaHA pair config pushactive/passive synchronizationcentralized management - Question #231Threat Prevention - WildFire
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
WildFire basic servicefile type analysisAPKPDF and JAR files - Question #232High Availability
Which three firewall states are valid? (Choose three.)
HA firewall statesactive statepassive statesuspended state - Question #233Network Security - Decryption
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?
SSL inbound decryptionCRL connectivitycertificate trustdecryption troubleshooting - Question #235Network Security - Routing and Interface Configuration
An administrator needs to implement an NGFW between their DMZ and Core network. EIGRP Routing between the two environments is required. Which interface type would support this busi...
EIGRP routingLayer 3 interfacesvirtual routerinterface type selection - Question #236Troubleshooting
A network security engineer for a large company has just installed a PA-5060 Firewall to isolate the company's PCI environment from its production network. The company's engineers...
interface troubleshootingCLI commandsnetwork interfacesshow interface - Question #237Site-to-Site VPN
After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly...
IPSec VPNPFS group mismatchIPSec crypto profileVPN troubleshooting - Question #239Centralized Management with Panorama
If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is...
Panoramatemplate stackoverlapping settingsconfiguration priority - Question #241App-ID and Security Policy
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the...
App-IDcustom applicationthreat scanningunknown-tcp - Question #242App-ID Packet Processing
During the packet flow process, which two processes are performed in application identification? (Choose two.)
App-IDpacket flowapplication identificationapplication override - Question #243Device Administration
An administrator logs in to the Palo Alto Networks NGFW and reports that the WebUI is missing the Policies tab. Which profile is the cause of the missing Policies tab?
admin role profileRBACWebUI accessadministrative access - Question #244GlobalProtect
When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?
GlobalProtectportal configurationauthentication profileuser authentication - Question #245Certificate Management
The certificate information displayed in the following image is for which type of certificate?
certificatesPKIself-signed root CAcertificate management - Question #246High Availability
An administrator has been asked to configure active/passive HA for a pair of Palo Alto Networks NGFWs. The administrator assigns priority 100 to the active firewall. Which priority...
high availabilityactive/passive HAHA priorityfailover configuration - Question #247Security Processing and Packet Flow
Which option is part of the content inspection process?
content inspectionpacket flowsecurity processingthreat inspection - Question #248WildFire and Threat Prevention
Which three types of software will receive a Grayware verdict from WildFire? (Choose Three)
WildFiregrayware verdictmalware classificationthreat prevention - Question #249Device Management
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port which it connects. How would an administrator configure the interface to 1...
CLImanagement interfacespeed-duplexdevice configuration - Question #250Routing
In a virtual router, which object contains all potential routes?
virtual routerRIBrouting information baserouting table - Question #251NAT and Security Policy
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, wher...
DNATNAT policysecurity policy zone matchingdestination NAT - Question #252App-ID Configuration
A customer has an application that is being identified as unknown-top for one of their custom PostgreSQL database connections. Which two configuration options can be used to correc...
App-IDcustom applicationunknown-tcpapplication override - Question #254Routing and Troubleshooting
An administrator has enabled OSPF on a virtual router on the NGFW. OSPF is not adding new routes to the virtual router. Which two options enable the administrator to troubleshoot t...
OSPFrouting troubleshootingRuntime Statsvirtual router - Question #255Monitoring and Reporting
Which tool provides an administrator the ability to see trends in traffic over periods of time, such as threats detected in the last 30 days?
Application Command Centertraffic visibilitytrend reportingmonitoring - Question #256Routing and Troubleshooting
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router. Which two options would help t...
BGProuting troubleshootingRuntime StatsSystem logs - Question #257Policy-Based Forwarding
How can the firewall be configured automatically disable the PBF rule if the next hop goes down?
Policy-Based ForwardingPBF monitor profilepath monitoringfailover action - Question #258Threat Prevention and URL Filtering
Which feature must you configure to prevent users form accidentally submitting their corporate credentials to a phishing website?
credential phishing preventionURL filteringuser credential protectionthreat prevention - Question #260Panorama Management
What are two benefits of nested device groups in Panorama? (Choose two.)
nested device groupsPanoramaShared group inheritancepolicy reuse - Question #261Logging and Reporting
PAN-OS 7.0 introduced an automated correlation engine that analyzes log patterns and generates correlation events visible in the new Application Command Center (ACC). Which license...
correlation engineACCThreat Prevention licensecorrelation objects - Question #262Device Management
An administrator needs to upgrade a Palo Alto Networks NGFW to the most current version of PAN-OS® software. The firewall has internet connectivity through an Ethernet interface, b...
service routePAN-OS upgrademanagement interfacesoftware updates - Question #263Panorama Management
Which three settings are defined within the Templates object of Panorama? (Choose three.)
Panorama templatesVirtual Routersinterfacesnetwork configuration - Question #264Device Management
An administrator has left a firewall to use the default port for all management services. Which three functions are performed by the dataplane? (Choose three.)
dataplane functionsmanagement planeNATNTP - Question #265Security Policy
A Security policy rule is configured with a Vulnerability Protection Profile and an action of `Deny". Which action will this cause configuration on the matched traffic?
Security policyVulnerability Protection ProfileDeny actionSecurity Profiles - Question #266High Availability
If the firewall has the link monitoring configuration, what will cause a failover?
link monitoringHA failoverinterface monitoringhigh availability - Question #267Threat Prevention
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans. Which Security Profile type will protect against worms and t...
Anti-Spyware profileSecurity Profileswormstrojans - Question #269Threat Prevention
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?
classified DoS Protection Profileresource exhaustionDNS protectionper-IP protection - Question #270Network Configuration
Refer to the exhibit. Which will be the egress interface if the traffic's ingress interface is ethernet 1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?
routingegress interfacevirtual routerroute lookup - Question #271Authentication and Authorization
Which PAN-OS?policy must you configure to force a user to provide additional credentials before he is allowed to access an internal application that contains highly-sensitive busin...
Authentication policystep-up authenticationMFAsensitive applications - Question #272Troubleshooting
How would an administrator monitor/capture traffic on the management interface of the Palo Alto Networks NGFW?
tcpdumpmanagement interfacepacket captureCLI troubleshooting - Question #273Decryption
If an administrator does not possess a website's certificate, which SSL decryption mode will allow the Palo Alto networks NGFW to inspect when users browse to HTTP(S) websites?
SSL Forward ProxySSL decryptionHTTPS inspectiondecryption modes - Question #274Device Management
Which CLI command enables an administrator to view details about the firewall including uptime, PAN-OS?version, and serial number?
CLI commandsshow system infoPAN-OS versionserial number - Question #275Device Management
An administrator has configured the Palo Alto Networks NGFW's management interface to connect to the internet through a dedicated path that does not traverse back through the NGFW...
application signaturesdynamic updatesschedulermanagement interface - Question #276Network Configuration
A customer wants to set up a VLAN interface for a Layer 2 Ethernet port. Which two mandatory options are used to configure a VLAN interface? (Choose two.)
VLAN interfaceLayer 2virtual routersecurity zone