PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 6 of 7.
- Question #277Device Management
Which option would an administrator choose to define the certificate and protocol that Panorama and its managed devices use for SSL/TLS services?
SSL/TLS service profilecertificate managementPanoramamanaged devices - Question #278VPN
VPN traffic intended for an administrator's Palo Alto Networks NGFW is being maliciously intercepted and retransmitted by the interceptor. When creating a VPN tunnel, which protect...
VPNreplay protectionIPSecanti-replay - Question #279Monitoring and Logging
Which item enables a firewall administrator to see details about traffic that is currently active through the NGFW?
active sessionstraffic monitoringsession browserACC - Question #280QoS and Traffic Management
An administrator needs to optimize traffic to prefer business-critical applications over non- critical applications. QoS natively integrates with which feature to provide service q...
QoSApp-IDtraffic prioritizationquality of service - Question #281Securing Traffic
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and...
SSL decryptionDecryption ProfileApp-IDBitTorrent - Question #282Securing Traffic
Refer to the exhibit. Which certificates can be used as a Forwarded Trust certificate?
Forward Trust certificatePKIcertificate hierarchySSL decryption - Question #283User-ID and Authentication
Which method does an administrator use to integrate all non-native MFA platforms in PAN- OS?software?
MFARADIUSauthenticationPAN-OS - Question #285User-ID and Authentication
Which three authentication services can administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewa...
admin authenticationSAMLTACACS+RADIUS - Question #286User-ID and Authentication
Which method will dynamically register tags on the Palo Alto Networks NGFW?
dynamic tagsXML-APIUser-IDVM monitoring - Question #287Platform Architecture
Which feature can be configured on VM-Series firewalls?
VM-SeriesGlobalProtectvirtual firewall features - Question #288Monitoring and Troubleshooting
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)
packet capturetraffic offloadcapture filtertroubleshooting - Question #289High Availability
What is exchanged through the HA2 link?
HA2session synchronizationhigh availability - Question #290GlobalProtect
View the GlobalProtect configuration screen capture. What is the purpose of this configuration?
GlobalProtectinternal gateway detectionreverse DNSsplit tunneling - Question #291Platform Deployment
An administrator has been asked to create 100 virtual firewalls in a local, on-premise lab environment (not in "the cloud"). Bootstrapping is the most expedient way to perform this...
bootstrappingVM-Seriesvirtual CD-ROMISO - Question #292Panorama
Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.)
Panoramadynamic updatescontent subscriptionsAntivirus - Question #293Securing Traffic
Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a "No Decrypt" action? (Choose two.)
Decryption ProfileNo Decrypt actioncertificate validationcipher suites - Question #294Monitoring and Troubleshooting
Which CLI command enables an administrator to check the CPU utilization of the dataplane?
CLIdataplane CPUresource monitoringperformance - Question #296Threat Prevention
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against external hosts attempting to exploit a flaw in an operating system on an intern...
Vulnerability ProtectionSecurity Profileexploit preventionIPS - Question #297WildFire
Which three are valid configuration options in a WildFire Analysis Profile? (Choose three.)
WildFireAnalysis Profilefile typesdirection - Question #298Network Security
Which DoS protection mechanism detects and prevents session exhaustion attacks?
DoS protectionResource Protectionsession exhaustionzone protection - Question #299Panorama
Which processing order will be enabled when a Panorama administrator selects the setting "Objects defined in ancestors will take higher precedence?"
Panoramaobject precedencedevice groupspolicy hierarchy - Question #300Securing Traffic
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance. Which interface type and l...
Decryption MirrorSSL inspectionpacket exportDecryption Port Mirror license - Question #301Device Management
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between Panorama and the managed firewalls and Log Collectors. H...
custom certificatesPKIPanoramamutual authentication - Question #302App-ID and Traffic Identification
The firewall identifies a popular application as an unknown-tcp. Which two options are available to identify the application? (Choose two.)
App-IDcustom applicationunknown-tcpapplication identification - Question #303Decryption
An administrator has created an SSL Decryption policy rule that decrypts SSL sessions on any port. Which log entry can the administrator use to verify that sessions are being decry...
SSL decryptiontraffic logdecryption verificationsession logging - Question #304WildFire and Threat Intelligence
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
AutoFocuslicense verificationdevice managementconnectivity - Question #305App-ID and Content Inspection
When is the content inspection performed in the packet flow process?
packet flowcontent inspectionapplication identificationSSL proxy - Question #306User-ID
Which User-ID method should be configured to map IP addresses to usernames for users connected through a terminal server?
User-IDterminal serverport mappingIP-to-user mapping - Question #307NAT and Security Policies
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
DNATSecurity policyNATDMZ - Question #308High Availability
In High Availability, which information is transferred via the HA data link?
High AvailabilityHA data linksession synchronizationHA2 - Question #309Authentication and Authorization
Which three authentication factors does PAN-OS@software support for MFA? (Choose three.)
MFAauthentication factorsPAN-OSSMS - Question #310Threat Prevention
A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks. How can t...
DoS ProtectionDDoSsession countresource exhaustion - Question #311Network Interface Configuration
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using link aggregation. Which two formats are correct for naming aggregate interfaces? (Cho...
aggregate interfacelink aggregationinterface namingLAG - Question #313Decryption
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to...
SSL decryptionForward ProxySecurity policyweb-browsing - Question #314Authentication and Authorization
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
TACACS+LDAPRADIUSrole-based authentication - Question #315Decryption
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
SSH proxydecryption policyprerequisitesSSH decryption - Question #316Routing and Network Configuration
Which virtual router feature determines if a specific destination IP address is reachable?
virtual routerpath monitoringdestination IProuting - Question #317NAT and Security Policies
Which Zone Pair and Rule Type will allow a successful connection for a user on the Internet zone to a web server hosted on the DMZ zone? The web server is reachable using a Destina...
zone pairDNATSecurity policyDMZ - Question #318Quality of Service
An administrator has configured a QoS policy rule and a QoS Profile that limits the maximum allowable bandwidth for the YouTube application. However, YouTube is consuming more than...
QoSbandwidth limitingQoS interfacepolicy rule - Question #319Decryption
Which log file can be used to identify SSL decryption failures?
SSL decryptionTraffic logdecryption failureslogging - Question #320VPN
A customer wants to set up a site-to-site VPN using tunnel interfaces? Which two formats are correct for naming tunnel interfaces? (Choose two.)
tunnel interfaceVPNsite-to-site VPNinterface naming - Question #321Decryption and PKI
Based on the following image, what is the correct path of root, intermediate, and end-user certificate?
PKIcertificate chainroot CAintermediate certificate - Question #322Device Management
An administrator wants a new Palo Alto Networks NGFW to obtain automatic application updates daily, so it is configured to use a scheduler for the application database. Unfortunate...
service routesapplication updatesdataplane interfacecontent updates - Question #324User-ID and Identity Policy
Which data flow describes redistribution of user mappings?
User-ID redistributionIP-to-username mappingfirewall-to-firewallUser-ID agent - Question #325Platform Management and Monitoring
Where can an administrator see both the management plane and data plane CPU utilization in the WebUI?
management planedata planeCPU utilizationWebUI monitoring - Question #326Authentication and Access Control
Which four NGFW multi-factor authentication factors are supported by PAN-OS? (Choose four.)
multi-factor authenticationPAN-OS MFAOTPSMS push - Question #327Application Identification and Control
Which two features does PAN-OS® software use to identify applications? (Choose two.)
App-IDapplication identificationtransaction characteristicsapplication layer payload - Question #328Platform Management and Administration
An administrator wants to upgrade an NGFW from PAN-OS® 7.1.2 to PAN-OS® 8.0.2. The firewall is not a part of an HA pair. What needs to be updated first?
PAN-OS upgradedevice state exportmajor version upgradeHA upgrade path - Question #330Panorama and Centralized Management
Which two settings can be configured only locally on the firewall and not pushed from a Panorama template stack? (Choose two.)
Panorama templateslocal-only settingsHA IP addressmaster key - Question #331Threat Prevention and WildFire
An administrator just submitted a newly found piece of spyware for WildFire analysis. The spyware monitors behavior without the user's knowledge. What is the expected verdict from...
WildFiregrayware verdictspyware classificationmalware analysis