PSE-PLATFORM Exam Questions
329 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 6 of 7.
- Question #281
An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and...
- Question #282
Refer to the exhibit. Which certificates can be used as a Forwarded Trust certificate?
- Question #283
Which method does an administrator use to integrate all non-native MFA platforms in PAN- OS?software?
- Question #285
Which three authentication services can administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewa...
- Question #286
Which method will dynamically register tags on the Palo Alto Networks NGFW?
- Question #287
Which feature can be configured on VM-Series firewalls?
- Question #288
Which two options prevent the firewall from capturing traffic passing through it? (Choose two.)
- Question #289
What is exchanged through the HA2 link?
- Question #290
View the GlobalProtect configuration screen capture. What is the purpose of this configuration?
- Question #291
An administrator has been asked to create 100 virtual firewalls in a local, on-premise lab environment (not in "the cloud"). Bootstrapping is the most expedient way to perform this...
- Question #292
Which two subscriptions are available when configuring panorama to push dynamic updates to connected devices? (Choose two.)
- Question #293
Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a "No Decrypt" action? (Choose two.)
- Question #294
Which CLI command enables an administrator to check the CPU utilization of the dataplane?
- Question #296
An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against external hosts attempting to exploit a flaw in an operating system on an intern...
- Question #297
Which three are valid configuration options in a WildFire Analysis Profile? (Choose three.)
- Question #298
Which DoS protection mechanism detects and prevents session exhaustion attacks?
- Question #299
Which processing order will be enabled when a Panorama administrator selects the setting "Objects defined in ancestors will take higher precedence?"
- Question #300
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance. Which interface type and l...
- Question #301
An administrator using an enterprise PKI needs to establish a unique chain of trust to ensure mutual authentication between Panorama and the managed firewalls and Log Collectors. H...
- Question #302
The firewall identifies a popular application as an unknown-tcp. Which two options are available to identify the application? (Choose two.)
- Question #303
An administrator has created an SSL Decryption policy rule that decrypts SSL sessions on any port. Which log entry can the administrator use to verify that sessions are being decry...
- Question #304
Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)
- Question #305
When is the content inspection performed in the packet flow process?
- Question #306
Which User-ID method should be configured to map IP addresses to usernames for users connected through a terminal server?
- Question #307
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
- Question #308
In High Availability, which information is transferred via the HA data link?
- Question #309
Which three authentication factors does PAN-OS@software support for MFA? (Choose three.)
- Question #310
A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks. How can t...
- Question #311
A customer wants to combine multiple Ethernet interfaces into a single virtual interface using link aggregation. Which two formats are correct for naming aggregate interfaces? (Cho...
- Question #313
A web server is hosted in the DMZ and the server is configured to listen for incoming connections on TCP port 443. A Security policies rules allowing access from the Trust zone to...
- Question #314
Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)
- Question #315
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
- Question #316
Which virtual router feature determines if a specific destination IP address is reachable?
- Question #318
An administrator has configured a QoS policy rule and a QoS Profile that limits the maximum allowable bandwidth for the YouTube application. However, YouTube is consuming more than...
- Question #319
Which log file can be used to identify SSL decryption failures?
- Question #320
A customer wants to set up a site-to-site VPN using tunnel interfaces? Which two formats are correct for naming tunnel interfaces? (Choose two.)
- Question #321
Based on the following image, what is the correct path of root, intermediate, and end-user certificate?
- Question #322
An administrator wants a new Palo Alto Networks NGFW to obtain automatic application updates daily, so it is configured to use a scheduler for the application database. Unfortunate...
- Question #324
Which data flow describes redistribution of user mappings?
- Question #325
Where can an administrator see both the management plane and data plane CPU utilization in the WebUI?
- Question #326
Which four NGFW multi-factor authentication factors are supported by PAN-OS? (Choose four.)
- Question #327
Which two features does PAN-OS® software use to identify applications? (Choose two.)
- Question #328
An administrator wants to upgrade an NGFW from PAN-OS® 7.1.2 to PAN-OS® 8.0.2. The firewall is not a part of an HA pair. What needs to be updated first?
- Question #330
Which two settings can be configured only locally on the firewall and not pushed from a Panorama template stack? (Choose two.)
- Question #331
An administrator just submitted a newly found piece of spyware for WildFire analysis. The spyware monitors behavior without the user's knowledge. What is the expected verdict from...
- Question #332
When configuring the firewall for packet capture, what are the valid stage types?
- Question #333
Which operation will impact performance of the management plane?
- Question #334
Which User-ID method maps IP addresses to usernames for users connecting through a web proxy that has already authenticated the user?
- Question #335
The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?
- Question #336
Which GlobalProtect Client connect method requires the distribution and use of machine certificates?