PSE-PLATFORM Exam Questions
335 real PSE-PLATFORM exam questions with expert-verified answers and explanations. Page 7 of 7.
- Question #332Troubleshooting and Diagnostics
When configuring the firewall for packet capture, what are the valid stage types?
packet capturestage typesfirewall stagesdrop stage - Question #333Platform Management and Monitoring
Which operation will impact performance of the management plane?
management plane performanceSaaS Application reportdata plane vs management planeresource utilization - Question #334User-ID and Identity Policy
Which User-ID method maps IP addresses to usernames for users connecting through a web proxy that has already authenticated the user?
User-IDsyslog listeningweb proxy authenticationIP-to-username mapping - Question #335Traffic Processing and Session Management
The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?
session lookup6-tuple matchnew session detectionpacket processing - Question #336GlobalProtect and Remote Access
Which GlobalProtect Client connect method requires the distribution and use of machine certificates?
GlobalProtectpre-logonmachine certificatesclient connect method - Question #337User-ID and Identity Policy
Which feature can provide NGFWs with User-ID mapping information?
User-IDGlobalProtectIP mappingidentity source - Question #338Panorama and Centralized Management
Which Panorama administrator types require the configuration of at least one access domain? (Choose two.)
Panorama administrator typesaccess domaindevice group admintemplate admin - Question #339Content and Threat Updates
Which option enables a Palo Alto Networks NGFW administrator to schedule Application and Threat updates while applying only new content IDs to traffic?
content updatesApplication and Threat updatesdisable new appsupdate scheduling - Question #340Threat Prevention and WildFire
Which is the maximum number of samples that can be submitted to WildFire per day, based on a WildFire subscription?
WildFire subscriptiondaily sample limitWildFire capacitysubmission quota - Question #341High Availability
In which two types of deployment is active/active HA configuration supported? (Choose two.)
active/active HALayer 3 modevirtual wire modeHA deployment - Question #343Decryption and SSL Inspection
Which logs enable a firewall administrator to determine whether a session was decrypted?
decryption loggingtraffic logsSSL decryptionsession visibility - Question #344Troubleshooting and Diagnostics
An administrator needs to upgrade an NGFW to the most current version of PAN-OS® software. The following is occurring: - Firewall has internet connectivity through e 1/1. - Default...
PAN-OS download errorDNS resolutionservice routeupdate server connectivity - Question #345Threat Prevention
A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks. How can the Palo Alto Ne...
DoS Protection Profilesession floodingsingle IP rate limitingNGFW threat prevention - Question #346Device Management and Operations
An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled. What must be ve...
active/passive HAPAN-OS upgradeApplications and ThreatsHA pair management - Question #347Threat Prevention
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and-contr...
Anti-Spywarecommand and controlC2 beaconingSecurity Profiles - Question #348Panorama Management
What should an administrator consider when planning to revert Panorama to a pre-PAN-OS 8.1 version?
Panorama reverttemplate variablesPAN-OS version managementpre-8.1 compatibility - Question #349Decryption and Certificate Management
Which two methods can be configured to validate the revocation status of a certificate? (Choose two.)
certificate revocationCRLOCSPPKI validation - Question #350Device Management and Administration
Which administrative authentication method supports authorization by an external service?
RADIUSadministrative authenticationexternal authorizationAAA - Question #351Threat Prevention
Which three file types can be forwarded to WildFire for analysis as a part of the basic WildFire service? (Choose three.)
WildFirebasic service file typesmalware analysisfile forwarding - Question #352High Availability
An administrator has been asked to configure active/active HA for a pair of Palo Alto Networks NGFWs. The firewall use Layer 3 interfaces to send traffic to a single gateway IP for...
active/active HAfloating IPgratuitous ARPLayer 3 HA - Question #354Panorama Management
How does Panorama prompt VMWare NSX to quarantine an infected VM?
PanoramaVMware NSX integrationVM quarantineHTTP Server Profile - Question #355Device Management and Operations
An administrator accidentally closed the commit window/screen before the commit was finished. Which two options could the administrator use to verify the progress or success of tha...
commit task verificationtask managerNGFW administrationcommit monitoring - Question #356Decryption and Certificate Management
Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)
SSL decryptionuntrusted certificatesno-decrypt policyblocking without forward proxy - Question #357Threat Prevention
An administrator is defining protection settings on the Palo Alto Networks NGFW to guard against resource exhaustion. When platform utilization is considered, which steps must the...
packet buffer protectionresource exhaustionzone protectionDoS mitigation - Question #358Decryption and Certificate Management
What is the purpose of the firewall decryption broker?
decryption brokerSSL cleartext forwardingsecurity chaininline inspection - Question #360Policy Management
What are the two behavior differences between Highlight Unused Rules and the Rule Usage Hit counter when a firewall is rebooted? (Choose two.)
Rule Usage Hit counterHighlight Unused Rulespolicy managementfirewall reboot behavior - Question #361Decryption and Certificate Management
Which is not a valid reason for receiving a decrypt-cert-validation error?
decrypt-cert-validation errorcertificate validation errorsHSMSSL decryption troubleshooting - Question #362Panorama Management
In the following image from Panorama, why are some values shown in red?
Panorama monitoringlogging rate baselineseven-day baselinemanaged device thresholds - Question #363Policy Management
The firewall is not downloading IP addresses from MineMeld. Based, on the image, what most likely is wrong?
MineMeldExternal Dynamic ListsCertificate ProfileEDL SSL connectivity - Question #364Decryption and Certificate Management
Based on the image, what caused the commit warning?
SSL Forward Proxycertificate chainFWDtrustdecryption commit warning - Question #365GlobalProtect
Which three split tunnel methods are supported by a GlobalProtect Gateway?
GlobalProtect Gatewaysplit tunneling methodsURL category split tunnelVPN traffic routing - Question #367App-ID and Security Policy Management
Starting with PAN-OS version 9.1, application dependency information is now reported in which new locations? (Choose two.)
App-IDapplication dependencyPAN-OS 9.1Security Policy - Question #368SD-WAN Configuration and Deployment
Which three items are import considerations during SD-WAN configuration planning? (Choose three.)
SD-WANnetwork planningbranch topologylink requirements - Question #369Panorama and Device Management
Which two events trigger the operation of automatic commit recovery? (Choose two.)
commit recoveryPanoramaconfiguration managementPAN-OS - Question #370SD-WAN Configuration and Deployment
Panorama provides which two SD_WAN functions? (Choose two.)
PanoramaSD-WANcontrol planenetwork monitoring