PSE-STRATA-PRO-24 Exam Questions
60 real PSE-STRATA-PRO-24 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Cloud-Delivered Security Services (CDSS)
A customer sees unusually high DNS traffic to an unfamiliar IP address. Which Palo Alto Networks Cloud-Delivered Security Services (CDSS) subscription should be enabled to further...
Advanced DNS SecurityCDSS subscriptionsDNS traffic analysisthreat detection - Question #2Zero Trust Architecture
While responding to a customer RFP, a systems engineer (SE) is presented the question, "How do PANW firewalls enable the mapping of transactions as part of Zero Trust principles?"...
Zero TrustNGFW visibilitysecurity policydecryption - Question #3Container Security
Which two files are used to deploy CN-Series firewalls in Kubernetes clusters? (Choose two.)
CN-SeriesKubernetes deploymentcontainer securityconfiguration files - Question #4Zero Trust Architecture
A current NGFW customer has asked a systems engineer (SE) for a way to prove to their internal management team that its NGFW follows Zero Trust principles. Which action should the...
Zero Trust reportingMonitor dashboardscompliance reportingNGFW management - Question #5User-ID and Identity Management
A company with Palo Alto Networks NGFWs protecting its physical data center servers is experiencing a performance issue on its Active Directory (AD) servers due to high numbers of...
Cloud Identity EngineUser-IDActive DirectoryIP-user mapping - Question #6Zero Trust Architecture
As a team plans for a meeting with a new customer in one week, the account manager prepares to pitch Zero Trust. The notes provided to the systems engineer (SE) in preparation for...
Zero Trustdiscovery questionssales methodologycustomer assessment - Question #7AIOps and Strata Cloud Manager
According to a customer's CIO, who is upgrading PAN-OS versions, "Finding issues and then engaging with your support people requires expertise that our operations team can better u...
AIOps for NGFWStrata Cloud Managercapacity planningoperational efficiency - Question #8Cloud-Delivered Security Services (CDSS)
A prospective customer is concerned about stopping data exfiltration, data infiltration, and command-and-control (C2) activities over port 53. Which subscription(s) should the syst...
DNS SecurityC2 detectiondata exfiltrationport 53 - Question #9Advanced Threat Prevention
Which statement appropriately describes performance tuning Intrusion Prevention System (IPS) functions on a Palo Alto Networks NGFW running Advanced Threat Prevention?
Advanced Threat PreventionIPS tuningthreat profilesperformance optimization - Question #10Strata Cloud Manager and AIOps
A systems engineer (SE) successfully demonstrates NGFW managed by Strata Cloud Manager (SCM) to a company. In the resulting planning phase of the proof of value (POV), the CISO req...
Security Lifecycle ReviewStrata Cloud ManagerPOV testingcompliance standards - Question #11Security Policy Management
Which three use cases are specific to Policy Optimizer? (Choose three.)
Policy Optimizerapplication-based policyport-based rulesrule migration - Question #12Cloud-Delivered Security Services (CDSS)
A systems engineer should create a profile that blocks which category to protect a customer from ransomware URLs by using Advanced URL Filtering?
Advanced URL FilteringransomwareURL categoriesthreat prevention - Question #13Cloud-Delivered Security Services (CDSS)
Which technique is an example of a DNS attack that Advanced DNS Security can detect and prevent?
Advanced DNS Securityhigh entropy domainsDNS tunnelingDNS attacks - Question #14Advanced Threat Prevention
A security engineer has been tasked with protecting a company's on-premises web servers but is not authorized to purchase a web application firewall (WAF). Which Palo Alto Networks...
Advanced Threat Preventionweb application securitySQL injectionXSS protection - Question #15Advanced Threat Prevention
When a customer needs to understand how Palo Alto Networks NGFWs lower the risk of exploitation by newly announced vulnerabilities known to be actively attacked, which solution and...
Advanced Threat Preventionzero-day vulnerabilitiesinline deep learningvirtual patching - Question #16User-ID and Identity Management
Which two methods are valid ways to populate user-to-IP mappings? (Choose two.)
User-IDXML APIIP-user mappingidentity management - Question #17Panorama Management
What are three valid Panorama deployment options? (Choose three.)
Panoramadeployment optionsvirtual machinehardware appliance - Question #18Security Policy Management
What does Policy Optimizer allow a systems engineer to do for an NGFW?
Policy Optimizerunused applicationssecurity policyrule cleanup - Question #19Advanced Threat Prevention
What is the minimum configuration to stop a Cobalt Strike Malleable C2 attack inline and in real time?
Advanced Threat PreventionCobalt StrikeC2 preventioninline ML - Question #20AIOps and Strata Cloud Manager
Which two statements clarify the functionality and purchase options for Palo Alto Networks AIOps for NGFW? (Choose two.)
AIOps for NGFWlicense tiersmachine learningtelemetry - Question #21Pre-Sales and Assessment Tools
In which two locations can a Best Practice Assessment (BPA) report be generated for review by a customer? (Choose two.)
BPApartner portalcustomer support portalreporting tools - Question #22Pre-Sales and Assessment Tools
Which two tools should a systems engineer use to showcase the benefit of an evaluation that a customer has just concluded?
BPASLRpost-evaluationsales engineering - Question #23Threat Prevention
What is used to stop a DNS-based threat?
DNS securityDNS sinkholingthreat preventionDNS threats - Question #24Identity and Access Management
A company with a large Active Directory (AD) of over 20,000 groups has user roles based on group membership in the directory. Up to 1,000 groups may be used in Security policies. T...
Active Directorygroup mappingUser-IDLDAP - Question #25Zero Trust Architecture
Which two actions should a systems engineer take when a customer is concerned about how to remain aligned to Zero Trust principles as they adopt additional security features over t...
Zero TrustdecryptionBPAsecurity posture - Question #26Pre-Sales and Assessment Tools
Which three tools can a prospective customer use to evaluate Palo Alto Networks products to assess where they will fit in the existing architecture? (Choose three)
POCSLRUltimate Test Driveevaluation tools - Question #27Platform Sizing and Deployment
Which two statements correctly describe best practices for sizing a firewall deployment with decryption enabled? (Choose two.)
SSL decryptionPFSfirewall sizingcryptography - Question #28Cloud-Delivered Security Services
While a quote is being finalized for a customer that is purchasing multiple PA-5400 series firewalls, the customer specifies the need for protection against zero-day malware attack...
Advanced WildFirezero-day malwareCDSSthreat prevention - Question #29Network Architecture and Routing
A prospective customer is interested in Palo Alto Networks NGFWs and wants to evaluate the ability to segregate its internal network into unique BGP environments. Which statement d...
BGPeBGPnetwork segmentationrouting - Question #30Cloud-Delivered Security Services
In addition to Advanced DNS Security, which three Cloud-Delivered Security Services (CDSS) subscriptions utilize inline machine learning (ML)? (Choose three)
inline MLCDSSAdvanced URL FilteringAdvanced Threat Prevention - Question #31Strata Cloud Manager
Which two compliance frameworks are included with the Premium version of Strata Cloud Manager (SCM)? (Choose two)
SCMcompliancePCICIS - Question #32NGFW Deployment Scenarios
Which use case is valid for Palo Alto Networks Next-Generation Firewalls (NGFWs)?
NGFW use casesIT/OT segmentationoperational technologynetwork security - Question #33SASE Architecture and Deployment
What would make a customer choose an on-premises solution over a cloud-based SASE solution for their network?
SASEon-premisesdeployment strategyarchitecture decision - Question #34Cloud-Delivered Security Services
In addition to DNS Security, which three Cloud-Delivered Security Services (CDSS) subscriptions are minimum recommendations for all NGFWs that handle north-south traffic? (Choose t...
CDSSnorth-south trafficAdvanced WildFireAdvanced URL Filtering - Question #35Network Architecture and Routing
A systems engineer (SE) has joined a team to work with a managed security services provider (MSSP) that is evaluating PAN-OS for edge connections to their customer base. The MSSP i...
advanced routinglogical routersBGPMSSP - Question #36Platform Sizing and Deployment
A customer has acquired 10 new branch offices, each with fewer than 50 users and no existing firewall. The systems engineer wants to recommend a PA-Series NGFW with Advanced Threat...
PA-400hardware sizingbranch officeNGFW selection - Question #37Strata Cloud Manager
Which two products can be integrated and managed by Strata Cloud Manager (SCM)? (Choose two)
SCMPrisma SD-WANVM-Seriesproduct integration - Question #38Zero Trust Architecture
What are the first two steps a customer should perform as they begin to understand and adopt Zero Trust principles? (Choose two)
Zero Trustasset inventorytransaction mappingadoption framework - Question #39Policy Management and Migration
Which action can help alleviate a prospective customer's concerns about transitioning from a legacy firewall with port-based policies to a Palo Alto Networks NGFW with application-...
Policy OptimizerApp-IDpolicy migrationport-based rules - Question #40Identity and Access Management
A company plans to deploy identity for improved visibility and identity-based controls for least privilege access to applications and data. The company does not have an on-premises...
identityGlobalProtectCloud Identity EngineEntra ID - Question #41Cloud Security and Deployment
A systems engineer (SE) is working with a customer that is fully cloud-deployed for all applications. The customer is interested in Palo Alto Networks NGFWs but describes the follo...
Cloud NGFWVM-SeriesPanoramamulti-cloud deployment - Question #42Cloud-Delivered Security Services
A customer claims that Advanced WildFire miscategorized a file as malicious and wants proof, because another vendor has said that the file is benign. How could the systems engineer...
Advanced WildFireWildFire Analysis Reportthreat logfile analysis - Question #43NGFW Hardware Sizing
Which three known variables can assist with sizing an NGFW appliance? (Choose three.)
NGFW sizingconnections per secondmax sessionsApp-ID throughput - Question #44Security Policy Configuration
Which statement applies to the default configuration of a Palo Alto Networks NGFW?
Security policyinterzone denydefault configurationimplicit trust - Question #45Remote Access and Identity
A company has multiple business units, each of which manages its own user directories and identity providers (IdPs) with different domain names. The company's network security team...
GlobalProtectSAMLauthentication profilesmulti-IdP - Question #46Device-ID Policy Enforcement
Device-ID can be used in which three policies? (Choose three.)
Device-IDSecurity policyPBFQoS - Question #47NGFW Hardware Architecture and Design
A prospective customer wants to validate an NGFW solution and seeks the advice of a systems engineer (SE) regarding a design to meet the following stated requirements: "We need an...
PA-5445NGFW hardware sizingaggregate interfacestransparent deployment - Question #48IoT and 5G Security
The efforts of a systems engineer (SE) with an industrial mining company account have yielded interest in Palo Alto Networks as part of its effort to incorporate innovative design...
5G SecurityIoT SecurityOT securitycloud application protection - Question #49Logging and Reporting
There are no Advanced Threat Prevention log events in a company's SIEM instance. However, the systems administrator has confirmed that the Advanced Threat Prevention subscription i...
Advanced Threat Preventionlog forwardingSIEM integrationSecurity policy - Question #50NGFW Architecture
A customer asks a systems engineer (SE) how Palo Alto Networks can claim it does not lose throughput performance as more Cloud-Delivered Security Services (CDSS) subscriptions are...
Single Pass ArchitectureCDSSparallel processingfirewall performance