PSE-STRATA Exam Questions
229 real PSE-STRATA exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1
What is the key benefit of Palo Alto Networks Single Pass Parallel Processing design?
- Question #2
Which security profile on the NGFW includes signatures to protect you from brute force attacks?
- Question #3NGFW Architecture and Content Security
The need for a file proxy solution, virus and spyware scanner, a vulnerability scanner, and HTTP decoder for URL filtering is handled by which component in the NGFW?
NGFW architecturestream-based signature enginecontent inspectionURL filtering - Question #4Threat Prevention and WildFire
A customer is looking for an analytics tool that uses the logs on the firewall to detect actionable events on the network. They require something to automatically process a series...
Automated Correlation Enginethreat correlationcompromised host detectionPAN-OS analytics - Question #5
Which two email links, contained in SMTP and POP3, can be submitted from WildFire analysis with a WildFire subscription? (Choose two.)
- Question #6
What two types of certificates are used to configure SSL Forward Proxy? (hoose two.)
- Question #7Decryption and SSL Inspection
Which two of the following does decryption broker provide on a NGFW? (Choose two.)
decryption brokerSSL decryptionNGFWthird-party integration - Question #8
There are different Master Keys on Panorama and managed firewalls. What is the result if a Panorama Administrator pushes configuration to managed firewalls?
- Question #9Device Management and Configuration
Which task would be identified in Best Practice Assessment tool?
Best Practice Assessmentdevice managementsecurity recommendationsBPA tool - Question #10
A customer requests that a known spyware threat signature be triggered based on a rate of occurrence, for example, 10 hits in 5 seconds. How is this goal accomplished?
- Question #11
Which two features are found in Palo Alto Networks NGFW but are absent in a legacy firewall product? (Choose two.)
- Question #12
For customers with high bandwidth requirements for Service Connections, what two limitations exist when onboarding multiple Service Connections to the same Prisma Access location s...
- Question #13
Which three categories are identified as best practices in the Best Practice Assessment tool? (Choose three.)
- Question #14
You have a prospective customer that is looking for a way to provide secure temporary access to contractors for a designated period of time. They currently add contractors to exist...
- Question #15User-ID and Credential Protection
Which methods are used to check for Corporate Credential Submissions? (Choose three.)
credential submissioncorporate credential protectionUser-IDdomain credential filter - Question #16Threat Prevention and WildFire
WildFire subscription supports analysis of which three types? (Choose three.)
WildFirefile type supportmalware analysissubscription features - Question #17Threat Prevention and WildFire
The WildFire Inline Machine Learning is configured using which Content-ID profiles?
WildFire Inline MLmachine learningantivirus profileContent-ID - Question #18High Availability
In an HA pair running Active/Passive mode, over which interface do the dataplanes communicate?
high availabilityHA2 interfaceActive/Passivedataplane sync - Question #19
A potential customer requires an NGFW solution which enables high-throughput, low-latency network security, all while incorporating unprecedented features and technology. They need...
- Question #20User-ID and Credential Protection
What filtering criteria is used to determine what users to include as members of a dynamic user group?
dynamic user groupstagsUser-IDpolicy membership - Question #21User-ID and Credential Protection
Which three features are used to prevent abuse of stolen credentials? (Choose three.)
credential theft preventionMFAURL filteringSSL decryption - Question #22
A customer has business-critical applications that rely on the general web-browsing application. Which security profile can help prevent drive-by-downloads while still allowing web...
- Question #23User-ID and Credential Protection
Which three settings must be configured to enable Credential Phishing Prevention? (Choose three.)
credential phishing preventionUser-IDSSL decryptionURL filtering profile - Question #24
A customer with a legacy firewall architecture is focused on port and protocol level security, and has heard that next generation firewalls open all ports by default. What is the a...
- Question #25Threat Prevention and WildFire
Which four actions can be configured in an Anti-Spyware profile to address command-and-control traffic from compromised hosts? (Choose four.)
anti-spyware profilecommand-and-controlthreat actionscompromised hosts - Question #26
What are three valid sources that are supported for user IP address mapping in Palo Alto Networks NGFW? (Choose three.)
- Question #27SD-WAN
Which CLI allows you to view the names of SD-WAN policy rules that send traffic to the specified virtual SD-WAN interface, along with the performance metrics?
SD-WANCLI commandspolicy rulesvirtual interface metrics - Question #28Threat Prevention and WildFire
Which two actions can be taken to enforce protection from brute force attacks in the security policy? (Choose two.)
brute force protectionvulnerability profilecontent updatessecurity policy - Question #29Threat Intelligence and Cortex
A customer is concerned about zero-day targeted attacks against its intellectual property. Which solution informs a customer whether an attack is specifically targeted at them?
AutoFocuszero-day attackstargeted threat intelligenceintellectual property protection - Question #30Panorama and Centralized Management
Which is the smallest Panorama solution that can be used to manage up to 2500 Palo Alto Networks Next Generation firewalls?
Panoramafirewall managementVM-Seriesscalability - Question #31Threat Prevention and WildFire
Which three activities can the botnet report track? (Choose three.)
botnet reportmalicious URLdynamic DNSthreat tracking - Question #32Threat Prevention and WildFire
A customer requires protections and verdicts for PE (portable executable) and ELF (executable and linkable format) as well as integration with products and services can also access...
WildFirePE filesELF filesverdict integration - Question #33SD-WAN
Which statement is true about Deviating Devices and metrics?
deviating devicesmetric health baselineSD-WAN monitoringperformance metrics - Question #34Threat Prevention and WildFire
Palo Alto Networks publishes updated Command-and-Control signatures. How frequently should the related signatures schedule be set?
C2 signaturescontent updatesupdate schedulethreat prevention - Question #35High Availability
Which two methods will help avoid Split Brain when running HA in Active/Active mode? (Choose two.)
split brain preventionHA Active/Activeheartbeat backupHA1 interface - Question #36WildFire and Threat Prevention
Which three script types can be analyzed in WildFire? (Choose three.)
WildFirescript analysisfile typesthreat prevention - Question #37High Availability
What helps avoid split brain in active/passive HA pair deployment?
High Availabilitysplit brainHA1 backup linkactive/passive HA - Question #38User-ID
What are three considerations when deploying User-ID? (Choose three.)
User-IDdeployment best practiceszone configurationservice account - Question #39Decryption
Which three considerations should be made prior to installing a decryption policy on the NGFW? (Choose three.)
SSL decryptiondecryption policydeployment considerationsthroughput - Question #40Logging and Reporting
Which three components are specific to the Query Builder found in the Custom Report creation dialog of the firewall? (Choose three.)
custom reportsQuery Builderloggingmonitoring - Question #41SD-WAN
Which CLI commands allows you to view SD-WAN events such as path selection and path quality measurements?
SD-WANCLI commandspath selectionpath quality - Question #42
Which three steps in the cyberattack lifecycle does Palo Alto Networks Security Operating Platform prevent? (Choose three.)
- Question #43Network Security and Threat Prevention
Which profile or policy should be applied to protect against port scans from the internet?
Zone Protection Profileport scanDoS protectioningress zone - Question #44Platform and Product Portfolio
Which two products are included in the Prisma Brand? (Choose two.)
Prisma Cloudproduct portfolioPalo Alto Networkscloud security - Question #45WildFire and Threat Prevention
Which three platform components can identify and protect against malicious email links? (Choose three.)
WildFireemail securitymalicious linkscloud deployment - Question #46NGFW Fundamentals
When having a customer pre-sales call, which aspects of the NGFW should be covered?
NGFWURL filteringpre-salesproduct positioning - Question #47User-ID
What aspect of PAN-OS allows for the NGFW admin to create a policy that provides auto- remediation for anomalous user behavior and malicious activity while maintaining user visibil...
Dynamic User Groupsauto-remediationuser behavior analyticspolicy enforcement - Question #48
You have enabled the WildFire ML for PE files in the antivirus profile and have added the profile to the appropriate firewall rules. When you go to Palo Alto Networks WildFire test...
- Question #49
What action would address the sub-optimal traffic path shown in the figure? Key: RN -Remote Network SC -Service Connection MU GW -Mobile User Gateway
- Question #50WildFire and Threat Prevention
What are the three possible verdicts in WildFire Submissions log entries for a submitted sample? (Choose four.)
WildFireverdictsmalware analysissubmission log