PSE-STRATA Exam Questions
229 real PSE-STRATA exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #154Cloud Security Administration
An Administrator needs a PDF summary report that contains information compiled from existing reports based on data for the Top five(5) in each category. Which two timeframe options...
Report SchedulingPDF SummariesSecurity AnalyticsAdministration - Question #155Logging and Monitoring
The firewall includes predefined reports, custom reports can be built for specific data and actionable tasks, or predefined and custom reports can be combined to compile informatio...
Firewall ReportingNetwork MonitoringThreat IntelligenceSecurity Analytics - Question #156Pre-Sales Methodology
Which Palo Alto Networks pre-sales tool involves approximately 4 hour interview to discuss a customer's current security posture?
pre-sales assessmentsecurity posture evaluationBPAcustomer engagement - Question #157Threat Prevention
Access to a business site is blocked by URL Filtering inline machine learning (ML) and considered as a false-positive. How should the site be made available?
URL FilteringInline MLSecurity PolicyException Handling - Question #158High Availability and Redundancy Design
Which two features can be enabled to support asymmetric routing with redundancy on a Palo Alto networks next-generation firewall (NGFW)? (Choose two.)
High AvailabilityAsymmetric RoutingActive/Active HANon-SYN First Packet - Question #159Identity and Access Management
Which three mechanisms are valid for enabling user mapping? (Choose three.)
User MappingClient IdentificationCaptive PortalDomain Monitoring - Question #160Threat Prevention
Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)
Credential Phishing PreventionUser IdentificationURL FilteringThreat Detection - Question #161Identity and Access Management
Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
MFACredential Abuse PreventionAccess ControlURL Filtering - Question #162Threat Prevention
What are two benefits of the sinkhole Internet Protocol (IP) address that DNS Security sends to the client in place of malicious IP addresses? (Choose two.)
DNS SecurityThreat RedirectionDNS SinkholingNetwork Defense - Question #163Network Security
A customer worried about unknown attacks is hesitant to enable SSL decryption due to privacy and regulatory issues. How does the platform address the customer's concern?
SSL InspectionURL ExclusionPrivacy ControlsCompliance - Question #164Threat Prevention
WildFire machine learning (ML) for portable executable (PE) files is enabled in the antivirus profile and added to the appropriate firewall rules in the profile. In the Palo Alto N...
WildFire MLCLI CommandsAntivirus ConfigurationPE File Detection - Question #165Advanced Threat Prevention Services
A Fortune 500 customer has expressed interest in purchasing WildFire; however, they do not want to send discovered malware outside of their network. Which version of WildFire will...
WildFireCloud Deployment ModelsThreat PreventionOn-Premises Security - Question #166Identity and Access Management
Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?
Dynamic User GroupsTag-based User SegmentationUser Identity ManagementAccess Control - Question #167
A customer is starting to understand their Zero Trust protect surface using the Palo Alto Networks Zero Trust reference architecture. What are two steps in this process? (Choose tw...
- Question #168Identity and Access Management
Which proprietary technology solutions will allow a customer to identify and control traffic sources regardless of internet protocol (IP) address or network segment?
User IdentificationDevice IdentificationTraffic ControlIdentity-Based Security - Question #169URL Filtering
When HTTP header logging is enabled on a URL Filtering profile, which attribute-value can be logged?
URL filteringHTTP header loggingX-Forwarded-ForPAN-OS - Question #170Security Engine Architecture
Which statement applies to Palo Alto Networks Single Pass Parallel Processing (SP3)?
Single Pass Parallel ProcessingPerformance OptimizationTraffic ProcessingSecurity Engine Architecture - Question #171Threat Prevention
WildFire can discover zero-day malware in which three types of traffic? (Choose three)
WildFirezero-day detectionmalware inspectionprotocol inspection - Question #172Threat Detection and Response
In Panorama, which three reports or logs will help identify the inclusion of a host source in a command-and-control (C2) incident? (Choose three.)
Panorama ReportingC2 DetectionThreat LogsWildFire Analysis - Question #173Threat Defense and Prevention
What is the recommended way to ensure that firewalls have the most current set of signatures for up-to-date protection?
signature updatesdynamic updatesfirewall maintenancethreat defense - Question #174Threat Prevention
Which of the following statements is valid with regard to Domain Name System (DNS) sinkholing?
DNS sinkholinganti-spywarebotnet detectioninfected host identification - Question #175Network Security and Threat Prevention
A customer with a fully licensed Palo Alto Networks firewall is concerned about threats based on domain generation algorithms (DGAS). Which Security profile is used to configure Do...
DNS SecurityAnti-SpywareDGA DetectionThreat Prevention - Question #176
Which three actions should be taken before deploying a firewall evaluation unt in a customer environment? (Choose three.)
- Question #177Firewall Administration and Deployment
Which statement best describes the business value of Palo Alto Networks Zero Touch Provisioning (ZTP)?
Zero Touch ProvisioningFirewall DeploymentPanorama ManagementDevice Onboarding - Question #178Threat Prevention
In PAN-OS 10.0 and later, DNS Security allows policy actions to be applied based on which three domains? (Choose three.)
DNS Securitythreat categoriesC2 detectionmalware domains - Question #179Security Architecture
What will best enhance security of a production online system while minimizing the impact for the existing network?
virtual wire deploymenttransparent firewallingnetwork integrationsecurity insertion - Question #180Threat Prevention
Which Security profile on the Next-Generation Firewall (NGFW) includes Signatures to protect against brute force attacks?
Vulnerability ProtectionNGFW Security ProfilesAttack SignaturesBrute Force Protection - Question #181
A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but can...
- Question #182
Which solution informs a customer concerned about zero-day targeted attacks whether an attack is specifically targeted at its property?
- Question #183
A customer requires protections and verdicts for portable executable (PE) and executable and linkable format (ELF), as well as the ability to integrate with existing security tools...
- Question #184
A WildFire subscription is required for which two of the following activities? (Choose two)
- Question #185
Within the Five-Step Methodology of Zero Trust, in which step would application access and user access be defined?
- Question #186
Which two features are key in preventing unknown targeted attacks? (Choose two)
- Question #187
A customer is designing a private data center to host their new web application along with a separate headquarters for users. Which cloud-delivered security service (CDSS) would be...
- Question #188Threat Prevention
Which two methods are used to check for Corporate Credential Submissions? (Choose two.)
credential theft preventionDomain Credential FilterIP-user mappingphishing protection - Question #189
Which CLI command allows visibility into SD-WAN events such as path Selection and path quality measurements?
- Question #190Threat Prevention
A customer requires an analytics tool with the following attributes: - Uses the logs on the firewall to detect actionable events on the network - Automatically processes a series o...
Automated Correlation Enginecompromised host detectionthreat analyticslog analysis - Question #191
What are three key benefits of the Palo Alto Networks platform approach to security? (Choose three)
- Question #192
Which Palo Alto Networks security component should an administrator use to and NGFW policies to remote users?
- Question #193
The ability to prevent users from resolving internet protocol (IP) addresses to malicious, grayware, or newly registered domains is provided by which Security service?
- Question #194
in which step of the Palo Alto Networks Five-Step Zero Trust Methodology would an organization's critical data, applications, assets, and services (DAAS) be identified?
- Question #195
Which built-in feature of PAN-OS allows the NGFW administrator to create a policy that provides autoremediation for anomalous user behavior and malicious activity while maintaining...
- Question #196
What will a Palo Alto Networks next-generation firewall (NGFW) do when it is unable to retrieve a DNS verdict from the DNS cloud service in the configured lookup time?
- Question #197
What is the default behavior in PAN-OS when a 12 MB portable executable (PE) fe is forwarded to the WildFire cloud service?
- Question #198
What is an advantage of having WildFire machine learning (ML) capability Inline on the firewall?
- Question #199
Which three script types can be analyzed in WildFire? (Choose three)
- Question #200
What are two ways to manually add and remove members of dynamic user groups (DUGs)? (Choose two)
- Question #201
A packet that is already associated with a current session arrives at the firewall. What is the flow of the packet after the firewall determines that it is matched with an existing...
- Question #202
What helps avoid split brain in active / passive high availability (HA) pair deployment?
- Question #203Identity and Access Management
The Palo Ao Networks Cloud Identity Engino (CIE) includes which service that supports identity Providers (ldP)?
Cloud Identity EngineDirectory SyncCloud Authentication ServiceSAML 2.0