Palo Alto PSE strata UPDATED ACTUAL
Exam Questions and CORRECT Answers
What are three sources of malware sample data for the Threat Intelligence Cloud? (Choose three)
A. Next-generation firewalls deployed with WildFire Analysis Security Profiles
B. WF-500 configured as private clouds for privacy concerns
C. Correlation Objects generated by AutoFocus
D. Third-party data feeds such as partnership with ProofPomt and the Cyber Threat Alliance
E.Palo Alto Networks non-firewall products such as Traps and Prisma SaaS - CORRECT
ANSWER - cde
What are two core values of the Palo Alto Network Security Operating Platform? (Choose two.}
A. prevention of cyber attacks
B. safe enablement of all applications
C. threat remediation
D. defense against threats with static security solution - CORRECT ANSWER - ac
What are two advantages of the DNS Sinkholing feature? (Choose two.)
A. It forges DNS replies to known malicious domains.
B. It monitors DNS requests passively for malware domains.
C. It can be deployed independently of an Anti-Spyware Profile.
D. It can work upstream from the internal DNS server. - CORRECT ANSWER - ad
Which two products can send logs to the Cortex Data Lake? (Choose two.)
A. AutoFocus
B. PA-3260 firewall
C. Prisma Access
D. Prisma Public Cloud - CORRECT ANSWER - bc
,Which two components must be configured within User-ID on a new firewall that has been
implemented? (Choose two.)
A. User Mapping
B. Proxy Authentication
C. Group Mapping
D. 802.1X Authentication - CORRECT ANSWER - ac
Which four steps of the cyberattack lifecycle does the Palo Alto Networks Security Operating
Platform prevent? (Choose four.)
A. breach the perimeter
B. weaponize vulnerabilities
C. lateral movement
D. exfiltrate data
E. recon the target
F.deliver the malware - CORRECT ANSWER - acdf
Which three settings must be configured to enable Credential Phishing Prevention? (Choose
three.)
A. define an SSL decryption rulebase
B. enable User-ID
C. validate credential submission detection
D. enable App-ID
E. define URL Filtering Profile - CORRECT ANSWER - bce
An SE is preparing an SLR report for a school and wants to emphasize URL filtering capabilities
because the school is concerned that its students are accessing inappropriate websites. The URL
categories being chosen by default in the report are not highlighting these types of websites. How
should the SE show the customer the firewall can detect that these websites are being accessed?
A. Create a footnote within the SLR generation tool
, B. Edit the Key-Findings text to list the other types of categories that may be of interest
C. Remove unwanted categories listed under 'High Risk' and use relevant information
D.Produce the report and edit the PDF manually - CORRECT ANSWER -c
Which three methods used to map users to IP addresses are supported in Palo Alto Networks
firewalls? (Choose three.)
A. eDirectory monitoring
B. Client Probing
C. SNMP server
D. TACACS
E. Active Directory monitoring
F. Lotus Domino
G. RADIUS - CORRECT ANSWER - bdg
When the Cortex Data Lake is sized for Traps Management Service, which two factors should be
considered? (Choose two.)
A. retention requirements
B. Traps agent forensic data
C. the number of Traps agents
D. agent size and OS - CORRECT ANSWER - bd
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to
secure data center traffic? (Choose two.)
A. It can provide the Automated Correlation Engine functionality, which the virtual firewalls do
not support.
B. It can monitor the virtual firewalls' physical hosts and Vmotion them as necessary
C. It can automatically create address groups for use with KVM.
D. It can bootstrap the virtual firewalls for dynamic deployment scenarios. - CORRECT
ANSWER - ad
Exam Questions and CORRECT Answers
What are three sources of malware sample data for the Threat Intelligence Cloud? (Choose three)
A. Next-generation firewalls deployed with WildFire Analysis Security Profiles
B. WF-500 configured as private clouds for privacy concerns
C. Correlation Objects generated by AutoFocus
D. Third-party data feeds such as partnership with ProofPomt and the Cyber Threat Alliance
E.Palo Alto Networks non-firewall products such as Traps and Prisma SaaS - CORRECT
ANSWER - cde
What are two core values of the Palo Alto Network Security Operating Platform? (Choose two.}
A. prevention of cyber attacks
B. safe enablement of all applications
C. threat remediation
D. defense against threats with static security solution - CORRECT ANSWER - ac
What are two advantages of the DNS Sinkholing feature? (Choose two.)
A. It forges DNS replies to known malicious domains.
B. It monitors DNS requests passively for malware domains.
C. It can be deployed independently of an Anti-Spyware Profile.
D. It can work upstream from the internal DNS server. - CORRECT ANSWER - ad
Which two products can send logs to the Cortex Data Lake? (Choose two.)
A. AutoFocus
B. PA-3260 firewall
C. Prisma Access
D. Prisma Public Cloud - CORRECT ANSWER - bc
,Which two components must be configured within User-ID on a new firewall that has been
implemented? (Choose two.)
A. User Mapping
B. Proxy Authentication
C. Group Mapping
D. 802.1X Authentication - CORRECT ANSWER - ac
Which four steps of the cyberattack lifecycle does the Palo Alto Networks Security Operating
Platform prevent? (Choose four.)
A. breach the perimeter
B. weaponize vulnerabilities
C. lateral movement
D. exfiltrate data
E. recon the target
F.deliver the malware - CORRECT ANSWER - acdf
Which three settings must be configured to enable Credential Phishing Prevention? (Choose
three.)
A. define an SSL decryption rulebase
B. enable User-ID
C. validate credential submission detection
D. enable App-ID
E. define URL Filtering Profile - CORRECT ANSWER - bce
An SE is preparing an SLR report for a school and wants to emphasize URL filtering capabilities
because the school is concerned that its students are accessing inappropriate websites. The URL
categories being chosen by default in the report are not highlighting these types of websites. How
should the SE show the customer the firewall can detect that these websites are being accessed?
A. Create a footnote within the SLR generation tool
, B. Edit the Key-Findings text to list the other types of categories that may be of interest
C. Remove unwanted categories listed under 'High Risk' and use relevant information
D.Produce the report and edit the PDF manually - CORRECT ANSWER -c
Which three methods used to map users to IP addresses are supported in Palo Alto Networks
firewalls? (Choose three.)
A. eDirectory monitoring
B. Client Probing
C. SNMP server
D. TACACS
E. Active Directory monitoring
F. Lotus Domino
G. RADIUS - CORRECT ANSWER - bdg
When the Cortex Data Lake is sized for Traps Management Service, which two factors should be
considered? (Choose two.)
A. retention requirements
B. Traps agent forensic data
C. the number of Traps agents
D. agent size and OS - CORRECT ANSWER - bd
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to
secure data center traffic? (Choose two.)
A. It can provide the Automated Correlation Engine functionality, which the virtual firewalls do
not support.
B. It can monitor the virtual firewalls' physical hosts and Vmotion them as necessary
C. It can automatically create address groups for use with KVM.
D. It can bootstrap the virtual firewalls for dynamic deployment scenarios. - CORRECT
ANSWER - ad