Pass the Paloalto Networks PSE-Software Firewall Professional PSE-SoftwareFirewall Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

When implementing active-active high availability (HA), which feature must be configured to allow the HA pair to share a single IP address that may be used as the network's gateway IP address?

Options:

A.

Floating IP address


B.

VRRP


C.

ARP load sharing


D.

HSRP


Questions # 2:

Which two valid components are used in installation of a VM-Series firewall in an OpenStack environment? (Choose two.)

Options:

A.

VM-Series VHD image


B.

OpenStack heat template in JSON format


C.

VM-Series qcow2 image


D.

OpenStack heat template in YAML Ain’t Markup Language (YAML) format


Questions # 3:

Which element protects and hides an internal network in an outbound flow?

Options:

A.

DNS sinkholing


B.

NAT


C.

User-ID


D.

App-ID


Questions # 4:

Which two configuration options does Palo Alto Networks recommend for outbound high availability (HA) design in Amazon Web Services using a VM-Series firewall? (Choose two.)

Options:

A.

Traditional active-active HA


B.

Transit gateway and Security VPC


C.

Traditional active-passive HA


D.

Transit VPC and Security VPC


Questions # 5:

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

Options:

A.

Threat Prevention


B.

SD-WAN


C.

Intelligent Traffic Offload


D.

WildFire


Questions # 6:

What must be enabled when using Terraform templates with a Cloud next-generation firewall (NGFW) for Amazon Web Services (AWS)?

Options:

A.

Access to the Cloud NGFW for AWS console


B.

AWS Firewall Manager console access


C.

AWS CloudWatch logging


D.

Access to the Palo Alto Networks Customer Support Portal


Questions # 7:

How does a CN-Series firewall prevent exfiltration?

Options:

A.

It distributes incoming virtual private cloud (VPC) traffic across the pool of VM-Series firewalls.


B.

It inspects outbound traffic content and blocks suspicious activity.


C.

It provides a license deactivation API key.


D.

It employs custom-built signatures based on hash.


Questions # 8:

Which offering inspects encrypted outbound traffic?

Options:

A.

TLS decryption


B.

Content-ID


C.

Advanced URL Filtering (AURLF)


D.

WildFire


Questions # 9:

What are two requirements for automating service deployment of a VM-Series firewall from an NSX Manager? (Choose two.)

Options:

A.

Panorama has been configured to recognize both the NSX Manager and vCenter.


B.

vCenter has been given Palo Alto Networks subscription licenses for VM-Series firewalls.


C.

The deployed VM-Series firewall can establish communications with Panorama.


D.

Panorama can establish communications to the public Palo Alto Networks update servers.


Questions # 10:

Which offering can gain visibility and prevent an attack by a malicious actor attempting to exploit a known web server vulnerability using encrypted communication?

Options:

A.

OCSP


B.

Advanced URL Filtering (AURLF)


C.

Secure Sockets Layer (SSL) Inbound Inspection


D.

WildFire


Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions