Home » Exams » Palo Alto Networks Dumps » Exam PSE-SoftwareFirewall: Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional
Exam PSE-SoftwareFirewall: Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional
Exam Number: PSE-SoftwareFirewall |
Length of test: 120 mins |
Exam Name: Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional |
Number of questions in the actual exam: 50 |
Format: PDF, VPLUS |
Passing Score: +70% |
Download practice test questions
Some questions:
Q
Which three NSX features can be pushed from Panorama in PAN-OS? (Choose three.)
A. Multiple authorization codes
B. User IP mappings
C. Steering rules
D. Security group assignment of virtual machines (VMs)
D. Security groups
Q
Which two mechanisms could trigger a high availability (HA) failover event? (Choose two.)
A. Ping monitoring
B. Link monitoring
C. Session polling
D. Heartbeat polling
Q
How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?
A. It must be deployed as a member of a device cluster.
B. It must be identified as a default gateway.
C. It must receive all forwarding lookups from the network controller.
D. It must use a Layer 3 underlay network.
Q
Which two elements of the Palo Alto Networks platform architecture enable security orchestration in a software-defined network (SDN)? (Choose two.)
A. NVGRE support for advanced VLAN integration
B. Full set of APIs enabling programmatic control of policy and configuration
C. VXLAN support for network-layer abstraction
D. Dynamic Address Groups to adapt Security policies dynamically
Q
What do tags allow a VM-Series firewall to do in a virtual environment?
A. Integrate with security information and event management (SIEM) solutions.
B. Enable machine learning (ML).
C. Provide adaptive reporting.
D. Adapt Security policy rules dynamically.
Q
A customer in a VMware ESXi environment wants to add a VM-Series firewall and partition an existing group of virtual machines (VMs) in the same subnet into two groups. One group requires no additional security, but the second group requires substantially more security.
How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?
A. Edit the IP address of all of the affected VMs.
B. Create a new virtual switch and use the VM-Series firewall to separate virtual switches using virtual wire mode. Then move the guests that require more security into the new virtual switch.
C. Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete it.
D. Create a Layer 3 interface in the same subnet as the VMs and then configure proxy Address Resolution Protocol (ARP).
Q
Which software firewall would help a prospect interested in securing an environment with Kubernetes?
A. ML-Series
B. CN-Series
C. KN-Series
D. VM-Series
Q
What is the appropriate file format for Kubernetes applications?
A. .yaml
B. .exe
C. Json
D. .xml
…………….