Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

PSE-SoftwareFirewall Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional Questions and Answers

Questions 4

Which two routing options are supported by VM-Series? (Choose two.)

Options:

A.

RIP

B.

OSPF

C.

IGRP

D.

BGP

Buy Now
Questions 5

A customer in a VMware ESXi environment wants to add a VM-Series firewall and partition an existing group of virtual machines (VMs) in the same subnet into two groups. One group requires no additional security, but the second group requires substantially more security.

How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?

Options:

A.

Edit the IP address of all of the affected VMs.

B.

Create a new virtual switch and use the VM-Series firewall to separate virtual switches using virtual wire mode. Then move the guests that require more security into the new virtual switch.

C.

Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete it.

D.

Create a Layer 3 interface in the same subnet as the VMs and then configure proxy Address Resolution Protocol (ARP).

Buy Now
Questions 6

What Palo Alto Networks software firewall protects Amazon Web Services (AWS) deployments with network security delivered as a managed cloud service?

Options:

A.

Ion-Series Ion-Series

B.

CN-Series

C.

Cloud next-generation firewall (NGFW)

D.

VM-Series

Buy Now
Questions 7

Which three NSX features can be pushed from Panorama in PAN-OS? (Choose three.)

Options:

A.

Multiple authorization codes

B.

User IP mappings

C.

Steering rules

D.

Security group assignment of virtual machines (VMs)

E.

Security groups

Buy Now
Questions 8

Which two criteria are required to deploy VM-Series firewalls in high availability (HA)? (Choose two.)

Options:

A.

Configuration of asymmetric routing

B.

Assignment of identical licenses and subscriptions

C.

Deployment on a different host

D.

Deployment on same type of hypervisor

Buy Now
Questions 9

Which two actions can be performed for VM-Series firewall licensing by an orchestration system? (Choose two.)

Options:

A.

Registering an authorization code

B.

Creating a license

C.

Downloading a content update

D.

Renewing a license

Buy Now
Questions 10

Which two factors lead to improved return on investment for prospects interested in Palo Alto Networks virtualized next-generation firewalls (NGFWs)? (Choose two.)

Options:

A.

Reduced operational expenditures

B.

Decreased likelihood of data breach

C.

Reduced insurance premiums

D.

Reduced time to deploy

Buy Now
Questions 11

Where do CN-Series devices obtain a VM-Series authorization key?

Options:

A.

Panorama

B.

Local installation

C.

GitHub

D.

Customer Support Portal

Buy Now
Questions 12

Which two design options address split brain when configuring high availability (HA)? (Choose two.)

Options:

A.

Bundling multiple interfaces in an aggregated interface group and assigning HA2

B.

Using the heartbeat backup

C.

Sending heartbeats across the HA2 interfaces

D.

Adding a backup HA1 interface

Buy Now
Questions 13

Which of the following can provide application-level security for a web-server instance on Amazon Web Services (AWS)?

Options:

A.

VM-Series firewalls

B.

Hardware firewalls

C.

Terraform templates

D.

Security groups

Buy Now
Questions 14

What is a design consideration for a prospect who wants to deploy VM-Series firewalls in an Amazon Web Services (AWS) environment?

Options:

A.

Resources are shared within the cluster.

B.

Only active-passive high availability (HA) is supported.

C.

High availability (HA) clusters are limited to fewer than 8 virtual appliances.

D.

Special AWS plugins are needed for load balancing.

Buy Now
Questions 15

Which two configuration options does Palo Alto Networks recommend for outbound high availability (HA) design in Amazon Web Services using a VM-Series firewall? (Choose two.)

Options:

A.

Traditional active-active HA

B.

Transit gateway and Security VPC

C.

Traditional active-passive HA

D.

Transit VPC and Security VPC

Buy Now
Questions 16

How are Palo Alto Networks Next-Generation Firewalls (NGFWs) deployed within a Cisco ACI architecture?

Options:

A.

Traffic can be automatically redirected using static address objects.

B.

VXLAN or NVGRE traffic is terminated and inspected for translation to VLANs.

C.

Service graphs are configured to allow their deployment.

D.

SDN code hooks can help detonate malicious file samples designed to detect virtual environments.

Buy Now
Questions 17

What helps avoid split brain in active-passive high availability (HA) pair deployment?

Options:

A.

Enabling preemption on both firewalls in the HA pair

B.

Using a standard traffic interface as the HA2 backup

C.

Using a standard traffic interface as the HA3 link

D.

Using the management interface as the HA1 backup link

Buy Now
Questions 18

Which feature provides real-time analysis using machine learning (ML) to defend against new and unknown threats?

Options:

A.

Cortex Data Lake

B.

DNS Security

C.

Panorama VM-Series plugin

D.

Advanced URL Filtering (AURLF)

Buy Now
Questions 19

Which software firewall would assist a prospect who is interested in securing extensive DevOps deployments?

Options:

A.

VM-Series

B.

CN-Series

C.

Ion-Series

D.

Cloud next-generation firewall (NGFW)

Buy Now
Exam Name: Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional
Last Update: Sep 15, 2024
Questions: 65
PSE-SoftwareFirewall pdf

PSE-SoftwareFirewall PDF

$28  $80
PSE-SoftwareFirewall Engine

PSE-SoftwareFirewall Testing Engine

$33.25  $95
PSE-SoftwareFirewall PDF + Engine

PSE-SoftwareFirewall PDF + Testing Engine

$45.5  $130