Certbus > Palo Alto Networks > Strata Associate > PSE-STRATA-ASSOCIATE > PSE-STRATA-ASSOCIATE Online Practice Questions and Answers

PSE-STRATA-ASSOCIATE Online Practice Questions and Answers

Questions 4

Which two of the following are benefits of the Palo AltoNetworks Zero Trust architecture? (Choose two.)

Select 2 Correct Responses

A. tighter access control

B. increased detection of threats and infiltration

C. more network segments

D. cloud-based virtual private network (VPN)

Browse 35 Q&As
Questions 5

An administrator wants to deploy a pair of firewalls in an active/active high availability (HA) architecture.

Which two deployment types are supported in this circumstance? (Choose two.) Select 2 Correct Responses

A. Layer 3

B. TAP mode

C. Virtual Wire

D. Layer 2

Browse 35 Q&As
Questions 6

Which architecture is unique to Palo Alto Networks and results in no additional performance overhead when enabling additional features?

A. multi-pass

B. multiple-core threaded

C. single-pass

D. no-pass

Browse 35 Q&As
Questions 7

When deploying an Eval Next-Generation Firewall (NGFW) within a customer environment for the purpose of generating a Security Lifecycle Review (SLR) report, creation of which interface will not impact production traffic?

A. Layer 3 interface

B. SLR interface

C. virtual wire interface

D. TAP interface

Browse 35 Q&As
Questions 8

In which two of the following scenarios is personal data excluded fromprotection under the General Data Protection Regulation (GDPR)?

Select 2 Correct Responses

A. The data was automated as part of an information filing system.

B. The data was generated in the course of a purely personal or household activity.

C. The data will be used for the prevention of criminal offenses.

D. The data is related to a person's economic or cultural identity.

Browse 35 Q&As
Questions 9

A Human Resources (HR) application has the URL of https://hr.company.com:4433/.

How should the "Service" column of the Security policy be set to match and permit this application?

A. Define and then select a new custom Transmission Control Protocol (TCP) service with port 4433.

B. Edit "service-https" to use port 4433.

C. Set to "service-http".

D. Set to "application-defaults," which will locate and match the HR application.

Browse 35 Q&As
Questions 10

Which subscription should be activated when a predefined, known malicious IP address is updated?

A. WildFire

B. Cortex Data Lake

C. Threat Prevention

D. URL Filtering

Browse 35 Q&As
Questions 11

Using a comprehensive range of natively-integratedsubscriptions and inline machine learning (ML), what does a Next-Generation Firewall (NGFW) use to prevent known and unknown threats in real time?

A. Cloud Delivered Security Services (CDSS)

B. Cloud Security Posture Management (CSPM)

C. Cloud NativeSecurity Platform (CNSP)

D. Cloud Identity Access Management (CIAM)

Browse 35 Q&As
Questions 12

A customer has enabled the Threat Prevention subscription on their Palo Alto Networks Next-Generation Firewall.

How will the performance of the firewall beaffected if the customer also enables both WildFire and User-ID?

A. The maximum throughput performance will be reduced, but the impact will vary based on the firewall model being used.

B. Enabling User-ID will have no additional performance impact, but enabling WildFire will reduce throughput.

C. There will be no additional performance impact to the firewall, and throughput will remain the same, regardless of firewall model.

D. Enabling WildFire will have no additional performance impact, but enabling User-ID will reduce throughput.

Browse 35 Q&As
Questions 13

Which three of the following arefeatures of the Palo Alto Networks Next-Generation Firewall (NGFW) that differentiate it from a stateful inspection firewall? (Choose three.)

Select 3 Correct Responses

A. Login-ID

B. User-ID

C. App-ID

D. Network-ID

E. SSL/SSH Decrypt

Browse 35 Q&As
Questions 14

The ability of a Next-Generation Firewall (NGFW) to logically group physical and virtual interfaces and then control traffic based on that grouping is known aswhat?

A. LLDP profiles

B. security zones

C. DHCP groups

D. security profile groups

Browse 35 Q&As
Questions 15

What file is needed from a firewall to generate a Security Lifecycle Review (SLR) report when creating the SLR?

A. tech support file

B. Panorama plugin registration file

C. stats dump file

D. system process core file

Browse 35 Q&As
Questions 16

Which deployment method is used to integrate a firewall to be inline in an existing network but does not support additional routing or switching?

A. virtual wire

B. TAP mode

C. Layer 3

D. Layer 2

Browse 35 Q&As
Questions 17

Which Next-Generation Firewall (NGFW) deployment model allows an organization to monitor trafficduring evaluations without interruption to network traffic?

A. Layer 2

B. TAP mode

C. virtual wire

D. Layer 3

Browse 35 Q&As
Questions 18

Which Palo Alto Networks product offers a centrally managed firewall update process?

A. SD_WAN

B. Prisma SaaS

C. Panorama

D. WildFire

Browse 35 Q&As
Exam Name: Palo Alto Networks Systems Engineer (PSE) - Strata Associate
Last Update: May 03, 2024
Questions: 35 Q&As

PDF

$45.99

VCE

$49.99

PDF + VCE

$59.99