Exit demo PSE-HARDWARE-FIREWAL Palo Alto Networks Systems Engineer Professional - Hardware Firewall PDF format · free preview

Palo Alto Networks PSE-HARDWARE-FIREWAL - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pse-hardware-firewal.html

Question 1
Single choice

What is the minimum configuration to stop a Cobalt Strike Malleable C2 attack inline and in real time?

A.

Next-Generation CASB on PAN-OS 10.1

B.

Advanced Threat Prevention and PAN-OS 10.2

C.

Threat Prevention and Advanced WildFire with PAN-OS 10.0

D.

DNS Security, Threat Prevention, and Advanced WildFire with PAN-OS 9.x

Question 2
Multiple choice

While responding to a customer RFP, a systems engineer (SE) is presented the question, "How do PANW firewalls enable the mapping of transactions as part of Zero Trust principles?"

Which two narratives can the SE use to respond to the question? (Choose two.)

A.

Emphasize Zero Trust as an ideology, and that the customer decides how to align to Zero Trust principles.

B.

Reinforce the importance of decryption and security protections to verify traffic that is not malicious.

C.

Explain how the NGFW can be placed in the network so it has visibility into every traffic flow.

D.

Describe how Palo Alto Networks NGFW Security policies are built by using users, applications, and data objects.

Question 3
Single choice

A current NGFW customer has asked a systems engineer (SE) for a way to prove to their internal management team that its NGFW follows Zero Trust principles.

Which action should the SE take?

A.

Use the "Monitor > PDF Reports" node to schedule a weekly email of the Zero Trust report to the
internal management team.

B.

Help the customer build reports that align to their Zero Trust plan in the "Monitor > Manage Custom
Reports" tab.

C.

Use a third-party tool to pull the NGFW Zero Trust logs, and create a report that meets the customer's needs.

D.

Use the "ACC" tab to help the customer build dashboards that highlight the historical tracking of the NGFW enforcing policies.

Question 4
Multiple choice

Which two actions should a systems engineer take when a customer is concerned about how to remain aligned to Zero Trust principles as they adopt additional security features over time? (Choose two)

A.

Turn on all licensed Cloud-Delivered Security Services (CDSS) subscriptions in blocking mode for all policies.

B.

Apply decryption where possible to inspect and log all new and existing traffic flows.

C.

Use the Best Practice Assessment (BPA) tool to measure progress toward Zero Trust principles.

D.

Use the Policy Optimizer tool to understand security rules allowing users to bypass decryption.

Question 5
Single choice

Which statement applies to the default configuration of a Palo Alto Networks NGFW?

A.

Security profiles are applied to all policies by default, eliminating implicit trust of any data traversing the firewall.

B.
The default policy action for intrazone traffic is deny, eliminating implicit trust within a security zone.
C.

The default policy action allows all traffic unless explicitly denied.

D.

The default policy action for interzone traffic is deny, eliminating implicit trust between security zones.

Question 6
Multiple choice

Which two compliance frameworks are included with the Premium version of Strata Cloud Manager (SCM)? (Choose two)

A.

Payment Card Industry (PCI)

B.

National Institute of Standards and Technology (NIST)

C.

Center for Internet Security (CIS)

D.

Health Insurance Portability and Accountability Act (HIPAA)

Question 7
Multiple choice

In which two locations can a Best Practice Assessment (BPA) report be generated for review by a customer? (Choose two.)

A.

PANW Partner Portal

B.

Customer Support Portal

C.

AIOps

D.

Strata Cloud Manager (SCM)

Question 8
Single choice

When a customer needs to understand how Palo Alto Networks NGFWs lower the risk of exploitation by newly announced vulnerabilities known to be actively attacked, which solution and functionality delivers the most value?

A.

Advanced URL Filtering uses machine learning (ML) to learn which malicious URLs are being utilized by the attackers, then block the resulting traffic.

B.

Advanced Threat Prevention's command injection and SQL injection functions use inline deep learning
against zero-day threats.

C.

Single Pass Architecture and parallel processing ensure traffic is efficiently scanned against any
enabled Cloud-Delivered Security Services (CDSS) subscription.

D.

WildFire loads custom OS images to ensure that the sandboxing catches any activity that would affect the customer's environment.

Question 9
Single choice

What is used to stop a DNS-based threat?

A.

DNS proxy

B.

Buffer overflow protection

C.

DNS tunneling

D.

DNS sinkholing

Question 10
Multiple choice

Which two statements correctly describe best practices for sizing a firewall deployment with decryption enabled? (Choose two.)

A.

SSL decryption traffic amounts vary from network to network.

B.

Large average transaction sizes consume more processing power to decrypt.

C.

Perfect Forward Secrecy (PFS) ephemeral key exchange algorithms such as Diffie-Hellman Ephemeral (DHE) and Elliptic-Curve Diffie-Hellman Exchange (ECDHE) consume more processing resources than Rivest-Shamir-Adleman (RSA) algorithms.

D.

Rivest-Shamir-Adleman (RSA) certificate authentication method (not the RSA key exchange algorithm) consumes more resources than Elliptic Curve Digital Signature Algorithm (ECDSA), but ECDSA is more secure.

Showing 10 of 60 questions · Unlock the full set