Paloalto Networks PSE Strata Palo Alto Networks System Engineer Professional – Strata Online Training
Paloalto Networks PSE Strata Online Training
The questions for PSE Strata were last updated at Nov 19,2024.
- Exam Code: PSE Strata
- Exam Name: Palo Alto Networks System Engineer Professional - Strata
- Certification Provider: Paloalto Networks
- Latest update: Nov 19,2024
A customer requires an analytics tool with the following attributes:
– Uses the logs on the firewall to detect actionable events on the network
– Automatically processes a series of related threat events that, when combines, indicate a likely comprised host on the network
– Pinpoints the area of risk and allows for assessment of the risk to action can be taken to prevent exploitation of network resources
Which feature of PAN-OS will address these requirements?
- A . WildFire with application program interface (API) calls for automation
- B . Third-party security information and event management (SIEM) which can ingest next-generation firewall (NGFW) logs
- C . Automated correlation engine (ACE)
- D . Cortex XDR and Cortex Data Lake
What are three key benefits of the Palo Alto Networks platform approach to security? (Choose three)
- A . operational efficiencies due to reduction in manual incident review and decrease in mean time to resolution (MTTR)
- B . improved revenue due to more efficient network traffic throughput
- C . Increased security due to scalable cloud delivered security Services (CDSS)
- D . Cost savings due to reduction in IT management effort and device
WildFire can discover zero-day malware in which three types of traffic? (Choose three)
- A . SMTP
- B . HTTPS
- C . FTP
- D . DNS
- E . TFTP
A Fortune 500 customer has expressed interest in purchasing WildFire; however, they do not want to send discovered malware outside of their network.
Which version of WildFire will meet this customerās requirements?
- A . WildFire Private Cloud
- B . WildFire Government Cloud
- C . WildFire Secure Cloud
- D . WildFire Public Cloud
Which three script types can be analyzed in WildFire? (Choose three)
- A . PythonScript
- B . MonoSenpt
- C . JScript
- D . PowerShell Script
- E . VBScript
Which component is needed for a large-scale deployment of NGFWs with multiple Panorama Management Servers?
- A . M-600 appliance
- B . Panorama Interconnect plugin
- C . Panorama Large Scale VPN (LSVPN) plugin
- D . Palo Alto Networks Cluster license
Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
- A . WildFire analysis
- B . Dynamic user groups (DUGs)
- C . Multi-factor authentication (MFA)
- D . URL Filtering Profiles
Which CLI command allows visibility into SD-WAN events such as path Selection and path quality measurements?
- A . >show sdwan path-monitor stats vif
- B . >show sdwan session distribution policy-name
- C . >show sdwan connection all
- D . >show sdwan event
A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what Layer 7 application traffic is going over that port.
Which capability of PAN-OS would address the customer’s lack of visibility?
- A . Device ID, because it will give visibility into which devices are communicating with external destinations over port 53
- B . single pass architecture (SPA), because it will improve the performance of the Palo Alto Networks Layer 7 inspection
- C . User-ID, because it will allow the customer to see which users are sending traffic to external destinations over port 53
- D . App-ID, because it will give visibility into what exact applications are being run over that port and allow the customer to block unsanctioned applications using port 53
In PAN-OS 10.0 and later, DNS Security allows policy actions to be applied based on which three domains? (Choose three.)
- A . grayware
- B . command and control (C2)
- C . benign
- D . government
- E . malware