Palo Alto Networks Systems Engineer PSE-Strata Dumps Full Questions with Free PDF Questions to Pass [Q56-Q78]

Share

Palo Alto Networks Systems Engineer PSE-Strata Dumps Full Questions with Free PDF Questions to Pass

100% Updated Palo Alto Networks PSE-Strata Enterprise PDF Dumps

NEW QUESTION # 56
A customer with a fully licensed Palo Alto Networks firewall is concerned about threats based on domain generation algorithms (DGAS).
Which Security profile is used to configure Domain Name Security (DNS) to Identity and block previously unknown DGA-based threats in real time?

  • A. Anti-Spyware profile
  • B. URL Filtering profile
  • C. Vulnerability Protection profile
  • D. WildFire Analysis profile

Answer: A


NEW QUESTION # 57
A client chooses to not block uncategorized websites.
Which two additions should be made to help provide some protection? (Choose two.)

  • A. A file blocking profile to security policy rules that allow uncategorized websites to help reduce the risk of drive by downloads
  • B. A URL filtering profile with the action set to continue for unknown URL categories to security policy rules that allow web access
  • C. A data filtering profile with a custom data pattern to security policy rules that deny uncategorized websites
  • D. A security policy rule using only known URL categories with the action set to allow

Answer: B,D


NEW QUESTION # 58
What two types of certificates are used to configure SSL Forward Proxy? (Choose two.)

  • A. Enterprise CA-signed certificates
  • B. Private key certificates
  • C. Self-Signed certificates
  • D. Intermediate certificates

Answer: A,C

Explanation:
Reference:
%20certificate.&text=Certificate%20Name-,.,unique%20name%20for%20each%20firewall


NEW QUESTION # 59
Which two features are found in a next-generation firewall but are absent in a legacy firewall product? (Choose two)

  • A. Onboard SSL decryption capability is used
  • B. Traffic is separated by zones
  • C. Identification of application is possible on any port
  • D. Traffic control is based on IP, port, and protocol
  • E. Policy match is a based on application

Answer: C,E


NEW QUESTION # 60
Which two actions can be taken to enforce protection from brute force attacks in the security policy? (Choose two.)

  • A. Add the URL filtering profile to a security rule
  • B. Attach the vulnerability profile to a security rule
  • C. Install content updates that include new signatures to protect against emerging threats
  • D. Create a log forwarding object to send logs to Panorama and a third-party syslog server event correlation

Answer: B,C

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/prevent-brute-force-attacks.html


NEW QUESTION # 61
Which selection must be configured on PAN-OS External Dynamic Lists to support MineMeld indicators?

  • A. Prototype
  • B. Inputs
  • C. Feed Base URL
  • D. Class

Answer: C

Explanation:
Explanation
https://live.paloaltonetworks.com/t5/minemeld-articles/connecting-pan-os-to-minemeld-using-external-dynamic-


NEW QUESTION # 62
Which two methods will help avoid Split Brain when running HA in Active/Active mode? (Choose two.)

  • A. Configure a Heartbeat Backup
  • B. Configure a Backup HA1 Interface
  • C. Create a loopback IP address and use that as a Source Interface
  • D. Place your management interface in an Aggregate Interface Group configuration

Answer: A,B

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activeactive-ha/configure-activeactive-ha.html


NEW QUESTION # 63
The botnet report displays a confidence score of 1 to 5 indicating the likelihood of a botnet infection.
Which three sources are used by the firewall as the basis of this score? (Choose three.)

  • A. Botnet Reports
  • B. Threat Landscape
  • C. Number of Events
  • D. Bad Certificate Reports
  • E. Traffic Type
  • F. Executable Downloads

Answer: C,E,F

Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/generate-botnet- reports


NEW QUESTION # 64
Given the following network diagram, an administrator is considering the use of Windows Log Forwarding and Global Catalog servers for User-ID implementation. What are two potential bandwidth and processing bottlenecks to consider? (Choose two.)

  • A. Domain Controllers
  • B. Firewall
  • C. Member Servers
  • D. Windows Server

Answer: A,C


NEW QUESTION # 65
Which three categories are identified as best practices in the Best Practice Assessment tool?
(Choose three.)

  • A. use of device management access and settings
  • B. use of decryption policies
  • C. expose the visibility and presence of command-and-control sessions
  • D. measure the adoption of URL filters, App-ID, User-ID
  • E. identify sanctioned and unsanctioned SaaS applications

Answer: B,D,E


NEW QUESTION # 66
XYZ Corporation has a legacy environment with asymmetric routing. The customer understands that Palo Alto Networks firewalls can support asymmetric routing with redundancy.
Which two features must be enabled to meet the customer's requirements? (Choose two.)

  • A. Virtual systems
  • B. Policy-based forwarding
  • C. HA active/passive
  • D. HA active/active

Answer: B,D


NEW QUESTION # 67
Which three script types can be analyzed in WildFire? (Choose three)

  • A. PowerShell Script
  • B. VBScript
  • C. JScript
  • D. MonoSenpt
  • E. PythonScript

Answer: B,C,E


NEW QUESTION # 68
Access to a business site is blocked by URL Filtering inline machine learning (ML) and considered as a false-positive.
How should the site be made available?

  • A. Disable URL Filtering inline ML
  • B. Create a custom URL category and add it to the Security policy
  • C. Change the action of real-time detection category on URL filtering profile
  • D. Create a custom URL category and add it on exception of the inline ML profile

Answer: D


NEW QUESTION # 69
Because of regulatory compliance a customer cannot decrypt specific types of traffic.
Which license should an SE recommend to the customer who will be decrypting traffic on the Palo Alto Networks firewall?

  • A. SSL Decryption, for inbound inspection and granular Forward Proxy SSL decryption
  • B. URL Filtering, to use predefined URL categories as match criteria in the decryption policy rules
  • C. App-ID, to use applications as match criteria in the decryption policy rules
  • D. Support, to request custom categories as match criteria in decryption policy rules

Answer: B


NEW QUESTION # 70
In which two ways can PAN-OS software consume MineMeld outputs? (Choose two.)

  • A. API
  • B. CSV
  • C. TXT
  • D. EDL

Answer: C,D


NEW QUESTION # 71
Which solution informs a customer concerned about zero-day targeted attacks whether an attack is specifically targeted at its property?

  • A. Cortex XDR Prevent
  • B. Cortex XSOAR Community edition
  • C. Panorama Correlation Report
  • D. AutoFocus

Answer: D


NEW QUESTION # 72
Which three features are used to prevent abuse of stolen credentials? (Choose three.)

  • A. SSL decryption rules
  • B. URL Filtering Profiles
  • C. Prisma Access
  • D. WildFire Profiles
  • E. multi-factor authentication

Answer: A,D,E


NEW QUESTION # 73
You have enabled the WildFire ML for PE files in the antivirus profile and have added the profile to the appropriate firewall rules. When you go to Palo Alto Networks WildFire test av file and attempt to download the test file it is allowed through. In order to verify that the machine learning is working from the command line, which command returns a valid result?

  • A. show ml cloud-status
  • B. show mlav cloud-status
  • C. show wfml cloud-status
  • D. show wfav cloud-status

Answer: B


NEW QUESTION # 74
A customer with a legacy firewall architecture is focused on port and protocol level security, and has heard that next generation firewalls open all ports by default. What is the appropriate rebuttal that positions the value of a NGFW over a legacy firewall?

  • A. Default policies block all interzone traffic. Palo Alto Networks empowers you to control applications by default ports or a configurable list of approved ports on a per-policy basis.
  • B. Palo Alto Networks NGFW protects all applications on all ports while leaving all ports opened by default.
  • C. Palo Alto Networks does not consider port information, instead relying on App-ID signatures that do not reference ports.
  • D. Palo Alto Networks keep ports closed by default, only opening ports after understanding the application request, and then opening only the application-specified ports.

Answer: A


NEW QUESTION # 75
A potential customer requires an NGFW solution which enables high-throughput, low-latency network security, all while incorporating unprecedented features and technology. They need a solution that solves the performance problems that plague today's security infrastructure.
Which aspect of the Palo Alto Networks NGFW capabilities can you highlight to help them address the requirements?

  • A. Threat Prevention
  • B. SP3 (Single Pass Parallel Processing)
  • C. Elastic Load Balancers
  • D. GlobalProtect

Answer: B

Explanation:
https://www.paloguard.com/SP3-Architecture.asp


NEW QUESTION # 76
What three Tabs are available in the Detailed Device Health on Panorama for hardware-based firewalls? (Choose three.)

  • A. Throughput
  • B. Mounts
  • C. Status
  • D. Errors
  • E. Interfaces
  • F. Sessions
  • G. Environments

Answer: E,F,G


NEW QUESTION # 77
When the Cortex Data Lake is sized for Prisma Access mobile users, what is a valid log size range you would use per day. per user?

  • A. 1500 to 2500 bytes
  • B. 1MB to 5 MB
  • C. 10MB to 30 MB
  • D. 100MB to 200 MB

Answer: D


NEW QUESTION # 78
......

Use Valid Exam PSE-Strata by Free4Torrent Books For Free Website: https://braindumps.free4torrent.com/PSE-Strata-valid-dumps-torrent.html