PSE-Strata Palo Alto Networks System Engineer Professional - Strata Questions and Answers
Which three settings must be configured to enable Credential Phishing Prevention? (Choose three.)
A company has deployed the following
• VM-300 firewalls in AWS
• endpoint protection with the Traps Management Service
• a Panorama M-200 for managing its VM-Series firewalls
• PA-5220s for its internet perimeter,
• Prisma SaaS for SaaS security.
Which two products can send logs to the Cortex Data Lake? (Choose two).
As you prepare to scan your Amazon S3 account, what enables Prisma service permission to access Amazon S3?
Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?
Which four actions can be configured in an Anti-Spyware profile to address command-and-control traffic from compromised hosts? (Choose four.)
Which two email links, contained in SMTP and POP3, can be submitted from WildFire analysis with a WildFire subscription? (Choose two.)
In Panorama, which three reports or logs will help identify the inclusion of a host source in a command-and-control (C2) incident? (Choose three.)
What will a Palo Alto Networks next-generation firewall (NGFW) do when it is unable to retrieve a DNS verdict from the DNS cloud service in the configured lookup time?
Which component is needed for a large-scale deployment of NGFWs with multiple Panorama Management Servers?
Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
WildFire can discover zero-day malware in which three types of traffic? (Choose three)
What three Tabs are available in the Detailed Device Health on Panorama for hardware-based firewalls? (Choose three.)
Which three actions should be taken before deploying a firewall evaluation unt in a customer environment? (Choose three.)
Which functionality is available to firewall users with an active Threat Prevention subscription, but no WildFire license?
Which two features are found in a Palo Alto Networks NGFW but are absent in a legacy firewall product? (Choose two.)
WildFire machine learning (ML) for portable executable (PE) files is enabled in the antivirus profile and added to the appropriate firewall rules in the profile. In the Palo Alto Networks WildFire test av file, an attempt to download the test file is allowed through.
Which command returns a valid result to verify the ML is working from the command line.
A WildFire subscription is required for which two of the following activities? (Choose two)
When the Cortex Data Lake is sized for Prisma Access mobile users, what is a valid log size range you would use per day. per user?
Which four steps of the cyberattack lifecycle does the Palo Alto Networks Security Operating Platform prevent? (Choose four.)
What are two ways to manually add and remove members of dynamic user groups (DUGs)? (Choose two)
Which two of the following does decryption broker provide on a NGFW? (Choose two.)
Which profile or policy should be applied to protect against port scans from the internet?
Which Security profile on the Next-Generation Firewall (NGFW) includes Signatures to protect against brute force attacks?
Which statement applies to Palo Alto Networks Single Pass Parallel Processing (SP3)?
An Administrator needs a PDF summary report that contains information compiled from existing reports based on data for the Top five(5) in each category Which two timeframe options are available to send this report? (Choose two.)
An endpoint, inside an organization, is infected with known malware that attempts to make a command-and-control connection to a C2 server via the destination IP address
Which mechanism prevents this connection from succeeding?
Access to a business site is blocked by URL Filtering inline machine learning (ML) and
considered as a false-positive.
How should the site be made available?
An administrator wants to justify the expense of a second Panorama appliance for HA of the management layer.
The customer already has multiple M-100s set up as a log collector group. What are two valid reasons for deploying Panorama in High Availability? (Choose two.)
Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)
A prospective customer currently uses a firewall that provides only Layer 4
inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what Layer 7 application traffic is going over that port
Which capability of PAN-OS would address the customer ' s lack of visibility?
Which of the following statements is valid with regard to Domain Name System (DNS) sinkholing?
When the Cortex Data Lake is sized for Traps Management Service, which two factors should be considered? (Choose two.)
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to secure data center traffic? (Choose two.)
Which three features are used to prevent abuse of stolen credentials? (Choose three.)
In an HA pair running Active/Passive mode, over which interface do the dataplanes communicate?
Which filtering criterion is used to determine users to be included as members of a dynamic user group (DUG)?
