Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PSE-StrataDC Palo Alto Networks System Engineer Professional - Strata Data Center Questions and Answers

Questions 4

Which three deployment modes of VM-Series firewalls are supported across NSX-T? (Choose three )

Options:

A.

Partner Service

B.

Boot Strap

C.

Prism Central

D.

Tier-1 insertion

E.

Tier-0 insertion

Buy Now
Questions 5

When deploying VM series on Openstack platform, which statement is correct?

Options:

A.

Allow configuration of at least one interface

B.

OpenStack compute node could be installed on a hypervisor platform

C.

Accept the VM-Series OVA image

D.

Set Instance type OS::Nova Server

Buy Now
Questions 6

Which are two use cases for HSCI ports on the SMC module on PA-7000 Series? (Choose two )

Options:

A.

HA1 backup link in active/active HA

B.

HA1 link in active/passive HA

C.

HA3 link in active/active HA

D.

HA2 link in active/passive HA

Buy Now
Questions 7

How does Twistlock offer workload security at runtime?

Options:

A.

works with the IDP to identify over-privileged containers and services and restricts network access

B.

quarantines containers that demonstrate increased CPU and memory usage

C.

automatically patches vulnerabilities and compliance issues for every container and service

D.

builds a whitelist security model automatically for every container and service

Buy Now
Questions 8

Why are containers uniquely suitable for whitelist-based runtime security?

Options:

A.

Developers typically define the processes used in their containers within the Dockerfile

B.

Docker has a built-in runtime analysis capability to aid in whitelisting.

C.

Containers typically have only a few defined processes that should ever be executed.

D.

Operations teams typically know what processes are used within a container

Buy Now
Questions 9

A customer wants to completely segment their internal networks They have Cisco switches and extensively use 10Gbps interfaces. They are running VMware ESXi and are considering implementing NSX. Which three Palo Alto Networks firewall models will support this deployment? (Choose three.)

Options:

A.

PA-3050

B.

VM-100

C.

VM-300

D.

PA-3250

E.

PA-7050

Buy Now
Questions 10

When would a PA-7000 Series NPC GQXM Card be preferable to a PA-7000 Series NPC GQ Card?

Options:

A.

When the organization requires a greater number of sessions

B.

When the environment has a need for more SFP+ interfaces

C.

When the organization requires gear with a smaller slot size.

D.

When the environment has a need for more policy rules.

Buy Now
Questions 11

Which protocol is used by VMware to encapsulate packets in NSX?

Options:

A.

VRLAN

B.

VXLAN

C.

GRE

D.

VMLAN

Buy Now
Questions 12

Which three criteria are required to deploy VM-Series firewalls in High Availability? (Choose three)

Options:

A.

deployed on same type of hypervisor

B.

allocate identical CPU cores and network interfaces

C.

assigned identical licenses and subscriptions

D.

deployed on a different host

E.

configured asymmetric routing

Buy Now
Questions 13

Which three advantages of the Palo Alto Networks platform architecture are used to enable security orchestration in SDN? (Choose three )

Options:

A.

a full set of APIs enabling programmatic control of policy and configuration

B.

NVGRE support for advanced VLAN integration

C.

integration with leading orchestration platforms: VMware NSX. OpenStack. and Cisco ACI

D.

Dynamic Address Groups to adapt Security policies dynamically

E.

VXLAN support for network-layer abstraction

Buy Now
Questions 14

How does Palo Alto Networks integrate with VXLAN tagging?

Options:

A.

does not integrate with VXLAN tagging, so virtual appliances cannot be provided, but hardware appliances can be offered at the data center gateway border

B.

integrates with VXLAN. but scripting is necessary, and Professional Services should be engaged

C.

integrates fully into VXLAN architectures if they are provided by VMware

D.

does not integrate natively with VXLAN tagging, network equipment can convert VXLAN flows to VLANs and send those VLANs to Palo Alto Networks firewalls

Buy Now
Questions 15

A single VM runs a web server and a DNS server A separate VM needs to access the DNS server, but is not allowed to access the web server What network control functionality is necessary to enforce this security posture'?

Options:

A.

can use a Palo Alto Networks NGFW for this requirement, but not a port filter firewall.

B.

can use either a Palo Alto Networks NGFW or a port filler firewall for this requirement.

C.

can use a port filter firewall for this requirement but not the Palo Alto Networks NGFW.

D.

can use a specialized VM with advanced threat protection for this requirement

Buy Now
Questions 16

Which interface mode does an administrator use to generate the statdump file that can be converted into an SLR? Assume that the administrator wants to make the evaluation as unintrusive as possible

Options:

A.

Virtual Wire

B.

TAP

C.

Layer 2

D.

Layer 3

Buy Now
Questions 17

Which option describes Arista's micro-segmentation?

Options:

A.

Arista and VMware are extending secure segmentation with an open API (RESTZJSON)-based exchange, which allows NSX to federate with CloudVision to extend the micro-segmentation policy for physical workloads.

B.

Arista and Kubernetes are extending secure segmentation with an open API (RESTVJSON)-based exchange, which allows Kubernetes to federate with CloudVision to extend the micro-segmentation policy for physical workloads.

C.

Arista's micro-segmentation and macro-segmentation are identical concepts that can be used interchangeably

D.

Arista and VMware both perform identical functions for NGFW micro-segmentation

Buy Now
Questions 18

Which two OpenStack components are used in the creation of a VM-Series firewall from a heat template in OpenStack? (Choose two )

Options:

A.

Swift creates the storage resources.

B.

Nova creates the firewall instance.

C.

Horizon

D.

Neutron creates the network resources.

Buy Now
Exam Code: PSE-StrataDC
Exam Name: Palo Alto Networks System Engineer Professional - Strata Data Center
Last Update: Apr 30, 2026
Questions: 60

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now PSE-StrataDC testing engine

PDF (Q&A)

$43.57  $124.49
buy now PSE-StrataDC pdf