[Feb 22, 2022] PSE-Strata Exam Dumps, PSE-Strata Practice Test Questions [Q31-Q54]

Share

[Feb 22, 2022] PSE-Strata Exam Dumps, PSE-Strata Practice Test Questions

Free PSE-Strata Study Guides Exam Questions and Answer

NEW QUESTION 31
Which three categories are identified as best practices in the Best Practice Assessment tool? (Choose three.)

  • A. expose the visibility and presence of command-and-control sessions
  • B. measure the adoption of URL filters. App-ID. User-ID
  • C. use of decryption policies
  • D. use of device management access and settings
  • E. identify sanctioned and unsanctioned SaaS applications

Answer: B,C,E

 

NEW QUESTION 32
Which security profile on the NGFW includes signatures to protect you from brute force attacks?

  • A. Vulnerability Protection Profile
  • B. URL Filtering Profile
  • C. Zone Protection Profile
  • D. Anti-Spyware Profile

Answer: A

 

NEW QUESTION 33
What can be applied to prevent users from unknowingly downloading malicious file types from the internet?

  • A. A file blocking profile to security policy rules that allow general web access
  • B. An antivirus profile to security policy rules that deny general web access
  • C. A vulnerability profile to security policy rules that deny general web access
  • D. A zone protection profile to the untrust zone

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/best-practices/8-1/internet-gateway-best-practices/best-practice-internet-gatew

 

NEW QUESTION 34
WildFire subscription supports analysis of which three types? (Choose three.)

  • A. GIF
  • B. 7-Zip
  • C. DMG
  • D. Flash
  • E. RPM
  • F. ISO

Answer: B,D,F

 

NEW QUESTION 35
Which statement is true about Deviating Devices and metrics?

  • A. A metric health baseline is determined by averaging the health performance for a given metric over seven days plus the standard deviation
  • B. An Administrator can set the metric health baseline along with a valid standard deviation
  • C. Deviating Device Tab is only available with a SD-WAN Subscription
  • D. Deviating Device Tab is only available for hardware-based firewalls

Answer: A

 

NEW QUESTION 36
When log sizing is factored for the Cortex Data Lake on the NGFW, what is the average log size used in calculation?

  • A. 1500 bytes
  • B. depends on the Cortex Data Lake tier purchased
  • C. 18 bytes
  • D. 8MB

Answer: A

 

NEW QUESTION 37
Which two new file types are supported on the WF-500 in PAN-OS 9? (Choose two)

  • A. RAR
  • B. Zip
  • C. 7-Zip
  • D. ELF

Answer: A,C

Explanation:
https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-file-type-support

 

NEW QUESTION 38
Match the WildFire Inline Machine Learning Model to the correct description for that model.

Answer:

Explanation:

 

NEW QUESTION 39
The firewall includes predefined reports, custom reports can be built for specific data and actionable tasks, or predefined and custom reports can be combined to compile information needed to monitor network security.
The firewall provides which three types of reports? (Choose three.)

  • A. PDF Summary Reports
  • B. SNMP Reports
  • C. Botnet Reports
  • D. User or Group Activity Reports
  • E. Netflow Reports

Answer: C,D,E

 

NEW QUESTION 40
A client chooses to not block uncategorized websites.
Which two additions should be made to help provide some protection? (Choose two.)

  • A. A URL filtering profile with the action set to continue for unknown URL categories to security policy rules that allow web access
  • B. A data filtering profile with a custom data pattern to security policy rules that deny uncategorized websites
  • C. A file blocking profile attached to security policy rules that allow uncategorized websites to help reduce the risk of drive by downloads
  • D. A security policy rule using only known URL categories with the action set to allow

Answer: A,D

 

NEW QUESTION 41
Which CLI allows you to view the names of SD-WAN policy rules that send traffic to the specified virtual SD-WAN interface, along with the performance metrics?
A)

B)

C)

D)

  • A. Option
  • B. Option
  • C. Option
  • D. Option

Answer: D

 

NEW QUESTION 42
As you prepare to scan your Amazon S3 account, what enables Prisma service permission to access Amazon S3?

  • A. AWS account ID
  • B. secret access key
  • C. access key ID
  • D. administrative Password

Answer: C

 

NEW QUESTION 43
Which three features are used to prevent abuse of stolen credentials? (Choose three.)

  • A. multi-factor authentication
  • B. SSL decryption rules
  • C. Prisma Access
  • D. WildFire Profiles
  • E. URL Filtering Profiles

Answer: A,B,D

 

NEW QUESTION 44
Which three items contain information about Command-and-Control (C2) hosts? (Choose three.)

  • A. WildFire analysis reports
  • B. Botnet reports
  • C. SaaS reports
  • D. Threat logs
  • E. Data filtering logs

Answer: A,B,E

 

NEW QUESTION 45
Which three considerations should be made prior to installing a decryption policy on the NGFW? (Choose three.)

  • A. Exclude certain types of traffic in decryption policy
  • B. Inability to access websites
  • C. Ensure throughput is not an issue
  • D. Deploy decryption setting all at one time
  • E. Include all traffic types in decryption policy

Answer: A,B,E

 

NEW QUESTION 46
Which functionality is available to firewall users with an active Threat Prevention subscription, but no WildFire license?

  • A. WildFire hybrid deployment
  • B. Access to the WildFire API
  • C. 5 minute WildFire updates to threat signatures
  • D. PE file upload to WildFire

Answer: C

 

NEW QUESTION 47
What are three purposes for the Eval Systems, Security Lifecycle Reviews and Prevention Posture Assessment tools? (Choose three.)

  • A. help streamline the deployment and migration of NGFWs
  • B. when you're delivering a security strategy
  • C. provide users visibility into the applications currently allowed on the network
  • D. assess the state of NGFW feature adoption
  • E. when client's want to see the power of the platform

Answer: C,D,E

 

NEW QUESTION 48
The need for a file proxy solution, virus and spyware scanner, a vulnerability scanner, and HTTP decoder for URL filtering is handled by which component in the NGFW?

  • A. Stream-based Signature Engine
  • B. SIA (Scan It All) Processing Engine
  • C. Security Processing Engine
  • D. First Packet Processor

Answer: A

 

NEW QUESTION 49
Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)

  • A. dedicated pair of decryption forwarding interfaces required per security chain
  • B. a single pair of decryption forwarding interfaces
  • C. a unique Transparent Bridge Decryption Forwarding Profile to a single Decryption policy rule
  • D. a unique Decryption policy rule is required per security chain

Answer: C,D

 

NEW QUESTION 50
What are two benefits of using Panorama for a customer who is deploying virtual firewalls to secure data center traffic? (Choose two.)

  • A. It can automatically create address groups for use with KVM.
  • B. It can bootstrap the virtual firewalls for dynamic deployment scenarios.
  • C. It can provide the Automated Correlation Engine functionality, which the virtual firewalls do not support.
  • D. It can monitor the virtual firewalls' physical hosts and Vmotion them as necessary

Answer: B,C

 

NEW QUESTION 51
An Administrator needs a PDF summary report that contains information compiled from existing reports based on data for the Top five(5) in each category Which two timeframe options are available to send this report? (Choose two.)

  • A. Daily
  • B. Bi-weekly
  • C. Weekly
  • D. Monthly

Answer: A

 

NEW QUESTION 52
Which two new file types are supported on the WF-500 in PAN-OS 9? (Choose two)

  • A. RAR
  • B. Zip
  • C. 7-Zip
  • D. ELF

Answer: A,C

 

NEW QUESTION 53
A customer is concerned about malicious activity occurring directly on their endpoints and will not be visible to their firewalls.
Which three actions does the Traps agent execute during a security event, beyond ensuring the prevention of this activity? (Choose three.)

  • A. Remediates the event by deleting the malicious file
  • B. Notifies the user about the event
  • C. Collects forensic information about the event
  • D. Informs WildFire and sends up a signature to the Cloud
  • E. Communicates the status of the endpoint to the ESM

Answer: B,C,E

 

NEW QUESTION 54
......

PSE-Strata Exam Dumps, PSE-Strata Practice Test Questions: https://examtorrent.actualtests4sure.com/PSE-Strata-practice-quiz.html