Updated Feb-2024 PSE-Strata Exam Practice Test Questions [Q49-Q69]

Share

Updated Feb-2024 PSE-Strata Exam Practice Test Questions

Verified PSE-Strata dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump

NEW QUESTION # 49
Which two components must to be configured within User-ID on a new firewall that has been implemented? (Choose two.)

  • A. User mapping
  • B. 802.1X Authentication
  • C. Group Mapping
  • D. Proxy Authentication

Answer: A,C

Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/enable-user-id


NEW QUESTION # 50
Which CLI allows you to view the names of SD-WAN policy rules that send traffic to the specified virtual SD-WAN interface, along with the performance metrics?

  • A. >show sdwan rule vif sdwan.x
  • B. >show sdwan session distribution policy-name
  • C. >show sdwan connection all |
  • D. >show sdwan path-monitor stats vif

Answer: A

Explanation:
https://docs.paloaltonetworks.com/sd-wan/1-0/sd-wan-admin/troubleshooting/use-cli-commands-for-sd-wan-tasks.html


NEW QUESTION # 51
Prisma SaaS provides which two SaaS threat prevention capabilities? (Choose two)

  • A. WildFire analysis
  • B. file quarantine
  • C. shellcode protection
  • D. SaaS AppID signatures
  • E. remote procedural call (RPC) interrogation

Answer: A,D


NEW QUESTION # 52
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinkhole enabled, generating a traffic log. What will be the destination IP address in that log entry?

  • A. The IP address of the command-and-control server.
  • B. The IP address specified in the sinkhole configuration.
  • C. The IP address of one of the external DNS servers identified in the anti-spyware database.
  • D. The IP address of sinkhole.paloaltonetworks.com

Answer: B


NEW QUESTION # 53
What are two presales selling advantages of using Expedition? (Choose two.)

  • A. reduce effort to implement policies based on App-ID and User-ID
  • B. map migration gaps to professional services statement of Works (SOWs)
  • C. streamline & migrate to Layer7 policies using Policy Optimizer
  • D. easy migration process to move to Palo Alto Networks NGFWs

Answer: B,D


NEW QUESTION # 54
What filtering criteria is used to determine what users to include as members of a dynamic user group?

  • A. IP Addresses
  • B. Tags
  • C. Login IDs
  • D. Security Policy Rules

Answer: B

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/user-id-features/dynamic- user-groups


NEW QUESTION # 55
Which two actions can be taken to enforce protection from brute force attacks in the security policy? (Choose two.)

  • A. Create a log forwarding object to send logs to Panorama and a third-party syslog server event correlation
  • B. Install content updates that include new signatures to protect against emerging threats
  • C. Attach the vulnerability profile to a security rule
  • D. Add the URL filtering profile to a security rule

Answer: B,C

Explanation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/prevent-brute-force-attacks.html


NEW QUESTION # 56
What are three valid sources that are supported for user IP address mapping in Palo Alto Networks NGFW? (Choose three.)

  • A. TACACS
  • B. Lotus Domino
  • C. Client Probing
  • D. eDirectory monitoring
  • E. RADIUS
  • F. Active Directory monitoring

Answer: C,D,F


NEW QUESTION # 57
What are two advantages of the DNS Sinkholing feature? (Choose two.)

  • A. It can be deployed independently of an Anti-Spyware Profile.
  • B. It forges DNS replies to known malicious domains.
  • C. It can work upstream from the internal DNS server.
  • D. It monitors DNS requests passively for malware domains.

Answer: B,C

Explanation:
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/threat-prevention/dns-sinkholing


NEW QUESTION # 58
Match the WildFire Inline Machine Learning Model to the correct description for that model.

Answer:

Explanation:


NEW QUESTION # 59
Which two of the following does decryption broker provide on a NGFW? (Choose two.)

  • A. Provides a third party SSL decryption option which allows you to increase the total number of third party devices performing analysis and enforcement
  • B. Eliminates the need for a third party SSL decryption option which allows you to reduce the total number of third party devices performing analysis and enforcement
  • C. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic multiple times
  • D. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic only once

Answer: C,D


NEW QUESTION # 60
What are three considerations when deploying User-ID? (Choose three.)

  • A. Enable WMI probing in high security networks
  • B. Only enable User-ID on trusted zones
  • C. Use a dedicated service account for User-ID services with the minimal permissions necessary
  • D. Specify included and excluded networks when configuring User-ID
  • E. User-ID can support a maximum of 15 hops

Answer: B,C,D


NEW QUESTION # 61
What can be applied to prevent users from unknowingly downloading malicious file types from the internet?

  • A. A file blocking profile to security policy rules that allow general web access
  • B. An antivirus profile to security policy rules that deny general web access
  • C. A vulnerability profile to security policy rules that deny general web access
  • D. A zone protection profile to the untrust zone

Answer: A

Explanation:
Explanation
https://docs.paloaltonetworks.com/best-practices/8-1/internet-gateway-best-practices/best-practice-internet-gatew


NEW QUESTION # 62
Which three mechanisms are valid for enabling user mapping? (Choose three.)

  • A. Domain server monitoring
  • B. Reverse DNS lookup
  • C. User behaviour recognition
  • D. Captive Portal
  • E. Client probing

Answer: A,D,E


NEW QUESTION # 63
What two types of certificates are used to configure SSL Forward Proxy? (Сhoose two.)

  • A. Private key certificates
  • B. Self-Signed certificates
  • C. Intermediate certificates
  • D. Enterprise CA-signed certificates

Answer: B,D

Explanation:
Reference:
%20certificate.&text=Certificate%20Name-,.,unique%20name%20for%20each%20firewall


NEW QUESTION # 64
A customer is concerned about zero-day targeted attacks against its intellectual property.
Which solution informs a customer whether an attack is specifically targeted at them?

  • A. Cortex XSOAR Community edition
  • B. Panorama Correlation Report
  • C. Cortex XDR Prevent
  • D. AutoFocus

Answer: C


NEW QUESTION # 65
Which selection must be configured on PAN-OS External Dynamic Lists to support MineMeld indicators?

  • A. Inputs
  • B. Class
  • C. Prototype
  • D. Feed Base URL

Answer: D

Explanation:
https://live.paloaltonetworks.com/t5/minemeld-articles/connecting-pan-os-to-minemeld-using-external-dynamic-lists/ta-p/190414


NEW QUESTION # 66
What are three best practices for running an Ultimate Test Drive (UTD)? (Choose three.)

  • A. It should be used to create pipeline and customer interest.
  • B. It should be used to demonstrate the power of the platform.
  • C. The required equipment should be shipped to lab site in advance.
  • D. It should be led by Palo Alto Network employees.
  • E. The lab documentation should be reviewed and tested.

Answer: A,B,E


NEW QUESTION # 67
What does WildFire block on a next-generation firewall (NGFW) that already has Advanced Threat Prevention (ATP) enabled?

  • A. Malicious unknown files
  • B. Benign unknown files
  • C. Port scans
  • D. Brute-force attacks

Answer: A


NEW QUESTION # 68
Which two of the following does decryption broker provide on a NGFW? (Choose two.)

  • A. Provides a third party SSL decryption option which allows you to increase the total number of third party devices performing analysis and enforcement
  • B. Eliminates the need for a third party SSL decryption option which allows you to reduce the total number of third party devices performing analysis and enforcement
  • C. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic only once
  • D. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic multiple times

Answer: B,C

Explanation:
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-broker.html


NEW QUESTION # 69
......

Pass Palo Alto Networks Systems Engineer PSE-Strata Exam With 224 Questions: https://examtorrent.actualtests4sure.com/PSE-Strata-practice-quiz.html