Best Preparations of PSE-Strata Exam 2021 Palo Alto Networks Systems Engineer Unlimited 90 Questions
Focus on PSE-Strata All-in-One Exam Guide For Quick Preparation.
NEW QUESTION 51
Which two tabs in Panorama can be used to identify templates to define a common base configuration?
(Choose two.)
- A. Device Tab
- B. Network Tab
- C. Policies Tab
- D. Objects Tab
Answer: A,B
Explanation:
Explanation
https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/panorama-web-interface/panora
NEW QUESTION 52
What are two presales selling advantages of using Expedition? (Choose two.)
- A. reduce effort to implement policies based on App-ID and User-ID
- B. easy migration process to move to Palo Alto Networks NGFWs
- C. streamline & migrate to Layer7 policies using Policy Optimizer
- D. map migration gaps to professional services statement of Works (SOWs)
Answer: B,D
NEW QUESTION 53
A company has deployed the following
* VM-300 firewalls in AWS
* endpoint protection with the Traps Management Service
* a Panorama M-200 for managing its VM-Series firewalls
* PA-5220s for its internet perimeter,
* Prisma SaaS for SaaS security.
Which two products can send logs to the Cortex Data Lake? (Choose two).
- A. VM-300 firewalls
- B. Prisma SaaS
- C. Traps Management Service
- D. Panorama M-200 appliance
Answer: A,D
NEW QUESTION 54
Which three settings must be configured to enable Credential Phishing Prevention? (Choose three.)
- A. enable User-ID
- B. define URL Filtering Profile
- C. enable App-ID
- D. define an SSL decryption rulebase
- E. validate credential submission detection
Answer: A,B,E
Explanation:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/prevent-credential-phishing.html
NEW QUESTION 55
Which two of the following does decryption broker provide on a NGFW? (Choose two.)
- A. Eliminates the need for a third party SSL decryption option which allows you to reduce the total number of third party devices performing analysis and enforcement
- B. Provides a third party SSL decryption option which allows you to increase the total number of third party devices performing analysis and enforcement
- C. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic only once
- D. Decryption broker allows you to offload SSL decryption to the Palo Alto Networks next-generation firewall and decrypt traffic multiple times
Answer: A,C
NEW QUESTION 56
Which statement is true about Deviating Devices and metrics?
- A. Deviating Device Tab is only available with a SD-WAN Subscription
- B. An Administrator can set the metric health baseline along with a valid standard deviation
- C. Deviating Device Tab is only available for hardware-based firewalls
- D. A metric health baseline is determined by averaging the health performance for a given metric over seven days plus the standard deviation
Answer: D
NEW QUESTION 57
Which two components must be configured within User-ID on a new firewall that has been implemented? (Choose two.)
- A. Group Mapping
- B. Proxy Authentication
- C. User Mapping
- D. 802.1X Authentication
Answer: A,C
NEW QUESTION 58
In an HA pair running Active/Passive mode, over which interface do the dataplanes communicate?
- A. HA4
- B. HA1
- C. HA3
- D. HA2
Answer: D
NEW QUESTION 59
Which two types of security chains are supported by the Decryption Broker? (Choose two.)
- A. virtual wire
- B. transparent bridge
- C. Layer 3
- D. Layer 2
Answer: B,C
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-broker/decryption-broker-con
NEW QUESTION 60
How often are the databases for Anti-virus. Application, Threats, and WildFire subscription updated?
- A. Anti-virus (weekly), Application (daily), Threats (daily), WildFire (5 minutes)
- B. Anti-virus (daily), Application (weekly), Threats (weekly), WildFire (5 minutes)
- C. Anti-virus (daily), Application (weekly), Threats (daily), WildFire (5 minutes)
- D. Anti-virus (weekly): Application (daily). Threats (weekly), WildFire (5 minutes)
Answer: B
NEW QUESTION 61
How frequently do WildFire signatures move into the antivirus database?
- A. every 1 hour
- B. every 24 hours
- C. once a week
- D. every 12 hours
Answer: B
NEW QUESTION 62
Which three new script types can be analyzed in WildFire? (Choose three.)
- A. PythonScript
- B. JScript
- C. MonoScript
- D. PowerShell Script
- E. VBScript
Answer: B,D,E
Explanation:
The WildFire cloud is capable of analyzing the following script types:
* JScript (.js)
* VBScript (.vbs)
* PowerShell Script (.ps1)
https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/script-sample-support
NEW QUESTION 63
A customer is looking for an analytics tool that uses the logs on the firewall to detect actionable events on the network. They require something to automatically process a series of related threat events that, when combined, indicate a likely compromised host on their network or some other higher level conclusion. They need to pinpoint the area of risk, such as compromised hosts on the network, allows you to assess the risk and take action to prevent exploitation of network resources.
Which feature of PAN-OS can you talk about to address their requirement to optimize their business outcomes?
- A. The Automated Correlation Engine
- B. Cortex XDR and Cortex Data Lake
- C. WildFire with API calls for automation
- D. 3rd Party SIEM which can ingest NGFW logs and perform event correlation
Answer: A
NEW QUESTION 64
Match the functions to the appropriate processing engine within the dataplane.
Answer:
Explanation:
NEW QUESTION 65
A price-sensitive customer wants to prevent attacks on a Windows Virtual Server. The server will max out at
100Mbps but needs to have 45.000 sessions to connect to multiple hosts within a data center Which VM instance should be used to secure the network by this customer?
- A. VM-100
- B. VM-200
- C. VM-300
- D. VM-50
Answer: D
NEW QUESTION 66
Which three new script types can be analyzed in WildFire? (Choose three.)
- A. PythonScript
- B. JScript
- C. MonoScript
- D. PowerShell Script
- E. VBScript
Answer: B,D,E
Explanation:
Explanation
The WildFire cloud is capable of analyzing the following script types:
* JScript (.js)
* VBScript (.vbs)
* PowerShell Script (.ps1)
https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/script-sample-s
NEW QUESTION 67
Match the WildFire Inline Machine Learning Model to the correct description for that model.
Answer:
Explanation:
NEW QUESTION 68
Which two network events are highlighted through correlation objects as potential security risks? (Choose two.)
- A. Launch of an identified malware executable file
- B. Identified vulnerability exploits
- C. Suspicious host behavior
- D. Endpoints access files from a removable drive
Answer: B,C
NEW QUESTION 69
An SE is preparing an SLR report for a school and wants to emphasize URL filtering capabilities because the school is concerned that its students are accessing inappropriate websites. The URL categories being chosen by default in the report are not highlighting these types of websites. How should the SE show the customer the firewall can detect that these websites are being accessed?
- A. Create a footnote within the SLR generation tool
- B. Edit the Key-Findings text to list the other types of categories that may be of interest
- C. Produce the report and edit the PDF manually
- D. Remove unwanted categories listed under 'High Risk' and use relevant information
Answer: D
NEW QUESTION 70
Which two products can send logs to the Cortex Data Lake? (Choose two.)
- A. Prisma Public Cloud
- B. Prisma Access
- C. AutoFocus
- D. PA-3260 firewall
Answer: B,D
Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/forward-logs-to-cortex-data-lake
NEW QUESTION 71
Which three settings must be configured to enable Credential Phishing Prevention? (Choose three.)
- A. enable User-ID
- B. define URL Filtering Profile
- C. enable App-ID
- D. define an SSL decryption rulebase
- E. validate credential submission detection
Answer: A,B,E
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/prevent-credential-phishing.html
NEW QUESTION 72
Which two products can send logs to the Cortex Data Lake? (Choose two.)
- A. Prisma Public Cloud
- B. Prisma Access
- C. AutoFocus
- D. PA-3260 firewall
Answer: B,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-corte
NEW QUESTION 73
An Administrator needs a PDF summary report that contains information compiled from existing reports based on data for the Top five(5) in each category Which two timeframe options are available to send this report? (Choose two.)
- A. Monthly
- B. Weekly
- C. Daily
- D. Bi-weekly
Answer: B,C
NEW QUESTION 74
Which CLI allows you to view the names of SD-WAN policy rules that send traffic to the specified virtual SD-WAN interface, along with the performance metrics?
A)
B)
C)
D)
- A. Option
- B. Option
- C. Option
- D. Option
Answer: D
Explanation:
https://docs.paloaltonetworks.com/sd-wan/1-0/sd-wan-admin/troubleshooting/use-cli-commands-for-sd-wan-tasks.html
NEW QUESTION 75
When the Cortex Data Lake is sized for Traps Management Service, which two factors should be considered?
(Choose two.)
- A. agent size and OS
- B. retention requirements
- C. the number of Traps agents
- D. Traps agent forensic data
Answer: A,D
NEW QUESTION 76
......
Guaranteed Success with PSE-Strata Dumps: https://www.dumpsreview.com/PSE-Strata-exam-dumps-review.html
Pass Palo Alto Networks PSE-Strata Exam – Experts Are Here To Help You: https://drive.google.com/open?id=1ukceXEM5dhGaIeCDwih5rmel3iaqk1CJ

