Skip to main content

PSE-DATACENTER Real Exam Questions

Palo Alto Networks System Engineer Professional - Data Center

25 questions available · Page 1 of 3

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which security component can detect command-and-control traffic sent from multiple endpoints within a corporate data center?

  1. A

    stateless firewall

  2. B

    next-generation firewall

  3. C

    personal endpoint firewall

  4. D

    port-based firewall

Show answer and explanation

Correct answer: B

Question 2 Single choice

A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?

  1. A

    Define a custom App-ID to ensure that only legitimate application traffic reaches the server

  2. B

    Add QoS Profiles to throttle incoming requests

  3. C

    Add a tuned DoS Protection Profile

  4. D

    Add an Anti-Spyware Profile to block attacking IP address

Show answer and explanation

Correct answer: C

Question 3 Multiple choice

What are three sources of malware sample data for the Palo Alto Networks Threat Intelligence Cloud? (Choose three.)

  1. A

    Third-Party data feeds, like the partnership with ProofPoint and the Cyber Threat Alliance

  2. B

    Palo Alto Networks AutoFocus generated Correlation Objects

  3. C

    Palo Alto Networks Next Generation Firewalls deployed with Wildfire Analysis Security Profiles

  4. D

    WF-500 configured as private clouds for privacy concerns

  5. E

    Palo Alto Networks non-firewall products, like Traps and Aperture

Show answer and explanation

Correct answers: A, B, E

Question 4 Single choice

A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect this server against resource exhaustion originating from multiple IP addresses (DDoS attack)?

  1. A

    Define a custom App-ID to ensure that only legitimate application traffic reaches the server.

  2. B

    Add a Vulnerability Protection Profile to block the attack.

  3. C

    Add QoS Profiles to throttle incoming requests.

  4. D

    Add a DoS Protection Profile with defined session count.

Show answer and explanation

Correct answer: D

Question 5 Single choice

What is the result of deploying virtualization in your data center?

  1. A

    reduced security threat

  2. B

    reduced operational costs

  3. C

    increased hardware capital costs

  4. D

    increased host provisioning

Show answer and explanation

Correct answer: B

Question 6 Single choice

A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect tins server against resource exhaustion originating from multiple IP address (DDoS attack)?

  1. A

    Define a custom App-ID to ensure that only legitimate application traffic reaches the server

  2. B

    Add a DoS Protection Profile with defined session count.

  3. C

    Add a Vulnerability Protection Profile to block the attack.

  4. D

    Add QoS Profiles to throttle incoming requests.

Show answer and explanation

Correct answer: B

Question 7 Single choice

Which statement is true regarding the HA3 interface on VM - Series firewalls in an HA configuration?

  1. A

    The second VM - Series firewall should be in a different host and the HA3 connection should be over a
    dedicated high - speed link .

  2. B

    The second VM - Series firewall should be in the same virtual machine so the HA3 connection does not have to travel over a physical connection .

  3. C

    The HA3 connection should traverse no more than a single virtual switch.

  4. D

    There is no HA3 connection on a VM - Series firewall.

Show answer and explanation

Correct answer: D

Question 8 Single choice

A service provider has acquired a pair of PA-7080s for its data center to secure its customer base's traffic.
The server provider's traffic is largely generated by smart phones and averages 6,000,000 concurrent sessions.

Which Network Processing Card should be recommended in the Bill of Materials?

  1. A

    PA-7000-40G-NPC

  2. B

    PA-7000-20GQ-NPC

  3. C

    PA-7000-20GQXM-NPC

  4. D

    PA-7000-20G-NPC

Show answer and explanation

Correct answer: C

Question 9 Multiple choice

Which of these statements is true about Dynamic Address Groups?

  1. A

    T hey allow you to create a policy that automatically adapts to changes -- adds, moves, or deletions of servers.

  2. B

    They enable the flexibility to apply different rules to th e same server based on tags that define its role on the network, the operating system, or the different kinds of traffic it processes.

  3. C

    A dynamic address group uses tags as a filtering criterion to determine its members.

  4. D

    The filtering criteria uses logical and , or , and not operators.

Show answer and explanation

Correct answers: A, B, C

Question 10 Multiple choice

What are two benefits of using Panorama for a customer who is deploying virtual firewalls to secure data center traffic? (Choose two.)

  1. A

    It can monitor the virtual firewalls' physical hosts and Vmotion them as necessary.

  2. B

    It can bootstrap the virtual firewall for dynamic deployment scenarios

  3. C

    It can manage the virtual firewalls' resource use, allowing for VM resource over-subscription.

  4. D

    It can provide the Automated Correlation Engine functionality, which the virtual firewalls do not support

Show answer and explanation

Correct answers: B, D