Skip to main content

PSE-PLATFORM Real Exam Questions

Palo Alto Networks System Engineer Professional - Platform

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

A customer is targeted by a true zero-day, targeted attack. However, the customer is protected by the Palo Alto Networks security platform.
The attack leverages a previously unknown vulnerability in IE but utilizes existing hacking techniques on the endpoint. It is transported over standard HTTP traffic and conforms to the HTML standards. It then attempts to download from a website, compromised specifically for this attack, a custom piece of malware to run on the endpoints.

Which element of the platform will stop this attack?

  1. A

    App-ID

  2. B

    PAN-DB

  3. C

    Traps

  4. D

    WildFire

Show answer and explanation

Correct answer: D

Question 2 Multiple choice

What are three considerations when deploying User-ID. (Choose three.)

  1. A

    Enable WMI probing in high security networks

  2. B

    User-ID can support a maximum hops.

  3. C

    Specify included and excluded networks when configuring User-ID

  4. D

    Use a dedicated service account for User-ID services with the minimal permissions necessary.

  5. E

    Only enable User-ID on trusted zones

Show answer and explanation

Correct answers: A, C, D

Question 3 Single choice

Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?

  1. A

    WildFire on the firewall, and AutoFocus on Panorama

  2. B

    URL Filtering on the firewall, and MindMeld on Panorama

  3. C

    Threat Prevention on the firewall, and Support on Panorama

  4. D

    GlobalProtect on the firewall, and Threat Prevention on Panorama

Show answer and explanation

Correct answer: C

Question 4 Single choice

Which variable is used to regulate the rate of file submission to WildFire?

  1. A

    Based on the purchase license

  2. B

    Maximum number of files per minute

  3. C

    Available bandwidth

  4. D

    Maximum number of files per day

Show answer and explanation

Correct answer: B

Explanation

https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/submit-files-for-wildfire-analysis/firewall-file-forwarding-capacity-by-model

Question 5 Single choice

How often are regularly scheduled update for the Anti-virus Application, Threats, and Wildfire subscription databases made available by Palo Alto Networks in PAN-OS 8.0?

  1. A

    Anti-Virus (Daily) Application (Weekly), Threats (Daily), Wildfire (5 Minutes)

  2. B

    Anti-Virus (Weekly) Application (Daily), Threats (Daily), Wildfire (5 Minutes)

  3. C

    Anti-Virus (Daily) Application (Weekly), Threats (Weekly), Wildfire (5 Minutes)

  4. D

    Anti-Virus (Weekly) Application (Daily), Threats (Weekly), Wildfire (5 Minutes)

Show answer and explanation

Correct answer: C

Question 6 Multiple choice

Which three network events are highlighted through correlation objects as a potential security risks? (Choose three.)

  1. A

    Identified vulnerability exploits

  2. B

    Suspicious traffic patterns

  3. C

    Known command-and-control activity

  4. D

    Launch of an identified malware executable file

  5. E

    Endpoints access files from a removable drive

Show answer and explanation

Correct answers: A, B, C

Question 7 Single choice

Because of regulatory compliance a customer cannot decrypt specific types of traffic.

Which license should an SE recommend to the customer who will be decrypting traffic on the Palo Alto Networks firewall?

  1. A

    App-ID, to use applications as match criteria in the decryption policy rules

  2. B

    SSL Decryption, for inbound inspection and granular Forward Proxy SSL decryption

  3. C

    Support, to request custom categories as match criteria in decryption policy rules

  4. D

    URL Filtering, to use predefined URL categories as match criteria in the decryption policy rules

Show answer and explanation

Correct answer: D

Question 8 Multiple choice

Where are three tuning considerations when building a security policy to protect against modern day attacks? (Choose three)

  1. A

    Create an anti-spyware profile to block all spyware

  2. B

    Create a vulnerability protection profile to block all the vulnerabilities with severity low and higher

  3. C

    Create an SSL Decryption policy to decrypt 100% of the traffic

  4. D

    Create an antivirus profile to block all content that matches and antivirus signature

  5. E

    Create a WildFire profile to schedule file uploads during low network usage windows

Show answer and explanation

Correct answers: B, C, E

Question 9 Single choice

A customer is worried about unknown attacks, but due to privacy and regulatory issues, won't implement
SSL decrypt.

How can the platform still address this customer's concern?

  1. A

    It pivots the conversation to Traps on the endpoint preventing unknown exploits and malware there instead.

  2. B

    It bypasses the need to decrypt SSL Traffic by analyzing the file while still encrypted.

  3. C

    It shows how AutoFocus can provide visibility into targeted attacks at the industry sector.

  4. D

    It overcomes reservations about SSL decrypt by offloading to a higher capacity firewall to help with the decrypt throughput.

Show answer and explanation

Correct answer: A

Question 10 Multiple choice

Which three actions should be taken before deploying a firewall evaluation unit in the customer's environment? (Choose three.)

  1. A

    Inform the customer that they will need to provide a SPAN port for the evaluation unit assuming a TAP mode deployment.

  2. B

    Request that the customs make port 3978 available to allow the evaluation unit to communicate with Panorama.

  3. C

    Reset the evaluation unit to factory default to ensure that data from any previous customer evaluation is removed.

  4. D

    Upgrade the evaluation unit to the most current recommended firmware, unless a demo of the upgrade process is planned.

  5. E

    Set expectations around which information will be presented in the Security Lifecycle Review because sensitive information may be made visible.

Show answer and explanation

Correct answers: A, C, D