Skip to main content

PSE-STRATA-DC Real Exam Questions

Palo Alto Networks System Engineer Professional - Strata Data Center

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

In which two ways can micro-segmentation save money for the enterprise? (Choose two.)

  1. A

    fewer capital expenses because fewer physical servers need to be bought

  2. B

    fewer operating expenses because a smaller data center is operated

  3. C

    fewer operating expenses because less public cloud capacity needs to be rented

  4. D

    fewer capital expenses because the same number of physical servers can be kept in a smaller space

Show answer and explanation

Correct answers: A, C

Question 2 Multiple choice

Which three criteria are required to deploy VM-Series firewalls in High Availability? (Choose three)

  1. A

    deployed on same type of hypervisor

  2. B

    allocate identical CPU cores and network interfaces

  3. C

    assigned identical licenses and subscriptions

  4. D

    deployed on a different host

  5. E

    configured asymmetric routing

Show answer and explanation

Correct answers: A, B, C

Question 3 Single choice

Which VM-Series can be deployed on VMware NSX?

  1. A

    VM-100, VM-200, VM-300. VM-500. VM-1000-HV

  2. B

    VM-50r VM-100, VM-200, VM-300, VM-500

  3. C

    VM-100, VM-200, VM-300, VM-500, VM-700

  4. D

    All VM Series Models can be deployed on VMware NSX

Show answer and explanation

Correct answer: A

Question 4 Single choice

Which environment is least likely to be placed on a public cloud by a hospital that has a large health information management application?

  1. A

    production

  2. B

    development

  3. C

    testing

  4. D

    QA

Show answer and explanation

Correct answer: B

Question 5 Multiple choice

Which two methods provide a virtual IP address when implementing active/active HA? (Choose two )

  1. A

    VRRP

  2. B

    HSRP

  3. C

    floating IP address

  4. D

    ARP load sharing

Show answer and explanation

Correct answers: C, D

Question 6 Single choice

Why are containers uniquely suitable for whitelist-based runtime security?

  1. A

    Developers typically define the processes used in their containers within the Dockerfile

  2. B

    Docker has a built-in runtime analysis capability to aid in whitelisting.

  3. C

    Containers typically have only a few defined processes that should ever be executed.

  4. D

    Operations teams typically know what processes are used within a container

Show answer and explanation

Correct answer: A

Question 7 Single choice

Which interface mode do you use to generate the statdump file that can be converted into an SLR?
Assume that the SE wants to make the evaluation as unintrusive as possible.

  1. A

    Virtual Wire

  2. B

    Layer 2

  3. C

    TAP

  4. D

    Layer 3

Show answer and explanation

Correct answer: C

Question 8 Multiple choice

Which three components are relevant for installing a VM-Series firewall in an OpenStack environment? (Choose three )

  1. A

    bootstrap files including init-cfg.txt. bootstrap.xml, and VM-Series auth codes

  2. B

    a valid VM-Series gcow2 image

  3. C

    Hypervisor: ESX

  4. D

    a valid OpenStack heat template in json format

  5. E

    a valid vmseries vhd image

  6. F

    a valid OpenStack heat template in yaml format

Show answer and explanation

Correct answers: A, B, D

Question 9 Single choice

What is the primary operational benefit of a managed Kubernetes service from a Cloud Service Provider?

  1. A

    reduced complexity, alleviates the need to run masters

  2. B

    less expensive, typically offered at a lower cost than running containers on a VM

  3. C

    more powerful, offers more configuration options than running your own distribution of Kubernetes

  4. D

    increased visibility, provides more insight into application usage than what is natively available

Show answer and explanation

Correct answer: A

Question 10 Single choice

A customer in a non-NSX VMware environment wantsto add a VM-Series firewall and to partition an existing group of VMs in the same subnet into two groups. One group needs no additional security, but the
second group requires substantially more security.

How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?

  1. A

    Create a new virtual switch and use the VM-Series firewall to separate virtual switches using Virtual Wire mode Then move the guests that require more security into the new virtual switch

  2. B

    Edit the IP address of all of the affected VMs

  3. C

    Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete the old default gateway

  4. D

    Create a Layer 3 interface in the same subnet as the VMs and configure proxy ARP

Show answer and explanation

Correct answer: D