Winter Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

PCSFE Questions and Answers

Question # 6

Which two methods of Zero Trust implementation can benefit an organization? (Choose two.)

A.

Compliance is validated.

B.

Boundaries are established.

C.

Security automation is seamlessly integrated.

D.

Access controls are enforced.

Full Access
Question # 7

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

A.

Intelligent Traffic Offload

B.

Threat Prevention

C.

WildFire

D.

SD-WAN

Full Access
Question # 8

Which two steps are involved in deployment of a VM-Series firewall on NSX? (Choose two.)

A.

Create a virtual data center (vDC) and a vApp that includes the VM-Series firewall.

B.

Obtain the Amazon Machine Images (AMIs) from marketplace.

C.

Enable communication between Panorama and the NSX Manager.

D.

Register the VM-Series firewall as a service.

Full Access
Question # 9

Which solution is best for securing an EKS environment?

A.

VM-Series single host

B.

CN-Series high availability (HA) pair

C.

PA-Series using load sharing

D.

API orchestration

Full Access
Question # 10

Which Palo Alto Networks firewall provides network security when deploying a microservices-based application?

A.

PA-Series

B.

ICN-Series

C.

VM-Series

D.

HA-Series

Full Access
Question # 11

Which component allows the flexibility to add network resources but does not require making changes to existing policies and rules?

A.

Content-ID

B.

External dynamic list

C.

App-ID

D.

Dynamic address group

Full Access
Question # 12

Where do CN-Series devices obtain a VM-Series authorization key?

A.

Panorama

B.

Local installation

C.

GitHub

D.

Customer Support Portal

Full Access
Question # 13

Which PAN-OS feature allows for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment?

A.

Boundary automation

B.

Hypervisor integration

C.

Bootstrapping

D.

Dynamic Address Group

Full Access
Question # 14

Which two design options address split brain when configuring high availability (HA)? (Choose two.)

A.

Adding a backup HA1 interface

B.

Using the heartbeat backup

C.

Bundling multiple interfaces in an aggregated interface group and assigning HA2

D.

Sending heartbeats across the HA2 interfaces

Full Access
Question # 15

When implementing active-active high availability (HA), which feature must be configured to allow the HA pair to share a single IP address that may be used as the network's gateway IP address?

A.

ARP load sharing

B.

Floating IP address

C.

HSRP

D.

VRRP

Full Access
Question # 16

What must be enabled when using Terraform templates with a Cloud next-generation firewall (NGFW) for Amazon Web Services (AWS)?

A.

AWS CloudWatch logging

B.

Access to the Cloud NGFW for AWS console

C.

Access to the Palo Alto Networks Customer Support Portal

D.

AWS Firewall Manager console access

Full Access
Question # 17

Which feature provides real-time analysis using machine learning (ML) to defend against new and unknown threats?

A.

Advanced URL Filtering (AURLF)

B.

Cortex Data Lake

C.

DNS Security

D.

Panorama VM-Series plugin

Full Access
Question # 18

A CN-Series firewall can secure traffic between which elements?

A.

Host containers

B.

Source applications

C.

Containers

D.

IPods

Full Access
Question # 19

Which two configuration options does Palo Alto Networks recommend for outbound high availability (HA) design in Amazon Web Services using a VM-Series firewall? (Choose two.)

A.

Transit VPC and Security VPC

B.

Traditional active-active HA

C.

Transit gateway and Security VPC

D.

Traditional active-passive HA

Full Access