Winter Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

PSE-SoftwareFirewall Questions and Answers

Question # 6

Which type of group allows sharing cloud-learned tags with on-premises firewalls?

A.

Notify •

B.

Address

C.

Template

D.

Device

Full Access
Question # 7

Which component can provide application-based segmentation and prevent lateral threat movement?

A.

DNS Security

B.

NAT

C.

App-ID •

D.

URL Filtering

Full Access
Question # 8

How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

A.

Through a policy-based redirect (PBR)

B.

By creating an access policy

C.

By using contracts between endpoint groups that send traffic to the firewall using a shared policy

D.

Through a virtual machine (VM) monitor domain

Full Access
Question # 9

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

A.

Threat Prevention

B.

SD-WAN

C.

Intelligent Traffic Offload

D.

WildFire

Full Access
Question # 10

Which solution is best for securing an EKS environment?

A.

API orchestration

B.

CN-Series high availability (HA) pair

C.

PA-Series using load sharing

D.

VM-Series single host

Full Access
Question # 11

What can software next-generation firewall (NGFW) credits be used to provision?

A.

Enablement of DNS security

B.

Virtual Panorama appliances

C.

Remote browser isolation

D.

Migrating NGFWs from hardware to VMs

Full Access
Question # 12

What is a benefit of CN-Series firewalls securing traffic between pods and other workload types?

A.

It allows for automatic deployment, provisioning, and immediate policy enforcement without any manual intervention.

B.

It ensures consistent security across the entire environment.

C.

It allows extension of Zero Trust Network Security to the most remote locations and smallest branches.

D.

It protects data center and internet gateway deployments.

Full Access
Question # 13

Which software firewall would assist a prospect who is interested in securing extensive DevOps deployments?

A.

VM-Series

B.

CN-Series

C.

Ion-Series

D.

Cloud next-generation firewall (NGFW)

Full Access
Question # 14

Which software firewall would help a prospect interested in securing an environment with Kubernetes?

A.

ML-Series

B.

CN-Series

C.

KN-Series

D.

VM-Series

Full Access
Question # 15

Which two design options address split brain when configuring high availability (HA)? (Choose two.)

A.

Bundling multiple interfaces in an aggregated interface group and assigning HA2

B.

Using the heartbeat backup

C.

Sending heartbeats across the HA2 interfaces

D.

Adding a backup HA1 interface

Full Access
Question # 16

Which two public cloud platforms does the VM-Series plugin support? (Choose two.)

A.

IBM Cloud

B.

OCI

C.

Amazon Web Services (AWS)

D.

Azure

Full Access
Question # 17

What is required to integrate a Palo Alto Networks VM-Series firewall with Azure Orchestration?

A.

Client-ID

B.

API Key

C.

Dynamic Address Groups

D.

Aperture orchestration engine

Full Access
Question # 18

How are CN-Series firewalls licensed?

A.

Management-plane vCPU

B.

Data-plane vCPU

C.

Control-plane vCPU

D.

Service-plane vCPU

Full Access
Question # 19

Why are VM-Series firewalls and hardware firewalls that are external to the Kubernetes cluster problematic for protecting containerized workloads?

A.

They function differently based on whether they are located inside or outside of the cluster.

B.

They are located outside the cluster and have no visibility into application-level cluster traffic.

C.

They are managed by another entity when located inside the cluster.

D.

They do not scale independently of the Kubernetes cluster.

Full Access