Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Paloalto Networks > PSE-Software Firewall Professional > PSE-SWFW-Pro-24

PSE-SWFW-Pro-24 Palo Alto Networks SystemsEngineer Professional - Software Firewall Question and Answers

Question # 4

A company that purchased software NGFW credits from Palo Alto Networks has made a decision on the number of virtual machines (VMs) and licenses they wish to deploy in AWS cloud.

How are the VM licenses created?

A.

Access the AWS Marketplace and use the software NGFW credits to purchase the VMs.

B.

Access the Palo Alto Networks Application Hub and create a new VM profile.

C.

Access the Palo Alto Networks Customer Support Portal and request the creation of a new software NGFW serial number.

D.

Access the Palo Alto Networks Customer Support Portal and create a software NGFW credits deployment profile.

Full Access
Question # 5

When using VM-Series firewall bootstrapping, which three methods can be used to install licensed content, including antivirus, applications, and threats? (Choose three.)

A.

Panorama 10.2 or later to use the content auto push feature

B.

Complete bootstrapping and either Azure Blob storage or Amazon S3 bucket

C.

Content-Security-Policy update URL in the init-cfg.txt file

D.

Custom-AMI or Azure VM image, with content preloaded

E.

Panorama software licensing plugin

Full Access
Question # 6

What are three components of Cloud NGFW for AWS? (Choose three.)

A.

Cloud NGFW Resource

B.

Local or Global Rulestacks

C.

Cloud NGFW Inspector

D.

Amazon S3 bucket

E.

Cloud NGFW Tenant

Full Access
Question # 7

Which public cloud provider requires the creation of subnets that are dedicated to Cloud NGFW endpoints?

A.

Google Cloud Platform (GCP)

B.

Alibaba Cloud

C.

Amazon Web Services (AWS)

D.

 Microsoft Azure

Full Access
Question # 8

What three benefits does flex licensing for VM-Series firewalls offer? (Choose three.)

A.

Licensing additional memory resources to increase session capacity

B.

Licensing Strata Cloud Manager, Panorama with Dedicated Log Collectors, and CDSS per deployment profile

C.

Using a pool of credits for both CN-Series firewall and VM-Series firewall deployment profiles

D.

Moving credits between public and private cloud VM-Series firewall deployments

E.

Vertically scaling the number of licensed cores in an existing fixed deployment profile

Full Access
Question # 9

Which three features are supported by CN-Series firewalls? (Choose three.)

A.

App-ID

B.

Decryption

C.

GlobalProtect

D.

Content-ID

E.

IPSec

Full Access
Question # 10

Why should a customer use advanced versions of Cloud-Delivered Security Services (CDSS) subscriptions compared to legacy versions when creating or editing a deployment profile?

(e.g., using Advanced Threat Prevention instead of Threat Prevention.)

A.

To improve firewall throughput by inspecting hashes of advanced packet headers

B.

To download and install new threat-related signature databases in real-time

C.

To use cloud-scale machine learning inline for detection of highly evasive and zero-day threats

D.

To use external dynamic lists for blocking known malicious threat sources and destinations

Full Access
Question # 11

Which three Cloud NGFW management tasks are inherently performed by the service within AWS and Azure? (Choose three.)

A.

Horizontally scaling out to meet increased traffic demand

B.

Installing new content (applications and threats)

C.

Installing new PAN-OS software updates

D.

Blocking high-risk S2C threats in accordance with SOC2 compliance

E.

Decrypting high-risk SSL traffic

Full Access
Question # 12

Which three methods may be used to deploy CN-Series firewalls? (Choose three.)

A.

Terraform templates

B.

Panorama plugin for Kubernetes

C.

YAML file

D.

Helm charts

E.

Docker Swarm

Full Access
Question # 13

Which three solutions does Strata Cloud Manager (SCM) support? (Choose three.)

A.

Prisma Cloud

B.

CN-Series firewalls

C.

Prisma Access

D.

PA-Series firewalls

E.

VM-Series firewalls

Full Access
Question # 14

What are three Palo Alto Networks VM-Series firewall reference architecture deployment models? (Choose three.)

A.

Cloud NGFW for AWS: Combined Model

B.

AWS VM-Series: Isolated Transit Gateway

C.

Cloud NGFW for Azure: Virtual WAN integration

D.

GCP VM-Series: VPC network peering model with Shared VPC

E.

Azure VM-Series: Distributed VCN - common firewall

Full Access
Question # 15

A partner has successfully showcased and validated the efficacy of the Palo Alto Networks software firewall to a customer.

Which two additional partner-delivered or Palo Alto Networks-delivered common options can the sales team offer to the customer before the sale is completed? (Choose two.)

A.

Hardware collection and recycling services by Palo Alto Networks or by an approved NextWave Partner for the customer’s existing firewall infrastructure

B.

Professional services delivered by Palo Alto Networks or by an approved Certified Professional Services Partner (CPSP) for deployment assistance or QuickStart

C.

Network encryption services (NES) delivered by an approved NES partner to ensure none of the data traversed is readable by third-party entities

D.

Managed services delivered by an approved Managed Security Services Program (MSSP) partner for day-to-day management of the environment

Full Access
Question # 16

A company has created a custom application that collects URLs from various websites and then lists bad sites. They want to update a custom URL category on the firewall with the URLs collected.

Which tool can automate these updates?

A.

Dynamic User Groups

B.

SNMP SET

C.

Dynamic Address Groups

D.

XMLAPI

Full Access
Question # 17

Which statement correctly describes behavior when using Ansible to automate configuration changes on a PAN-OS firewall or in Panorama?

A.

Ansible can only be used to automate configuration changes on physical firewalls but not virtual firewalls.

B.

Ansible requires direct access to the firewall’s CLI to make changes.

C.

Ansible uses the XML API to make configuration changes to PAN-OS.

D.

Ansible requires the use of Python to create playbooks.

Full Access
Question # 18

Which capability, as described in the Securing Applications series of design guides for VM-Series firewalls, is common across Azure, GCP, and AWS?

A.

BGP dynamic routing to peer with cloud and on-premises routers

B.

GlobalProtect portal and gateway services

C.

Horizontal scalability through cloud-native load balancers

D.

Site-to-site VPN

Full Access