Winter Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Paloalto Networks PSE-DataCenter SE Professional Accreditation-Data Center Exam Practice Test

SE Professional Accreditation-Data Center Questions and Answers

Question 1

Which statement is true regarding the HA3 interface on VM - Series firewalls in an HA configuration?

Options:

A.

The second VM - Series firewall should be in a different host and the HA3 connection should be over a dedicated high - speed link .

B.

The second VM - Series firewall should be in the same virtual machine so the HA3 connection does not have to travel over a physical connection .

C.

The HA3 connection should traverse no more than a single virtual switch.

D.

There is no HA3 connection on a VM - Series firewall.

Question 2

What is the maximum number of QSFP+ interfaces that can be supported in a PA - 7080, and what is the minimum version of PAN - OS required to support them?

Options:

A.

12, PAN - OS 6.0

B.

12, PAN - OS 6.1

C.

12, PAN - OS 7.0

D.

20, PAN - OS 6.0

E.

20, PAN - OS 6.1

F.

20, PAN - OS 7.0

Question 3

Which two designs require virtual systems? (Choose two.)

Options:

A.

A shared gateway interface that does not need a full administrative boundary

B.

A virtual router as a replacement for an internet-facing router

C.

A single physical firewall shared by different organizations, each with unique traffic control needs

D.

A VMware NSX deployment that needs micros segmentation

Question 4

A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?

Options:

A.

Define a custom App-ID to ensure that only legitimate application traffic reaches the server

B.

Add QoS Profiles to throttle incoming requests

C.

Add a tuned DoS Protection Profile

D.

Add an Anti-Spyware Profile to block attacking IP address

Question 5

A service provider has acquired a pair of PA-7080s for its data center to secure its customer base’s traffic. The server provider’s traffic is largely generated by smart phones and averages 6,000,000 concurrent sessions.

Which Network Processing Card should be recommended in the Bill of Materials?

Options:

A.

PA-7000-40G-NPC

B.

PA-7000-20GQ-NPC

C.

PA-7000-20GQXM-NPC

D.

PA-7000-20G-NPC

Question 6

A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks.

How can the Palo Alto Networks NGFW be configured to specifically protect tins server against resource exhaustion originating from multiple IP address (DDoS attack)?

Options:

A.

Define a custom App-ID to ensure that only legitimate application traffic reaches the server

B.

Add a DoS Protection Profile with defined session count.

C.

Add a Vulnerability Protection Profile to block the attack.

D.

Add QoS Profiles to throttle incoming requests.

Question 7

In addition to the expanded capacity for NPCs, what else is improved in the PA - 7080 over the PA - 7050?

Options:

A.

A second LPC is standard.

B.

A second SMC is standard.

C.

Front - to - back airflow is standard.

D.

Available 100Gb p s interfaces , but only with PAN - OS 7.0 and higher