Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Paloalto Networks PSE-SWFW-Pro-24 Palo Alto Networks Systems Engineer Professional - Software Firewall Exam Practice Test

Palo Alto Networks Systems Engineer Professional - Software Firewall Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Which three Cloud NGFW management tasks are inherently performed by the service within AWS and Azure? (Choose three.)

Options:

A.

Horizontally scaling out to meet increased traffic demand

B.

Installing new content (applications and threats)

C.

Installing new PAN-OS software updates

D.

Blocking high-risk S2C threats in accordance with SOC2 compliance

E.

Decrypting high-risk SSL traffic

Question 2

Which capability, as described in the Securing Applications series of design guides for VM-Series firewalls, is common across Azure, GCP, and AWS?

Options:

A.

BGP dynamic routing to peer with cloud and on-premises routers

B.

GlobalProtect portal and gateway services

C.

Horizontal scalability through cloud-native load balancers

D.

Site-to-site VPN

Question 3

A partner has successfully showcased and validated the efficacy of the Palo Alto Networks software firewall to a customer.

Which two additional partner-delivered or Palo Alto Networks-delivered common options can the sales team offer to the customer before the sale is completed? (Choose two.)

Options:

A.

Hardware collection and recycling services by Palo Alto Networks or by an approved NextWave Partner for the customer’s existing firewall infrastructure

B.

Professional services delivered by Palo Alto Networks or by an approved Certified Professional Services Partner (CPSP) for deployment assistance or QuickStart

C.

Network encryption services (NES) delivered by an approved NES partner to ensure none of the data traversed is readable by third-party entities

D.

Managed services delivered by an approved Managed Security Services Program (MSSP) partner for day-to-day management of the environment

Question 4

Why should a customer use advanced versions of Cloud-Delivered Security Services (CDSS) subscriptions compared to legacy versions when creating or editing a deployment profile?

(e.g., using Advanced Threat Prevention instead of Threat Prevention.)

Options:

A.

To improve firewall throughput by inspecting hashes of advanced packet headers

B.

To download and install new threat-related signature databases in real-time

C.

To use cloud-scale machine learning inline for detection of highly evasive and zero-day threats

D.

To use external dynamic lists for blocking known malicious threat sources and destinations

Question 5

Which two capabilities are shared by the deployments of Cloud NGFW for Azure and VM-Series firewalls? (Choose two.)

Options:

A.

Using NGFW credits to deploy the firewall

B.

Securing public and private datacenter traffic

C.

Performing firewall administration using Azure Firewall Manager

D.

Securing inbound, outbound, and lateral traffic

Question 6

Which statement correctly describes behavior when using Ansible to automate configuration changes on a PAN-OS firewall or in Panorama?

Options:

A.

Ansible can only be used to automate configuration changes on physical firewalls but not virtual firewalls.

B.

Ansible requires direct access to the firewall’s CLI to make changes.

C.

Ansible uses the XML API to make configuration changes to PAN-OS.

D.

Ansible requires the use of Python to create playbooks.

Question 7

A company wants to make its flexible-license VM-Series firewall, which runs on ESXi, process higher throughput.

Which order of steps should be followed to minimize downtime?

Options:

A.

1. Increase the vCPU within the deployment profile.

2. Retrieve or fetch license keys on the VM-Series NGFW.

3. Confirm the correct tier level and vCPU appear on the NGFW dashboard.

4. Power-off the VM and increase the vCPUs within the hypervisor.

5. Power-on the VM-Series NGFW.

B.

1. Power-off the VM and increase the vCPUs within the hypervisor.

2. Increase the vCPU within the deployment profile.

3. Retrieve or fetch license keys on the VM-Series NGFW.

4. Confirm the correct tier level and vCPU appear on the NGFW dashboard.

5. Power-on the VM-Series NGFW.

C.

1. Increase the vCPU within the deployment profile.

2. Retrieve or fetch license keys on the VM-Series NGFW.

3. Power-off the VM and increase the vCPUs within the hypervisor.

4. Power-on the VM-Series NGFW.

5. Confirm the correct tier level and vCPU appear on the NGFW dashboard.

D.

1. Power-off the VM and increase the vCPUs within the hypervisor.

2. Power-on the VM-Series NGFW.

3. Retrieve or fetch license keys on the VM-Series NGFW.

4. Increase the vCPU within the deployment profile.

5. Confirm the correct tier level and vCPU appear on the NGFW dashboard.

Question 8

What are three benefits of Palo Alto Networks VM-Series firewalls as they relate to direct integration with third-party network virtualization solution providers? (Choose three.)

Options:

A.

Integration with Cisco ACI allows insertion of a virtual firewall and enforcement of dynamic policies between endpoint groups without the need for manual policy adjustments.

B.

Integration with a third-party network virtualization solution allows management and deployment of the entire virtual network and hosts directly from Panorama.

C.

Integration with Nutanix AHV allows the firewall to be dynamically informed of changes in the environment and ensures policy is applied to virtual machines (VMs) as they join the network.

D.

Integration with VMware NSX provides comprehensive visibility and security of all virtualized data center traffic including intra-host ESXi virtual machine (VM) communications.

E.

Integration with network virtualization solution providers allows manual deployment and management of firewall rules through multiple interfaces and front ends specific to each technology.

Question 9

Which tool facilitates a customer's migration from existing legacy firewalls to Palo Alto Networks Next-Generation Firewalls (NGFWs)?

Options:

A.

Expedition

B.

Policy Optimizer

C.

AutoFocus

D.

IronSkillet

Question 10

Which three tools or methods automate VM-Series firewall deployment? (Choose three.)

Options:

A.

Bootstrap the VM-Series firewall

B.

Palo Alto Networks GitHub repository

C.

Panorama Software Library image

D.

Panorama Software Firewall License plugin

E.

Shared Disk Software Library folder

Question 11

Which three features are supported by CN-Series firewalls? (Choose three.)

Options:

A.

App-ID

B.

Decryption

C.

GlobalProtect

D.

Content-ID

E.

IPSec

Question 12

Which two statements describe the functionality of the VM-Series firewall plugin? (Choose two.)

Options:

A.

The installed VM-Series firewall plugin on the VM-Series firewall can only be upgraded or deleted.

B.

The Panorama plugin must be installed on the VM-Series firewall to enable communication with Panorama.

C.

To use Panorama to configure public cloud VM-Series firewall integrations, the VM-Series firewall plugin must be installed on Panorama.

D.

The VM-Series firewall plugin on Panorama is not built in and must be installed to enable communication and manage the environment.

Question 13

Why are VM-Series firewalls now grouped by four tiers?

Options:

A.

To obscure the supported hypervisor manufacturer into generic terms

B.

To simplify the portfolio and reduce the number of VM-Series models customers must choose from

C.

To define the maximum limits for key criteria based on allocated memory

D.

To define the priority level of support customers expect when opening a TAC case, from lowest tier 1 to highest tier 4

Question 14

When registering a software NGFW to the deployment profile without internet access (i.e., offline registration), what information must be provided in the customer support portal?

Options:

A.

Authcode and serial number of the VM-Series firewall

B.

Hypervisor installation ID and software version

C.

Number of data plane and management plane interfaces

D.

CPUID and UUID of the VM-Series firewall

Question 15

Which two benefits are offered by flex licensing for VM-Series firewalls? (Choose two.)

Options:

A.

Credits that do not expire and are available until fully depleted

B.

Deployment of Cloud NGFWs, VM-Series firewalls, and CN-Series firewalls

C.

Ability to move credits between public and private cloud VM-Series firewall deployments

D.

Ability to add or remove subscriptions from software firewalls as needed

Question 16

What are two methods or tools to directly automate the deployment of VM-Series NGFWs into supported public clouds? (Choose two.)

Options:

A.

GitHub PaloAltoNetworks Terraform SWFW modules

B.

Deployment configuration in the public cloud Panorama plugins

C.

paloaltonetworks.panos Ansible collection

D.

panos Terraform provider

Question 17

A company is sponsoring a cybersecurity conference for attendees interested in a range of cybersecurity products that include malware protection, SASE, automation products, and firewalls. The company will deliver a single 3–4 hour conference workshop.

Which cybersecurity portfolio tool will give workshop attendees the appropriate exposure to the widest variety of Palo Alto Networks products?

Options:

A.

Capture the Flag

B.

Ultimate Lab Environment

C.

Demo Environment

D.

Ultimate Test Drive

Question 18

What are three benefits of using Palo Alto Networks software firewalls in public cloud, private cloud, and hybrid cloud environments? (Choose three.)

Options:

A.

They allow for centralized management of all firewalls, regardless of where or how they are deployed.

B.

They allow for complex management of per-use case security needs through multiple point products.

C.

They provide consistent policy enforcement across all architectures, whether on-premises or in the cloud.

D.

They allow management of underlying public cloud architecture without needing to leave the firewall itself.

E.

They create a simplified consumption and deployment model throughout the production environment.

Question 19

Which three statements describe the functionality of a Dynamic Address Group in Security policy? (Choose three.)

Options:

A.

Its update requires "Commit" to enforce membership mapping.

B.

It allows creation and enforcement of consistent Security policy across multiple cloud environments.

C.

Tags cannot be defined statically on the firewall.

D.

It uses tags as filtering criteria to determine IP address mapping to a group.

E.

Its maximum number of registered IP addresses is dependent on the firewall platform.

Question 20

Which three statements describe the functionality of Panorama plugins? (Choose three.)

Options:

A.

Limited to one plugin installation on Panorama

B.

Supports other Palo Alto Networks products and configurations with NGFWs

C.

May be installed on Panorama from the Palo Alto Networks customer support portal

D.

Complies with third-party product/platform integration and configuration with NGFWs

E.

Expands capabilities of hardware and software NGFWs

Question 21

What are two characteristics of firewall flex credit profiles of a credit pool in the Palo Alto Networks Customer Support Portal? (Choose two.)

Options:

A.

Each VM-Series firewall deployment profile can be either fixed or flexible until defined and saved.

B.

All firewalls activated to a deployment profile will have the same subscriptions.

C.

The number of licensed cores must match the number of provisioned CPU cores per instance.

D.

Allocate credits for use with Cloud NGFW for AWS and Azure.

Question 22

Which two deployment models are supported by Cloud NGFW for AWS? (Choose two.)

Options:

A.

Hierarchical

B.

Distributed

C.

Linear

D.

Centralized

Question 23

Which use case is valid for Strata Cloud Manager (SCM)?

Options:

A.

Supporting pre PAN-OS 10.1 SD-WAN migrations to SCM

B.

Provisioning and licensing new CN-Series firewall deployments

C.

Providing AI-Powered ADEM for all Prisma Access users

D.

Providing API-driven plugin framework for integration with third-party ecosystems

Question 24

Which three statements describe functionality of NGFW inline placement for Layer 2/3 implementation? (Choose three.)

Options:

A.

VMs on VMware ESXi hypervisors can be segregated from one another on the network by the VM-Series NGFW by IP addressing and Layer 3 gateways.

B.

VMs on VMware ESXi hypervisors can be segregated from each other by the VM-Series NGFW using VLAN tags while preserving existing Layer 3 gateways.

C.

VM-Series next-generation firewalls cannot be positioned between the physical datacenter network and guest VM workloads.

D.

VM-Series next-generation firewalls do not support VMware vMotion or guest VM workloads.

E.

A next-generation firewall VLAN interface can function as a Layer 3 interface.

Question 25

Which three statements describe the functionality of Dynamic Address Groups and tags? (Choose three.)

Options:

A.

Static tags are part of the configuration on the firewall, while dynamic tags are part of the runtime configuration.

B.

Dynamic Address Groups that are referenced in Security policies must be committed on the firewall.

C.

To dynamically register tags, use either the XML API or the VM Monitoring agent on the firewall or on the User-ID agent.

D.

IP-Tag registrations to Dynamic Address Groups must be committed on the firewall after each change.

E.

Dynamic Address Groups use tags as filtering criteria to determine their members, and filters do not use logical operators.