A fully updated 2022 PSE-Strata Exam Dumps exam guide from training expert Lead1Pass [Q39-Q55]

Share

A fully updated 2022 PSE-Strata Exam Dumps exam guide from training expert Lead1Pass

Provides complete coverage of every objective on exam and exam preparation PSE-Strata

NEW QUESTION 39
Palo Alto Networks publishes updated Command-and-Control signatures. How frequently should the related signatures schedule be set?

  • A. Once a day
  • B. Once an hour
  • C. Once every minute
  • D. Once a week

Answer: A

 

NEW QUESTION 40
Which CLI command will allow you to view latency, jitter and packet loss on a virtual SD-WAN interface?
A)

B)

C)

D)

  • A. Option
  • B. Option
  • C. Option
  • D. Option

Answer: D

 

NEW QUESTION 41
Which three categories are identified as best practices in the Best Practice Assessment tool? (Choose three.)

  • A. use of decryption policies
  • B. expose the visibility and presence of command-and-control sessions
  • C. measure the adoption of URL filters. App-ID. User-ID
  • D. use of device management access and settings
  • E. identify sanctioned and unsanctioned SaaS applications

Answer: C,E

 

NEW QUESTION 42
XYZ Corporation has a legacy environment with asymmetric routing. The customer understands that Palo Alto Networks firewalls can support asymmetric routing with redundancy.
Which two features must be enabled to meet the customer's requirements? (Choose two.)

  • A. Policy-based forwarding
  • B. HA active/passive
  • C. HA active/active
  • D. Virtual systems

Answer: A,C

 

NEW QUESTION 43
Match the functions to the appropriate processing engine within the dataplane.

Answer:

Explanation:

 

NEW QUESTION 44
Which three methods used to map users to IP addresses are supported in Palo Alto Networks firewalls?
(Choose three.)

  • A. RADIUS
  • B. Active Directory monitoring
  • C. Client Probing
  • D. TACACS
  • E. Lotus Domino
  • F. SNMP server
  • G. eDirectory monitoring

Answer: A,C,D

Explanation:
Explanation
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/user-id-concepts/user-mapping

 

NEW QUESTION 45
A company has deployed the following
* VM-300 firewalls in AWS
* endpoint protection with the Traps Management Service
* a Panorama M-200 for managing its VM-Series firewalls
* PA-5220s for its internet perimeter,
* Prisma SaaS for SaaS security.
Which two products can send logs to the Cortex Data Lake? (Choose two).

  • A. Traps Management Service
  • B. Prisma SaaS
  • C. VM-300 firewalls
  • D. Panorama M-200 appliance

Answer: C,D

 

NEW QUESTION 46
Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?

  • A. URL Filtering on the firewall, and MineMeld on Panorama
  • B. WildFire on the firewall, and AutoFocus on Panorama
  • C. GlobalProtect on the firewall, and Threat Prevention on Panorama
  • D. Threat Prevention on the firewall, and Support on Panorama

Answer: D

 

NEW QUESTION 47
What can be applied to prevent users from unknowingly downloading malicious file types from the internet?

  • A. A file blocking profile to security policy rules that allow general web access
  • B. An antivirus profile to security policy rules that deny general web access
  • C. A vulnerability profile to security policy rules that deny general web access
  • D. A zone protection profile to the untrust zone

Answer: A

 

NEW QUESTION 48
An Administrator needs a PDF summary report that contains information compiled from existing reports based on data for the Top five(5) in each category Which two timeframe options are available to send this report?
(Choose two.)

  • A. Daily
  • B. Bi-weekly
  • C. Weekly
  • D. Monthly

Answer: A,C

 

NEW QUESTION 49
As you prepare to scan your Amazon S3 account, what enables Prisma service permission to access Amazon S3?

  • A. AWS account ID
  • B. secret access key
  • C. access key ID
  • D. administrative Password

Answer: C

 

NEW QUESTION 50
Which profile or policy should be applied to protect against port scans from the internet?

  • A. Interface management profile on the zone of the ingress interface
  • B. Security profiles to security policy rules for traffic sourcing from the untrust zone
  • C. Zone protection profile on the zone of the ingress interface
  • D. An App-ID security policy rule to block traffic sourcing from the untrust zone

Answer: C

 

NEW QUESTION 51
Which two components must be configured within User-ID on a new firewall that has been implemented? (Choose two.)

  • A. 802.1X Authentication
  • B. Group Mapping
  • C. Proxy Authentication
  • D. User Mapping

Answer: B,D

 

NEW QUESTION 52
Which are the three mandatory components needed to run Cortex XDR? (Choose three.)

  • A. Traps
  • B. NGFW with PANOS 8 0.5 or later
  • C. Panorama
  • D. Directory Syn Service
  • E. Pathfinder
  • F. Cortex Data Lake

Answer: B,D,F

Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/cortex-xdr-prevent-overview/cort

 

NEW QUESTION 53
Palo Alto Networks publishes updated Command-and-Control signatures. How frequently should the related signatures schedule be set?

  • A. Once an hour
  • B. Once every minute
  • C. Once a day
  • D. Once a week

Answer: D

 

NEW QUESTION 54
When having a customer pre-sales call, which aspects of the NGFW should be covered?

  • A. Palo Alto Networks URL Filtering allows you to monitor and control the sites users can access, to prevent phishing attacks by controlling the sites to which users can submit valid corporate credentials, and to enforce safe search for search engines like Google and Bing
  • B. The NGFW creates tunnels that allow users/systems to connect securely over a public network, as if they were connecting over a local area network (LAN). To set up a VPN tunnel you need a pair of devices that can authenticate each other and encrypt the flow of information between them The devices can be a pair of Palo Alto Networks firewalls, or a Palo Alto Networks firewall along with a VPN-capable device from another vendor
  • C. The Palo Alto Networks-developed URL filtering database, PAN-DB provides high-performance local caching for maximum inline performance on URL lookups, and offers coverage against malicious URLs and IP addresses. As WildFire identifies unknown malware, zero-day exploits, and advanced persistent threats (APTs), the PAN-DB database is updated with information on malicious URLs so that you can block malware downloads and disable Command and Control (C2) communications to protect your network from cyberthreats. URL categories that identify confirmed malicious content - malware, phishing, and C2 are updated every five minutes - to ensure that you can manage access to these sites within minutes of categorization
  • D. The NGFW simplifies your operations through analytics and automation while giving you consistent protection through exceptional visibility and control across the data center, perimeter, branch, mobile and cloud networks

Answer: A

 

NEW QUESTION 55
......

Tested Material Used To PSE-Strata: https://www.lead1pass.com/Palo-Alto-Networks/PSE-Strata-practice-exam-dumps.html

Steps Necessary To Pass The PSE-Strata Exam: https://drive.google.com/open?id=1RvgIESfQmX8DoF4KMwBONBGTzEB5QUr_