Palo Alto Networks PSE Strata Exam Practice Questions (P. 5)
- Full Access (136 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
Which three features are used to prevent abuse of stolen credentials? (Choose three.)
- Amulti-factor authenticationMost Voted
- BURL Filtering ProfilesMost Voted
- CWildFire Profiles
- DPrisma Access
- ESSL decryption rulesMost Voted
Correct Answer:
ACE
Reference:
https://www.paloaltonetworks.com/company/press/2017/palo-alto-networks-delivers-industry-first-capabilities-to-prevent-credential-theft-and-abuse
ACE
Reference:
https://www.paloaltonetworks.com/company/press/2017/palo-alto-networks-delivers-industry-first-capabilities-to-prevent-credential-theft-and-abuse
send
light_mode
delete
Question #22
A customer has business-critical applications that rely on the general web-browsing application. Which security profile can help prevent drive-by-downloads while still allowing web-browsing traffic?
- AFile Blocking ProfileMost Voted
- BDoS Protection Profile
- CURL Filtering Profile
- DVulnerability Protection Profile
Correct Answer:
A
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjaw53CvdHyAhUPy4UKHXT5D-MQFnoECAMQAQ&url=https%
3A%2F%2Fknowledgebase.paloaltonetworks.com%2Fservlet%2FfileField%3FentityId%3Dka10g000000U0roAAC%26field%
3DAttachment_1__Body__s&usg=AOvVaw3DCBM7-FwWInkWYANLrzUt
(32)
A
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjaw53CvdHyAhUPy4UKHXT5D-MQFnoECAMQAQ&url=https%
3A%2F%2Fknowledgebase.paloaltonetworks.com%2Fservlet%2FfileField%3FentityId%3Dka10g000000U0roAAC%26field%
3DAttachment_1__Body__s&usg=AOvVaw3DCBM7-FwWInkWYANLrzUt
(32)
send
light_mode
delete
Question #23
Which three settings must be configured to enable Credential Phishing Prevention? (Choose three.)
- Avalidate credential submission detection
- Benable User-IDMost Voted
- Cdefine an SSL decryption rulebaseMost Voted
- Ddefine URL Filtering ProfileMost Voted
- EEnable App-ID
Correct Answer:
ABD
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/prevent-credential-phishing.html
ABD
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/prevent-credential-phishing.html
send
light_mode
delete
Question #24
A customer with a legacy firewall architecture is focused on port and protocol level security, and has heard that next generation firewalls open all ports by default.
What is the appropriate rebuttal that positions the value of a NGFW over a legacy firewall?
What is the appropriate rebuttal that positions the value of a NGFW over a legacy firewall?
- APalo Alto Networks does not consider port information, instead relying on App-ID signatures that do not reference ports
- BDefault policies block all interzone traffic. Palo Alto Networks empowers you to control applications by default ports or a configurable list of approved ports on a per-policy basisMost Voted
- CPalo Alto Networks keep ports closed by default, only opening ports after understanding the application request, and then opening only the application- specified ports
- DPalo Alto Networks NGFW protects all applications on all ports while leaving all ports opened by default
Correct Answer:
C
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVwCAK
C
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVwCAK
send
light_mode
delete
Question #25
Which four actions can be configured in an Anti-Spyware profile to address command-and-control traffic from compromised hosts? (Choose four.)
- AResetMost Voted
- BQuarantine
- CDropMost Voted
- DAllowMost Voted
- ERedirect
- FAlertMost Voted
Correct Answer:
ACDF
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-profiles
ACDF
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-profiles
send
light_mode
delete
All Pages