
Real Palo Alto Networks PSE-PrismaCloud Exam Questions [Updated 2021]
PSE-PrismaCloud Exam Dumps Pass with Updated 2021 PSE Palo Alto Networks System Engineer Professional - Prisma Cloud
Palo Alto Networks PSE-PrismaCloud Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
NEW QUESTION 37
Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)
- A. Excessive login failures
- B. Denial-of-service activity
- C. Unusual user activity
- D. Account hijacking attempts
- E. Suspicious file activity
Answer: A,C,D
Explanation:
Explanation
Account hijacking attempts
-Detect potential account hijacking attempts discovered by identifying unusual login activities. These can happen if there are concurrent login attempts made in short duration from two different geographic locations, which is impossible time travel
, or login from a previously unknown browser, operating system, or location.
Excessive login failures
-Detect potential account hijacking attempts discovered by identifying brute force login attempts. Excessive login failure attempts are evaluated dynamically based on the models observed with continuous learning.
Unusual user activity
-Discover insider threat and an account compromise using advanced data science. The Prisma Cloud machine learning algorithm profiles a user's activities on the console, as well as the usage of access keys based on the location and the type of cloud resources.
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-poli
NEW QUESTION 38
What configuration on AWS is required in order for VM-Series to forward traffic between its network interfaces?
- A. Source Check is disabled and Destination Check is enabled
- B. Both Source and Destination Checks are enabled
- C. Source Check is enabled and Destination Check is disabled
- D. Both Source and Destination Checks are disabled
Answer: D
Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/us
NEW QUESTION 39
What is the scope of the Amazon Web Services 1AM Service?
- A. global
- B. regional
- C. zonal
- D. VPC
Answer: A
NEW QUESTION 40
What are two ways to enable interface swap when deploying a VM-Series NGFW in Google Cloud Platform?
(Choose two.)
- A. in the Google Cloud Console Metadata Field, enter a key-value pair where mgmt-interface-swap is the key and enable is the value
- B. run the PAN-OS CLI command: set system mgmt-interface-swap setting enable yes
- C. create a bootstrap file that includes the mgmt-interface-swap command
- D. run the PAN-OS CLI command: set system mgmt-interface-swap enable yes
Answer: A,C
Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/8-1/vm-series-deployment/set-up-the-vm-series-firewall-on-google
NEW QUESTION 41
Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?
- A. Create alert rules.
- B. Define enterprise settings.
- C. Configure User-ID.
- D. Whitelist IP addresses.
Answer: B
Explanation:
Explanation
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-poli
NEW QUESTION 42
What resource is required to receive inbound traffic from the internet to VM-Series NGFW deployed as a gateway for Azure Stack workloads?
- A. Public IP for the VM-Series NGFW
- B. NAT appliance
- C. Border Customer Network
- D. Azure Stack Edge Router
Answer: B
NEW QUESTION 43
Which three features are not supported by VM-Series NGFWs on Azure Stack? (Choose three.)
- A. Bootstrapping
- B. Azure Application Insight
- C. Resource Group
- D. Azure Security Center
- E. ARM Template
Answer: A,B,E
NEW QUESTION 44
What are the two options to dynamically register tags used by Dynamic Address Groups that are referenced in policy? (Choose two.)
- A. External Dynamic List
- B. CFT Template
- C. XML API
- D. VM Monitoring
Answer: C,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/
NEW QUESTION 45
What is the scope of the Amazon Web Services IAM Service?
- A. global
- B. regional
- C. zonal
- D. VPC
Answer: A
NEW QUESTION 46
Which Amazon Web Services security service can provide host vulnerability information to Prisma Public Cloud?
- A. Amazon Web Services WAF
- B. Inspector
- C. GuardDuty
- D. Shield
Answer: C
Explanation:
Explanation
http://www.paloguard.com/datasheets/prisma-cloud-on-aws.pdf
NEW QUESTION 47
Which two items are required when a VM-100 BYOL instance is upgraded to a VM-300 BYOL instance?
(Choose two.)
- A. API Key
- B. UUID
- C. new Auth Code
- D. CPU ID
Answer: A,C
Explanation:
Explanation
In a public cloud deployment, if your firewall is licensed with the BYOL option, you must Deactivate VM before you change the instance type or VM type and apply the license again on the firewall after you complete the model or instance upgrade. When you change the instance type, because the firewall has a new UUID and CPU ID, the existing license will no longer be valid.
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series-firewall/upgrade-th
NEW QUESTION 48
What are three examples of outbound traffic flow? (Choose three.)
- A. issue apt-get install command on an instance inside Amazon Web Services
- B. issue yum update command on an instance inside Amazon Web Services
- C. Microsoft Windows inside Azure requesting a security patch
- D. outgoing Prisma Public Cloud API calls
- E. web server inside Amazon Web Services receiving web requests from internet
Answer: A,C,D
NEW QUESTION 49
Which three types of security checks can Prisma Public Cloud perform? (Choose three.)
- A. compliance where
- B. event where
- C. config where
- D. network where
- E. user where
Answer: B,C,D
NEW QUESTION 50
How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?
- A. Create an RQL network query to identify traffic from resources tagged "Private."
- B. Open the Asset Dashboard, filter on tags: and choose "Private."
- C. Generate a CIS compliance report and review the "Asset Summary."
- D. Create an RQL config query to identify resources with the tag "Private."
Answer: A
NEW QUESTION 51
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW Vulnerability Protection Profiles?
- A. Use the default Vulnerability Protection Profile to protect servers from all known critical, high, and medium-severity threats
- B. Use the default Vulnerability Protection Profile to protect clients from all known critical, high, and medium-severity threats
- C. Clone the predefined Strict Profile, with packet capture settings disabled
- D. Clone the predefined Strict Profile, with packet capture settings enabled
Answer: B
NEW QUESTION 52
......
PSE-PrismaCloud Exam Dumps, PSE-PrismaCloud Practice Test Questions: https://www.torrentexam.com/PSE-PrismaCloud-exam-latest-torrent.html
Free PSE-PrismaCloud Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=18oa9CODh5cPuKzFrVq9GjLJctnuhRmkr

