Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Paloalto Networks PCSFE - Palo Alto Networks Certified Software Firewall Engineer (PCSFE)

Page: 2 / 2
Total 65 questions

What helps avoid split brain in active-passive high availability (HA) pair deployment?

A.

Using a standard traffic interface as the HA2 backup

B.

Enabling preemption on both firewalls in the HA pair

C.

Using the management interface as the HA1 backup link

D.

Using a standard traffic interface as the HA3 link

Which element protects and hides an internal network in an outbound flow?

A.

DNS sinkholing

B.

User-ID

C.

App-ID

D.

NAT

What can software next-generation firewall (NGFW) credits be used to provision?

A.

Remote browser isolation

B.

Virtual Panorama appliances

C.

Migrating NGFWs from hardware to VMs

D.

Enablement of DNS security

Which component can provide application-based segmentation and prevent lateral threat movement?

A.

DNS Security

B.

NAT

C.

URL Filtering

D.

App-ID

A customer in a VMware ESXi environment wants to add a VM-Series firewall and partition an existing group of virtual machines (VMs) in the same subnet into two groups. One group requires no additional security, but the second group requires substantially more security.

How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?

A.

Edit the IP address of all of the affected VMs. www*

B.

Create a new virtual switch and use the VM-Series firewall to separate virtual switches using virtual wire mode. Then move the guests that require more security into the new virtual switch.

C.

Create a Layer 3 interface in the same subnet as the VMs and then configure proxy Address Resolution Protocol (ARP).

D.

Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete it.

Which three NSX features can be pushed from Panorama in PAN-OS? (Choose three.)

A.

Security group assignment of virtual machines (VMs)

B.

Security groups

C.

Steering rules

D.

User IP mappings

E.

Multiple authorization codes

Which offering inspects encrypted outbound traffic?

A.

WildFire

B.

TLS decryption

C.

Content-ID

D.

Advanced URL Filtering (AURLF)

What does the number of required flex credits for a VM-Series firewall depend on?

A.

vCPU allocation

B.

IP address allocation

C.

Network interface allocation

D.

Memory allocation

Which type of group allows sharing cloud-learned tags with on-premises firewalls?

A.

Device

B.

Notify

C.

Address

D.

Template