Latest [Oct 17, 2023] Palo Alto Networks PSE-PrismaCloud Real Exam Dumps PDF
PSE-PrismaCloud Practice Test Questions Updated 62 Questions
Palo Alto Networks PSE-PrismaCloud certification is a professional accreditation offered by Palo Alto Networks to system engineers who possess a deep understanding of the Prisma Cloud platform. PSE Palo Alto Networks System Engineer Professional - Prisma Cloud certification is designed to validate the skills and expertise of individuals in deploying, managing, and troubleshooting Prisma Cloud environments.
NEW QUESTION # 16
How does a customer that has deployed a VM-Series NGFW on Microsoft Azure using a BYOL license change to a PAYG license structure?
- A. launch a new VM using the PAYG image
- B. purchase a new PAYG license from a reseller
- C. purchase a new PAYG license for Microsoft Azure from Palo Alto Networks
- D. go to Palo Alto Networks Support website to change the BYOL license to a PAYG license
Answer: A
NEW QUESTION # 17
can you create a custom compliance standard in Prisma Public Cloud?
- A. Generate a new Compliance Report.
- B. Create compliance framework in a spreadsheet then import into Prisma Public Cloud.
- C. From Compliance tab > Compliance Standards, click "Add New."
- D. From Compliance tab, clone a default framework and customize.
Answer: C
Explanation:
Explanation
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-compliance/create-a-c
NEW QUESTION # 18
What are two ways to enable interface swap when deploying a VM-Series NGFW in Google Cloud Platform?
(Choose two.)
- A. create a bootstrap file that includes the mgmt-interface-swap command
- B. run the PAN-OS CLI command: set system mgmt-interface-swap enable yes
- C. run the PAN-OS CLI command: set system mgmt-interface-swap setting enable yes
- D. in the Google Cloud Console Metadata Field, enter a key-value pair where mgmt-interface-swap is the key and enable is the value
Answer: A,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/8-1/vm-series-deployment/set-up-the-vm-series-firewall-on-google
NEW QUESTION # 19
Which RQL string monitors all traffic from the Internet and Suspicious IPs destined for your Amazon Web Services databases?
- A. network where source.publicnetwork IN ('Suspicious IPs', 'Internet IPs') and dest.resource IN (resource where role IN ('LDAP'))
- B. network where source.publicnetwork IN ('Suspicious IPs', 'Internet IPs') and dest resource IN (resource where role IN ('AWS RDS'. 'Database'))
- C. network where dest.resource IN (resource where role = 'Database'}
- D. network where source.publicnetwork IN ('Suspicious IPs') and dest.resource IN (resource where role IN ('AWS RDS', 'Database'))
Answer: B
NEW QUESTION # 20
Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?
- A. Whitelist IP addresses.
- B. Create alert rules.
- C. Define enterprise settings.
- D. Configure User-ID.
Answer: C
Explanation:
Explanation
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-poli
NEW QUESTION # 21
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW VulnerabilityProtection Profiles?
- A. Use the default Vulnerability Protection Profile to protect servers from all known critical, high, and medium-severity threats
- B. Clone the predefined Strict Profile, with packet capture settings enabled
- C. Use the default Vulnerability Protection Profile to protect clients from all known critical, high, and medium-severity threats
- D. Clone the predefined Strict Profile, with packet capture settings disabled
Answer: B
NEW QUESTION # 22
Which regulatory framework in Prisma Public Cloud measures compliance with EU data privacy regulations in Amazon Web Services workloads?
- A. ISO 27001
- B. Payment Card Industry 3.0
- C. GDPR
- D. EU Data Protection Directive 95/46/EC
Answer: D
NEW QUESTION # 23
What is the scope of the Amazon Web Services IAM Service?
- A. VPC
- B. regional
- C. global
- D. zonal
Answer: C
NEW QUESTION # 24
Palo Alto Networks recommends which two options for outbound HA design in Amazon Web Services using VM-Series NGFW? (Choose two.)
- A. transit gateway and security VPC with VM-Series
- B. transit VPC and security VPC with VM-Series
- C. traditional active/standby HA on VM-Series
- D. iLB-as-next-hop
Answer: A,C
NEW QUESTION # 25
Match the logging service with its cloud provider.
Answer:
Explanation:
NEW QUESTION # 26
What is the default capacity license of a VM-Series NGFW being deployed from the Google Cloud Platform Marketplace?
- A. VM-300
- B. VM-500
- C. VM-GCP
- D. VM-100
Answer: A
NEW QUESTION # 27
Which three features are not supported by VM-Series NGFWs on Azure Stack? (Choose three.)
- A. Resource Group
- B. Azure Application Insight
- C. Bootstrapping
- D. ARM Template
- E. Azure Security Center
Answer: B,C,D
NEW QUESTION # 28
Which Amazon Web Services security service can provide host vulnerability information to Prisma Public Cloud?
- A. Amazon Web Services WAF
- B. GuardDuty
- C. Inspector
- D. Shield
Answer: B
Explanation:
Explanation
http://www.paloguard.com/datasheets/prisma-cloud-on-aws.pdf
NEW QUESTION # 29
Based on the diagram, how many routes will the virtual gateway advertise to the on-premises NGFW over the Amazon Web Services Direct Connect link?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 30
Which three services can Google Cloud Security Scanner assess? (Choose three.)
- A. Compute Engine
- B. App Engine
- C. Google Virtual Private Cloud
- D. BigQuery
- E. Google Kubernetes Engine
Answer: A,B,E
NEW QUESTION # 31
Which option is true about VM-Series NGFW templates available from the Palo Alto Networks GitHub repository?
- A. Support for the templates is available through Professional Services from Palo Alto Networks.
- B. Unless otherwise noted, these templates are released under an as-is. best effort support policy.
- C. Palo Alto Networks provides full support if a valid support license is in place.
- D. The author of the template provides full support as long as the PAN-OS version specific to the template is supported.
Answer: B
NEW QUESTION # 32
What is the scope of the Amazon Web Services 1AM Service?
- A. VPC
- B. regional
- C. global
- D. zonal
Answer: C
NEW QUESTION # 33
Which Prisma Public Cloud policy alerts administrators to unusual user activity?
- A. Network
- B. Configuration
- C. Anomaly
- D. Audit Event
Answer: C
Explanation:
Explanation
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-poli
NEW QUESTION # 34
How does a customer that has deployed a VM-Series NGFW on Microsoft Azure using a BYOL license change to a PAYG license structure?
- A. purchase a new PAYG license from a reseller
- B. purchase a new PAYG license for Microsoft Azure from Palo Alto Networks
- C. launch a new VM using the PAYG image
- D. go to Palo Alto Networks Support website to change the BYOL license to a PAYG license
Answer: D
NEW QUESTION # 35
Match the query type with its corresponding search
Answer:
Explanation:
Explanation
network where,
event where,
config where
NEW QUESTION # 36
Which RQL string searches for all EBS volumes that do not have a "DataClassification" tag?
- A. config where api.name = 'aws-ec2-describe-volumes, AND json.rule = tags[*]key contains DataClassification
- B. config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*].key exists
- C. config where api.name = 'aws-ec2-describe-volumes' AND json.rule = tags[*].key = 1
- D. config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*]key != DataClassification
Answer: D
NEW QUESTION # 37
How can you modify a range of dates default policy in Prisma Public Cloud?
- A. Click the Gear icon next to the policy name to open the Edit Policy dialog
- B. Manually create the RQL statement.
- C. Override the value and commit the configuration.
- D. Clone the existing policy and change the value.
Answer: D
NEW QUESTION # 38
How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?
- A. Create an RQL config query to identify resources with the tag "Private."
- B. Create an RQL network query to identify traffic from resources tagged "Private."
- C. Open the Asset Dashboard, filter on tags: and choose "Private."
- D. Generate a CIS compliance report and review the "Asset Summary."
Answer: B
NEW QUESTION # 39
An administrator deploys a VM-Series firewall into Amazon Web Services. Which attribute must be disabled on the data-plane elastic network interface for the instance to handle traffic that is not destined to its own IP address?
- A. security group
- B. source/destination checking
- C. elastic ip address
- D. tags
Answer: B
Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/8-1/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/de
NEW QUESTION # 40
......
Palo Alto Networks PSE-PrismaCloud Dumps - Secret To Pass in First Attempt: https://www.dumpsmaterials.com/PSE-PrismaCloud-real-torrent.html
PSE-PrismaCloud Dumps - Grab Out For [NEW-2023] Palo Alto Networks Exam: https://drive.google.com/open?id=1MigBtX_WuexaXOFoDCkwvIbH7xpQ163z
