Palo Alto Networks PSE Platform - Professional 認定 PSE-Platform 試験問題:
1. Which three network events are highlighted through correlation objects as a potential security risks? (Choose three.)
A) Suspicious traffic patterns
B) Launch of an identified malware executable file
C) Known command-and-control activity
D) Endpoints access files from a removable drive
E) Identified vulnerability exploits
2. A network covers three geographical areas: Americas, Europe (EMEA), and Asia (APAC).
The APAC segment of the network consists of nine HA pairs of PA-3060 firewalls, generating a combined log output of 25 K logs per second. Only 14 days of traffic log retention is required.
Which management and logging solution will be effective and cost-efficient for this segment of the network?
A) Two Dual-mode M-500s in HA for both global management and storage. Each M-500 has 8 TB of storage
B) Two M-500s in HA management at the global level, and one log collector-mode M-500 with 8 TB of storage for APAC
C) Two M-500s in HA management at the global level, and two log collector-mode M-500s in a log collector group with 16 TB of storage for APAC
D) Two M-500s in HA management at the global level, with one M-100 with 4 TB of storage for APAC
3. A customer is worried about unknown attacks, but due to privacy and regulatory issues, won't implement SSL decrypt.
How can the platform still address this customer's concern?
A) It pivots the conversation to Traps on the endpoint preventing unknown exploits and malware there instead.
B) It bypasses the need to decrypt SSL Traffic by analyzing the file while still encrypted.
C) It overcomes reservations about SSL decrypt by offloading to a higher capacity firewall to help with the decrypt throughput.
D) It shows how AutoFocus can provide visibility into targeted attacks at the industry sector.
4. Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?
A) URL Filtering on the firewall, and MindMeld on Panorama
B) WildFire on the firewall, and AutoFocus on Panorama
C) Threat Prevention on the firewall, and Support on Panorama
D) GlobalProtect on the firewall, and Threat Prevention on Panorama
5. Which three actions should be taken before deploying a firewall evaluation unit in the customer's environment? (Choose three.)
A) Upgrade the evaluation unit to the most current recommended firmware, unless a demo of the upgrade process is planned.
B) Reset the evaluation unit to factory default to ensure that data from any previous customer evaluation is removed.
C) Set expectations around which information will be presented in the Security Lifecycle Review because sensitive information may be made visible.
D) Request that the customs make port 3978 available to allow the evaluation unit to communicate with Panorama.
E) Inform the customer that they will need to provide a SPAN port for the evaluation unit assuming a TAP mode deployment.
質問と回答:
質問 # 1 正解: A、C、E | 質問 # 2 正解: C | 質問 # 3 正解: A | 質問 # 4 正解: C | 質問 # 5 正解: A、B、E |