Palo Alto Networks Systems Engineer (PSE): Software Firewall Professional PSE-SoftwareFirewall Exam Questions

Page: 1 / 14
Total 65 questions
Question 1

How does Prisma Cloud Compute offer workload security at runtime?



Answer : D

Allow-list Security Model:

Prisma Cloud Compute provides runtime security by automatically creating an allow-list security model for each container and service. This model ensures that only expected and authorized behaviors are allowed, effectively preventing unauthorized activities.


Prisma Cloud Compute Runtime Security

Question 2

What is a benefit of CN-Series firewalls securing traffic between pods and other workload types?



Answer : B

Consistent Security Across the Environment:

CN-Series firewalls are designed to provide security for containerized environments by protecting traffic between pods and other workload types. This ensures that security policies are consistently enforced across all elements of the environment, maintaining a unified security posture.


Palo Alto Networks CN-Series Documentation

Question 3

Which two public cloud platforms does the VM-Series plugin support? (Choose two.)



Answer : C, D

The VM-Series plugin supports integration with multiple public cloud platforms, including:

Amazon Web Services (AWS): The VM-Series firewalls can be deployed in AWS to provide comprehensive security for cloud applications and data, leveraging AWS's native services and integration capabilities.

Azure: The VM-Series firewalls also integrate with Microsoft Azure, offering advanced security features and policies for applications and data hosted in Azure's cloud environment.


Palo Alto Networks VM-Series on AWS: VM-Series on AWS

Palo Alto Networks VM-Series on Azure: VM-Series on Azure

Question 4

Which software firewall would assist a prospect who is interested in securing extensive DevOps deployments?



Answer : B

CN-Series for DevOps deployments:

The CN-Series firewall is specifically designed to secure containerized environments and is ideal for protecting extensive DevOps deployments. It integrates seamlessly with Kubernetes and other container orchestration platforms, providing the necessary security controls for DevOps processes.


Palo Alto Networks CN-Series Firewall Overview

Question 5

What are two requirements for automating service deployment of a VM-Series firewall from an NSX Manager? (Choose two.)



Answer : A, C

For automating the deployment of VM-Series firewalls from NSX Manager, Panorama must be configured to recognize and communicate with both the NSX Manager and vCenter. This ensures that Panorama can manage the firewall policies and orchestration efficiently.


Palo Alto Networks NSX Integration Guide

VM-Series Firewall Communication with Panorama:

It is crucial that the deployed VM-Series firewall can establish communication with Panorama. This connection allows for the centralized management of the firewalls and ensures that policy updates and configurations can be pushed from Panorama to the VM-Series firewalls.

Palo Alto Networks VM-Series Deployment Guide

Question 6

Which two mechanisms could trigger a high availability (HA) failover event? (Choose two.)



Answer : A, B

Ping monitoring:

This mechanism involves monitoring the reachability of a specified IP address. If the firewall cannot ping the address, it may trigger a failover.


PAN-OS Administrator's Guide - HA

Link monitoring:

Link monitoring checks the status of network links. If a monitored link fails, an HA failover can be triggered.

PAN-OS High Availability Link Monitoring

Question 7

Which offering can gain visibility and prevent an attack by a malicious actor attempting to exploit a known web server vulnerability using encrypted communication?



Answer : C

SSL Inbound Inspection allows VM-Series firewalls to decrypt, inspect, and re-encrypt SSL/TLS traffic coming into the network. This capability enables the firewall to gain visibility into encrypted communication and prevent attacks that exploit known web server vulnerabilities, even when the traffic is encrypted. By inspecting the decrypted traffic, the firewall can apply security policies to detect and block malicious activity.


Palo Alto Networks SSL Decryption Guide: SSL Decryption

Palo Alto Networks SSL Inbound Inspection Documentation: SSL Inbound Inspection

Page:    1 / 14   
Total 65 questions