Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

PCSFE Exam Dumps - Palo Alto Networks Certified Software Firewall Engineer (PCSFE)

Question # 4

Which feature must be configured in an NSX environment to ensure proper operation of a VM-Series firewall in order to secure east-west traffic?

A.

Deployment of the NSX DFW

B.

VMware Information Sources

C.

User-ID agent on a Windows domain server

D.

Device groups within VMware Services Manager

Full Access
Question # 5

What do tags allow a VM-Series firewall to do in a virtual environment?

A.

Enable machine learning (ML).

B.

Adapt Security policy rules dynamically.

C.

Integrate with security information and event management (SIEM) solutions.

D.

Provide adaptive reporting.

Full Access
Question # 6

Which three NSX features can be pushed from Panorama in PAN-OS? (Choose three.)

A.

Security group assignment of virtual machines (VMs)

B.

Security groups

C.

Steering rules

D.

User IP mappings

E.

Multiple authorization codes

Full Access
Question # 7

Which two deployment modes of VM-Series firewalls are supported across NSX-T? (Choose two.)

A.

Prism Central

B.

Bootstrap

C.

Service Cluster

D.

Host-based

Full Access
Question # 8

Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)

A.

Intelligent Traffic Offload

B.

Threat Prevention

C.

WildFire

D.

SD-WAN

Full Access
Question # 9

Why are containers uniquely suitable for runtime security based on allow lists?

A.

Containers have only a few defined processes that should ever be executed.

B.

Developers define the processes used in containers within the Dockerfile.

C.

Docker has a built-in runtime analysis capability to aid in allow listing.

D.

Operations teams know which processes are used within a container.

Full Access
Question # 10

Which two configuration options does Palo Alto Networks recommend for outbound high availability (HA) design in Amazon Web Services using a VM-Series firewall? (Choose two.)

A.

Transit VPC and Security VPC

B.

Traditional active-active HA

C.

Transit gateway and Security VPC

D.

Traditional active-passive HA

Full Access
Question # 11

What helps avoid split brain in active-passive high availability (HA) pair deployment?

A.

Using a standard traffic interface as the HA2 backup

B.

Enabling preemption on both firewalls in the HA pair

C.

Using the management interface as the HA1 backup link

D.

Using a standard traffic interface as the HA3 link

Full Access
Question # 12

Which technology allows for granular control of east-west traffic in a software-defined network?

A.

Routing

B.

Microseqmentation

C.

MAC Access Control List

D.

Virtualization

Full Access
Question # 13

Which Palo Alto Networks firewall provides network security when deploying a microservices-based application?

A.

PA-Series

B.

ICN-Series

C.

VM-Series

D.

HA-Series

Full Access
Question # 14

What Palo Alto Networks software firewall protects Amazon Web Services (AWS) deployments with network security delivered as a managed cloud service?

A.

VM-Series

B.

Cloud next-generation firewall

C.

CN-Series

D.

Ion-Series Ion-Series

Full Access
Question # 15

How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

A.

By using contracts between endpoint groups that send traffic to the firewall using a shared policy

B.

Through a virtual machine (VM) monitor domain

C.

Through a policy-based redirect

D.

By creating an access policy

Full Access
Question # 16

How are CN-Series firewalls licensed?

A.

Data-plane vCPU

B.

Service-plane vCPU

C.

Management-plane vCPU

D.

Control-plane vCPU

Full Access
Question # 17

Which solution is best for securing an EKS environment?

A.

VM-Series single host

B.

CN-Series high availability (HA) pair

C.

PA-Series using load sharing

D.

API orchestration

Full Access
Question # 18

Which two steps are involved in deployment of a VM-Series firewall on NSX? (Choose two.)

A.

Create a virtual data center (vDC) and a vApp that includes the VM-Series firewall.

B.

Obtain the Amazon Machine Images (AMIs) from marketplace.

C.

Enable communication between Panorama and the NSX Manager.

D.

Register the VM-Series firewall as a service.

Full Access