PSE-STRATA Palo Alto Networks Systems Engineer Professional - Strata Practice Questions
Prepare for PSE-STRATA with more than an answer.
- Exam fee
- $250 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 5
- Core Concepts and Product Knowledge20%
- Deploy and Configure Core Components30%
- Deploy and Configure Features and Subscriptions25%
- Deploy and Configure Firewalls Using Panorama15%
- Manage and Operate10%
- 1
Case Study: Global Expansion and Security Consolidation
Company Background:
FutureGadget Inc. is a rapidly growing technology firm that has recently acquired two smaller companies in Europe and Asia. Each company operates its own datacenter with a mix of legacy stateful firewalls from different vendors. FutureGadget's corporate headquarters in North America is secured by a pair of PA-5450 firewalls managed by Panorama. The security team is small, and they are struggling with inconsistent policy enforcement, lack of visibility into application traffic, and a high volume of alerts from the disparate systems.Current Situation:
The CISO has mandated a global security consolidation project. The goal is to replace all legacy firewalls with Palo Alto Networks NGFWs and manage them centrally. The European datacenter primarily hosts web applications accessible to the public, while the Asian datacenter handles R&D and requires strict access controls for intellectual property. All three datacenters need to be interconnected via secure VPN tunnels. The security team is concerned about zero-day malware entering the network through web traffic or email.Requirements and Constraints:
- All firewalls must be managed from the existing Panorama instance at the corporate headquarters.
- A consistent security posture must be enforced globally, but with specific policy exceptions for each region's needs.
- All traffic between datacenters must be encrypted.
- Advanced protection against unknown malware is a critical requirement.
- The solution must provide visibility into user activities across all locations.
Which combination of technologies and configurations best meets FutureGadget's requirements?
Show answer details
Correct answer: B
This solution addresses all requirements. Using a hierarchical device group structure (parent for global, children for regional) in Panorama provides both consistency and flexibility. IPsec VPNs provide secure inter-site connectivity. A WildFire subscription is essential for protection against unknown malware. Finally, integrating User-ID with regional directories provides the required visibility into user activities across all locations, fulfilling all key project goals.
- 2
A firewall is configured with a Zone Protection Profile applied to the external, untrust zone. The profile is configured to protect against TCP Port Scans. A remote security scanner initiates a scan against the firewall's external interface. Which action will the firewall take upon detecting this scan?
Show answer details
Correct answer: B
Zone Protection Profiles are designed to protect the firewall itself and the network behind it from reconnaissance attacks and floods. When a TCP Port Scan is detected based on the configured thresholds, the firewall's default action is to silently drop the packets from the scanner and, crucially, block the source IP for a configurable time to prevent further scanning. This is logged in the Threat log with a 'recon' threat type.
- 3
Which two statements accurately describe the differences between a Vulnerability Protection profile and an Anti-Spyware profile? (Select TWO)
Show answer details
Correct answer: A, C
- 4
An administrator needs to provide access to an internal application for a third-party contractor. The security policy requires that the contractor can only access this single application and nothing else on the network. The application is identified by App-ID as 'internal-crm'. Which security policy configuration is the most secure and precise way to grant this access?
Show answer details
Correct answer: C
This policy adheres to the principle of least privilege, a core concept of Zero Trust. It is highly specific, defining the known source zone, source IP, destination zone, destination IP, and most importantly, the specific application ('internal-crm'). Using 'application-default' for the service ensures that only the standard ports for that application are allowed, preventing use of non-standard ports. This is the most secure and precise configuration.
- 5
A financial services company needs to inspect all outbound SSL/TLS traffic for data loss prevention (DLP). They have a third-party, inline DLP appliance that requires clear text traffic. To avoid the performance impact of decrypting traffic on both the firewall and the DLP appliance, they want to use the firewall's Decryption Broker feature. Which configuration achieves this goal?
graph TD subgraph Firewall A[Client] --> B{NGFW Decrypts}; B --> C[Forward to DLP]; end subgraph Third-Party Tools DLP[DLP Appliance]; end subgraph Internet E((Internet)); end C --> DLP; DLP --> B; B --> E;Show answer details
Correct answer: C
Decryption Broker works by decrypting traffic once, forwarding the clear text packets out one interface to a security chain (like a DLP appliance), and receiving them back on another interface before re-encrypting and sending them to their destination. This is configured in a decryption policy rule by specifying a forward interface pair, which typically consists of two Layer 2 or Virtual Wire interfaces.
- 6
A financial institution is deploying Palo Alto Networks NGFWs in an Active/Passive HA pair. To ensure rapid failover, the security architect has configured path monitoring for critical upstream and downstream devices. The primary firewall's monitored IP addresses become unreachable, triggering a failover to the passive firewall. However, after the failover, users still cannot access the internet. A packet capture on the newly active firewall shows that it is not receiving any traffic on its external interface. Which configuration error is the most likely cause of this issue?
Show answer details
Correct answer: B
In an Active/Passive HA failover, the newly active firewall takes over the virtual MAC address and IP addresses of the interfaces. It sends a gratuitous ARP (GARP) request to update the ARP tables of adjacent network devices. If the upstream switch or router does not process this GARP correctly, it will continue sending traffic to the MAC address of the previously active firewall's physical port, causing traffic to be black-holed. This is a common real-world failover issue.
- 7
A large enterprise uses Panorama to manage hundreds of firewalls across multiple geographic regions. An administrator needs to create a new security policy for all firewalls located in Europe that allows access to a specific SaaS application. However, the network subnets used for user access differ in each European country. Which Panorama feature should be used to create a single, scalable policy rule that accommodates these differing local subnets?
Show answer details
Correct answer: C
Panorama variables allow administrators to create placeholder values in templates that are resolved on a per-firewall basis. By creating a variable (e.g.,
${local_subnet}) in a template, assigning that template to all European firewalls, and then defining the specific subnet value for that variable on each individual firewall, a single shared address object and security policy rule can be used across the entire region. This is the most scalable and efficient method. - 8
A hospital is implementing User-ID to enforce policies based on clinical staff roles. The primary source of user-to-IP mapping is the Active Directory domain controller, monitored by a PAN-OS integrated User-ID agent. However, a critical medical imaging application requires users to authenticate via a RADIUS server, and these logins are not captured from AD. To ensure complete user coverage, which two methods should be configured? (Select TWO)
Show answer details
Correct answer: A, D
- 9
A security engineer is configuring SSL Forward Proxy decryption. To ensure corporate policy compliance, all decrypted traffic must be inspected for threats and sensitive data patterns. However, an explicit exception must be made for traffic destined for financial and healthcare domains to protect user privacy. Which configuration represents the best practice to achieve this goal?
Show answer details
Correct answer: C
The best practice for managing decryption exceptions is to use a dedicated Decryption policy rulebase. By placing a specific 'No Decrypt' rule at the top for sensitive categories (Financial Services, Health and Medicine), you ensure this traffic is explicitly bypassed. A second, broader rule below it can then enforce decryption for all other traffic. This provides clear, auditable policy control.
- 10
True or False: When configuring a Palo Alto Networks firewall in Virtual Wire mode, it is possible to apply App-ID, Content-ID, and User-ID inspection to the traffic passing through the virtual wire.
Show answer details
Correct answer: A
This statement is true. A key feature of the Virtual Wire deployment mode is its ability to be inserted into a network segment transparently (like a bump on the wire) while still providing full Layer 7 threat inspection capabilities. All traffic passing through the v-wire can be subjected to Security policies that leverage App-ID, Content-ID, and User-ID.
