Skip to content

PSE-STRATA Palo Alto Networks Systems Engineer Professional - Strata Practice Questions

Prepare for PSE-STRATA with more than an answer.

233 questions in the full set20 sample questionsUpdated Aug 21, 2026
Exam fee
$250 USD
Level
Associate
Valid for
2 years
Domains covered on the exam 5
  1. Core Concepts and Product Knowledge20%
  2. Deploy and Configure Core Components30%
  3. Deploy and Configure Features and Subscriptions25%
  4. Deploy and Configure Firewalls Using Panorama15%
  5. Manage and Operate10%
  1. 1

    In a Panorama template stack, variables can be defined at different levels (e.g., Template, Template Stack, Firewall). If a variable named ${gateway_ip} is defined with different values at all three levels for a specific firewall, which value will be used when the configuration is pushed to that firewall?

    Show answer details

    Correct answer: C

    Panorama uses a specific order of precedence for resolving variable values. The most specific value always wins. The order is: Firewall > Template Stack > Template. Therefore, a value defined directly on the managed firewall object itself will override any values for the same variable defined at the higher Template Stack or Template levels.

  2. 2

    A pre-sales engineer is presenting the Palo Alto Networks Strata platform to a potential customer. The customer is concerned about performance degradation when multiple security services like App-ID, IPS, and Antivirus are enabled simultaneously. Which core architectural component of PAN-OS addresses this concern by performing all analysis in a single, integrated scan?

    Show answer details

    Correct answer: C

    The Single-Pass Parallel Processing (SP3) Architecture is a fundamental differentiator for Palo Alto Networks. Unlike other architectures that use separate engines or modules for each function (leading to multiple scans and latency), SP3 performs networking, policy lookup, and signature matching for all threats and content in a single pass. This dramatically reduces latency and ensures that performance remains high even with multiple security services enabled.

  3. 3

    Case Study: Global Expansion and Security Consolidation

    Company Background:
    FutureGadget Inc. is a rapidly growing technology firm that has recently acquired two smaller companies in Europe and Asia. Each company operates its own datacenter with a mix of legacy stateful firewalls from different vendors. FutureGadget's corporate headquarters in North America is secured by a pair of PA-5450 firewalls managed by Panorama. The security team is small, and they are struggling with inconsistent policy enforcement, lack of visibility into application traffic, and a high volume of alerts from the disparate systems.

    Current Situation:
    The CISO has mandated a global security consolidation project. The goal is to replace all legacy firewalls with Palo Alto Networks NGFWs and manage them centrally. The European datacenter primarily hosts web applications accessible to the public, while the Asian datacenter handles R&D and requires strict access controls for intellectual property. All three datacenters need to be interconnected via secure VPN tunnels. The security team is concerned about zero-day malware entering the network through web traffic or email.

    Requirements and Constraints:

    1. All firewalls must be managed from the existing Panorama instance at the corporate headquarters.
    2. A consistent security posture must be enforced globally, but with specific policy exceptions for each region's needs.
    3. All traffic between datacenters must be encrypted.
    4. Advanced protection against unknown malware is a critical requirement.
    5. The solution must provide visibility into user activities across all locations.

    Which combination of technologies and configurations best meets FutureGadget's requirements?

    Show answer details

    Correct answer: B

    This solution addresses all requirements. Using a hierarchical device group structure (parent for global, children for regional) in Panorama provides both consistency and flexibility. IPsec VPNs provide secure inter-site connectivity. A WildFire subscription is essential for protection against unknown malware. Finally, integrating User-ID with regional directories provides the required visibility into user activities across all locations, fulfilling all key project goals.

  4. 4

    A firewall is configured with a Zone Protection Profile applied to the external, untrust zone. The profile is configured to protect against TCP Port Scans. A remote security scanner initiates a scan against the firewall's external interface. Which action will the firewall take upon detecting this scan?

    Show answer details

    Correct answer: B

    Zone Protection Profiles are designed to protect the firewall itself and the network behind it from reconnaissance attacks and floods. When a TCP Port Scan is detected based on the configured thresholds, the firewall's default action is to silently drop the packets from the scanner and, crucially, block the source IP for a configurable time to prevent further scanning. This is logged in the Threat log with a 'recon' threat type.

  5. 5

    Which two statements accurately describe the differences between a Vulnerability Protection profile and an Anti-Spyware profile? (Select TWO)

    Show answer details

    Correct answer: A, C

  6. 6

    An administrator needs to provide access to an internal application for a third-party contractor. The security policy requires that the contractor can only access this single application and nothing else on the network. The application is identified by App-ID as 'internal-crm'. Which security policy configuration is the most secure and precise way to grant this access?

    Show answer details

    Correct answer: C

    This policy adheres to the principle of least privilege, a core concept of Zero Trust. It is highly specific, defining the known source zone, source IP, destination zone, destination IP, and most importantly, the specific application ('internal-crm'). Using 'application-default' for the service ensures that only the standard ports for that application are allowed, preventing use of non-standard ports. This is the most secure and precise configuration.

  7. 7

    A financial services company needs to inspect all outbound SSL/TLS traffic for data loss prevention (DLP). They have a third-party, inline DLP appliance that requires clear text traffic. To avoid the performance impact of decrypting traffic on both the firewall and the DLP appliance, they want to use the firewall's Decryption Broker feature. Which configuration achieves this goal?

    graph TD subgraph Firewall A[Client] --> B{NGFW Decrypts}; B --> C[Forward to DLP]; end subgraph Third-Party Tools DLP[DLP Appliance]; end subgraph Internet E((Internet)); end C --> DLP; DLP --> B; B --> E;
    Show answer details

    Correct answer: C

    Decryption Broker works by decrypting traffic once, forwarding the clear text packets out one interface to a security chain (like a DLP appliance), and receiving them back on another interface before re-encrypting and sending them to their destination. This is configured in a decryption policy rule by specifying a forward interface pair, which typically consists of two Layer 2 or Virtual Wire interfaces.

  8. 8

    A financial institution is deploying Palo Alto Networks NGFWs in an Active/Passive HA pair. To ensure rapid failover, the security architect has configured path monitoring for critical upstream and downstream devices. The primary firewall's monitored IP addresses become unreachable, triggering a failover to the passive firewall. However, after the failover, users still cannot access the internet. A packet capture on the newly active firewall shows that it is not receiving any traffic on its external interface. Which configuration error is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    In an Active/Passive HA failover, the newly active firewall takes over the virtual MAC address and IP addresses of the interfaces. It sends a gratuitous ARP (GARP) request to update the ARP tables of adjacent network devices. If the upstream switch or router does not process this GARP correctly, it will continue sending traffic to the MAC address of the previously active firewall's physical port, causing traffic to be black-holed. This is a common real-world failover issue.

  9. 9

    A large enterprise uses Panorama to manage hundreds of firewalls across multiple geographic regions. An administrator needs to create a new security policy for all firewalls located in Europe that allows access to a specific SaaS application. However, the network subnets used for user access differ in each European country. Which Panorama feature should be used to create a single, scalable policy rule that accommodates these differing local subnets?

    Show answer details

    Correct answer: C

    Panorama variables allow administrators to create placeholder values in templates that are resolved on a per-firewall basis. By creating a variable (e.g., ${local_subnet}) in a template, assigning that template to all European firewalls, and then defining the specific subnet value for that variable on each individual firewall, a single shared address object and security policy rule can be used across the entire region. This is the most scalable and efficient method.

  10. 10

    A hospital is implementing User-ID to enforce policies based on clinical staff roles. The primary source of user-to-IP mapping is the Active Directory domain controller, monitored by a PAN-OS integrated User-ID agent. However, a critical medical imaging application requires users to authenticate via a RADIUS server, and these logins are not captured from AD. To ensure complete user coverage, which two methods should be configured? (Select TWO)

    Show answer details

    Correct answer: A, D

Create an account to continue.