[2023] Pass Palo Alto Networks PSE-StrataDC Exam Updated 60 Questions [Q31-Q48]

Share

[2023] Pass Palo Alto Networks PSE-StrataDC Exam Updated 60 Questions

Get 2023 Updated Free Palo Alto Networks PSE-StrataDC Exam Questions and Answer


The PSE-StrataDC certification exam is a highly respected certification that IT professionals can obtain to demonstrate their expertise in the implementation and management of Palo Alto Networks’ Strata Data Center solutions. Palo Alto Networks System Engineer Professional - Strata Data Center certification exam is ideal for IT professionals who are responsible for the design, implementation, and maintenance of Strata Data Center solutions. Candidates must have a strong understanding of the technologies and protocols used within the Strata Data Center solutions and be able to troubleshoot issues that arise.

 

NEW QUESTION # 31
How do Palo Alto Networks NGFWs integrate with an ACI architecture?

  • A. VXLAN or NVGRE traffic is terminated and inspected for translation to VLANs.
  • B. Traffic can be automatically redirected using static Address objects.
  • C. Controllers can program firewalls using a REST-based API.
  • D. SDN code hooks can help to detonate malicious file samples designed to detect virtual environments

Answer: B


NEW QUESTION # 32
For which two reasons would an administrator have to install NGFW automatically in a cloud environment?
{Choose two )

  • A. resiliency and availability, to be able to install a new firewall as part of a new environment if an existing environment fails
  • B. integrity, to ensure that data is not changed illicitly
  • C. reduce capital expenses
  • D. security, to automatically install a firewall when a security threat is detected
  • E. performance, to be able to install a new firewall when the demand exceeds the ability of the existing environments to service

Answer: D,E


NEW QUESTION # 33
Which two methods provide a virtual IP address when implementing active/active HA? (Choose two )

  • A. floating IP address
  • B. ARP load sharing
  • C. VRRP
  • D. HSRP

Answer: A,B


NEW QUESTION # 34
Whichthree deployment modes of VM-Series firewalls are supported across NSX-T? (Choose three )

  • A. Partner Service
  • B. Boot Strap
  • C. Tier-0 insertion
  • D. Tier-1 insertion
  • E. Prism Central

Answer: A,C,D

Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-nsx/set You can deploy one or more instances of the VM-Series firewall as a partner service in your VMware NSX-T Data Center. Attach a VM-Series firewall to any tier-0 or tier-1 logical router to protect north-south traffic.
You can deploy the VM-Series firewall as standalone service instance or two firewalls in a high-availability (HA) pair. Panorama manages the connection with NSX-T Manager and the VM-Series firewalls deployed in your NSX-T software-defined datacenter.

* Tier-0 Insertion-Tier-0 insertion deploys a VM-Series firewall to a tier-0 logical router, which processes traffic between logical and physical networks. When you deploy the VM-Series firewall with tier-0 insertion, NSX-T Manager uses the deployment information you configured on Panorama to attach a firewall to a tier-0 logical router in virtual wire mode.
* Tier-1 Insertion-Tier-1 insertion deploys a VM-Series firewall to a tier-1 logical router, which provides downlink connections to segments and uplink connection to tier-0 logical routers. NSX-T Manager attaches VM-Series firewalls deployed with tier-1 insertions to a tier-1 logical router in virtual wire mode.
After deploying the firewall, you configure traffic redirection rules that send traffic to the VM-Series firewall when crossing a tier-0 or tier-1 router. Security policy rules that you configure on Panorama are pushed to managed VM-Series firewalls and then applied to traffic passing through the firewall.


NEW QUESTION # 35
How does Palo Alto Networks VM orchestration help service providers automatically provision security instances and policies on demand? (Choose two.)

  • A. Support for Dynamic Address Groups
  • B. VM Orchestration Policy Editor
  • C. Aperture Orchestration Engine (AOE)
  • D. Fully instrumented API

Answer: A,D


NEW QUESTION # 36
What is the default session distribution policy in the PA-7000 Series?

  • A. Round Robin
  • B. Ingress-Slot
  • C. Egress-Slot
  • D. Hash

Answer: B

Explanation:
Explanation
(
PA-7000 Series firewalls only
) New sessions are assigned to a DP on the same NPC on which the first packet of the session arrived. The selection of the DP is based on the session-load algorithm but, in this case, sessions are limited to the DPs on the ingress NPC.
Depending on the traffic and network topology, this policy generally decreases the odds that traffic will need to traverse the switch fabric.
Use this policy to reduce latency if both ingress and egress are on the same NPC. If the firewall has a mix of NPCs (PA-7000 20G and PA-7000 20GXM for example), this policy can isolate the increased capacity to the corresponding NPCs and help to isolate the impact of NPC failures.


NEW QUESTION # 37
What are two types of security that can be implemented across every phase of the Build, Ship, and Run lifecycle of a workload? (Choose two )

  • A. Compliance or Configuration Management
  • B. Firewalling
  • C. Vulnerability Management
  • D. Runtime Security

Answer: A,C


NEW QUESTION # 38
A customer in a non-NSX VMware environment wantsto add a VM-Series firewall and to partition an existing group of VMs in the same subnet into two groups. One group needs no additional security, but the second group requires substantially more security.
How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs?

  • A. Create a Layer 3 interface in the same subnet as the VMs and configure proxy ARP
  • B. Create a new virtual switch and use the VM-Series firewall to separate virtual switches using Virtual Wire mode Then move the guests that require more security into the new virtual switch
  • C. Edit the IP address of all of the affected VMs
  • D. Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete the old default gateway

Answer: A


NEW QUESTION # 39
A customer wants to completely segment their internal networks They have Cisco switches and extensively use 10Gbps interfaces. They are running VMware ESXi and are considering implementing NSX. Which three Palo Alto Networks firewall models will support this deployment? (Choose three.)

  • A. VM-300
  • B. PA-3050
  • C. VM-100
  • D. PA-7050
  • E. PA-3250

Answer: B,D,E


NEW QUESTION # 40
Which configuration is requiredto share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall?

  • A. a User-ID agent on a Windows domain server
  • B. notify device groups within VMware Services Manager
  • C. none, sharing happens by default
  • D. VMware Information Sources

Answer: A


NEW QUESTION # 41
Which two design options address split-brain when configuring HA? (Choose two )

  • A. Send heartbeats across the HA2 interfaces.
  • B. Bundle multiple interfaces in an Aggregated Interface Group and assign HA2.
  • C. Use the heartbeat backup.
  • D. Add a backup HA1 interface.

Answer: C,D


NEW QUESTION # 42
Which VM-Series can be deployed on Amazon Web Services (AWS)?

  • A. Any VM-Series model
  • B. Only VM-100, VM-200 and VM-300
  • C. Any VM-Series model except the VM-700
  • D. Can deploy any VM-Series except the VM-50

Answer: A


NEW QUESTION # 43
Which capacity license does an administrator get with a pay-as-you-go license on Public Cloud market places?

  • A. VM-300
  • B. VM-200
  • C. VM-100
  • D. VM-1000

Answer: C


NEW QUESTION # 44
Which three advantages of the Palo Alto Networks platform architecture are used to enable security orchestration in SDN? (Choose three )

  • A. NVGRE support for advanced VLAN integration
  • B. a full set of APIs enabling programmatic control of policy and configuration
  • C. Dynamic Address Groups to adapt Security policies dynamically
  • D. integration with leading orchestration platforms: VMware NSX. OpenStack. and Cisco ACI
  • E. VXLAN support for network-layer abstraction

Answer: C,D,E


NEW QUESTION # 45
Which task is required to create steering rules on NSX-V Manager?

  • A. Add a network introspective service and select Redirect to Service under Action.
  • B. Configure the rule in Panorama and push it to NSX-V Manager.
  • C. Select Steering Rules > 3rd Party Firewalls > Palo Alto Networks and then populate the object with the required details
  • D. Select Fabric > Access Policies > Quick Start and follow the prompts

Answer: C


NEW QUESTION # 46
What is the major decision factor that customers use when selecting a managed container platform such as AS/EKS/GKE?

  • A. licensing costs
  • B. enhanced capabilities not available in vanilla K8s
  • C. no need to manage containers, just the application code.
  • D. reduced operational costs and management overhead

Answer: B


NEW QUESTION # 47
How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

  • A. through a policy-based redirect (PBR)
  • B. through a virtual machine monitor (VMM) domain
  • C. by creating an access policy
  • D. contracts between EPGs that send traffic to the firewall using a shared policy

Answer: D


NEW QUESTION # 48
......


The PSE-StrataDC exam is a comprehensive test that covers a wide range of topics related to Strata Data Center technology. This includes understanding the architecture of the Strata Data Center, how to deploy and configure the solution, how to manage and monitor the Strata Data Center, and how to troubleshoot common issues.

 

Verified PSE-StrataDC exam dumps Q&As with Correct 60 Questions and Answers: https://www.prepawaypdf.com/Palo-Alto-Networks/PSE-StrataDC-practice-exam-dumps.html