[Nov 19, 2021] PSE-PrismaCloud Dumps Full Questions - Exam Study Guide
PSE-Prisma Cloud Professional Free Certification Exam Material from Real4Prep with 62 Questions
NEW QUESTION 18
What are the two options to dynamically register tags used by Dynamic Address Groups that are referenced in policy? (Choose two.)
- A. CFT Template
- B. XML API
- C. VM Monitoring
- D. External Dynamic List
Answer: B,C
Explanation:
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/monitor-changes-in-the-virtual-environment/
NEW QUESTION 19
Which option is true about VM-Series NGFW templates available from the Palo Alto Networks GitHub repository?
- A. The author of the template provides full support as long as the PAN-OS version specific to the template is supported.
- B. Unless otherwise noted, these templates are released under an as-is. best effort support policy.
- C. Support for the templates is available through Professional Services from Palo Alto Networks.
- D. Palo Alto Networks provides full support if a valid support license is in place.
Answer: B
NEW QUESTION 20
A customer CSO has asked you to demonstrate how to identify all "Amazon RDS" resources deployed and the region that they are deployed in. What are two ways that Prisma Public Cloud can show the relevant information?(Choose two.)
- A. Write an RQL query from the "Investigate" tab.
- B. Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.
- C. Generate a compliance report from the Compliance dashboard
- D. Configure an Inventory report from the "Alerts" tab
Answer: B,C
NEW QUESTION 21
How is license utilization displayed within the Prisma Public Cloud interface?
- A. navigate to Dashboard > Asset Inventory
- B. navigate to the CLI and run show license command
- C. navigate to Settings (via the gear icon) > Licensing
- D. navigate to General > Licensing
Answer: C
NEW QUESTION 22
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW VulnerabilityProtection Profiles?
- A. Use the default Vulnerability Protection Profile to protect servers from all known critical, high, and medium-severity threats
- B. Clone the predefined Strict Profile, with packet capture settings enabled
- C. Clone the predefined Strict Profile, with packet capture settings disabled
- D. Use the default Vulnerability Protection Profile to protect clients from all known critical, high, and medium-severity threats
Answer: B
NEW QUESTION 23
How does a customer that has deployed a VM-Series NGFW on Microsoft Azure using a BYOL license change to a PAYG license structure?
- A. go to Palo Alto Networks Support website to change the BYOL license to a PAYG license
- B. launch a new VM using the PAYG image
- C. purchase a new PAYG license from a reseller
- D. purchase a new PAYG license for Microsoft Azure from Palo Alto Networks
Answer: B
NEW QUESTION 24
Which option is defined by the creation and change of public cloud services managed in a repeatable and predictable fashion?
- A. platform as a service
- B. software as code
- C. infrastructure as a service
- D. infrastructure as code
Answer: C
NEW QUESTION 25
A customer has just launched a Palo Alto Networks VM-Series NGFW into an Amazon Web Services VPC to protect a cloud hosted application. They are experiencing unpredictable results and have identified that the interfaces on the firewall are in the incorrect order Which PAN-OS CLI command resolves this issue?
- A. set system setting mgmt-interface-swap enable yes
- B. set mgmt-interface settings swap yes
- C. set system setting mgmt-interface swap yes
- D. set mgmt-interface swap yes
Answer: A
NEW QUESTION 26
Which two items are required when a VM-100 BYOL instance is upgraded to a VM-300 BYOL instance?
(Choose two.)
- A. CPU ID
- B. UUID
- C. new Auth Code
- D. API Key
Answer: A,B
Explanation:
Explanation
In a public cloud deployment, if your firewall is licensed with the BYOL option, you must Deactivate VM before you change the instance type or VM type and apply the license again on the firewall after you complete the model or instance upgrade. When you change the instance type, because the firewall has a new UUID and CPU ID, the existing license will no longer be valid.
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series-firewall/upgrade-th
NEW QUESTION 27
What are two ways to initially deploy a VM-Series NGFW in Microsoft Azure? (Choose two.)
- A. through Expedition in the Customer Success Portal
- B. through Solution Templates in the Azure Marketplace
- C. through Iron Skillets in the GitHub Repository
- D. through ARM Templates in the GitHub Repository
Answer: A,D
NEW QUESTION 28
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW Vulnerability Protection Profiles?
- A. Use the default Vulnerability Protection Profile to protect clients from all known critical, high, and medium-severity threats
- B. Use the default Vulnerability Protection Profile to protect servers from all known critical, high, and medium-severity threats
- C. Clone the predefined Strict Profile, with packet capture settings disabled
- D. Clone the predefined Strict Profile, with packet capture settings enabled
Answer: A
NEW QUESTION 29
What is the scope of the Amazon Web Services IAM Service?
- A. regional
- B. VPC
- C. global
- D. zonal
Answer: C
NEW QUESTION 30
Which change represents a VM-Series NGFW license transfer?
- A. VM-100 BYOL on Microsoft Azure to VM-300 PAYG on Amazon Web Services
- B. VM-100 BYOL on Microsoft Azure to VM-300 BYOL on Microsoft Azure
- C. VM-100 BYOL on Microsoft Azure to VM-100 BYOL on Amazon Web Services
- D. VM-300 BYOL on Microsoft Azure to VM-300 PAY6 on Amazon Web Services
Answer: B
NEW QUESTION 31
The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW.
Which component handles address translation?
- A. The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses
- B. The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.
- C. The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.
- D. The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.
Answer: C
NEW QUESTION 32
Which RQL string returns a list of all Azure virtual machines that are not currently running?
- A. config where api.name = 'azure-vm-list' AND json.rule = powerState = "running"
- B. config where api.name = 'azure-vm-list' AND json.rule = powerState does not contain "running"
- C. config where api.name = 'azure-vm-list' AND json.rule = powerState contains "running"
- D. config where api.name = 'azure-vm-list' AND json.rule = powerState = "off'
Answer: B
NEW QUESTION 33
Which two cloud providers support Load Balancers as next hop configurations for outbound connections?
(Choose two.)
- A. Oracle Cloud
- B. Amazon Web Services
- C. Microsoft Azure
- D. Google Cloud Platform
Answer: A,D
NEW QUESTION 34
Match the logging service with its cloud provider.
Answer:
Explanation:
NEW QUESTION 35
Which three methods can provide application-level security for a web server instance on Amazon Web Services? (Choose three.)
- A. Security Groups
- B. VM-Series firewalls
- C. Traps
- D. Amazon Web Services WAF
- E. Prisma SaaS
Answer: A,B,E
NEW QUESTION 36
Which cloud provider supports iLB-as-next-hop?
- A. Oracle Cloud
- B. Alibaba Cloud
- C. Amazon Web Services
- D. Microsoft Azure
Answer: C
NEW QUESTION 37
A customer CSO has asked you to demonstrate how to identify all "Amazon RDS" resources deployed and the region that they are deployed in. What are two ways that Prisma Public Cloud can show the relevant information?(Choose two.)
- A. Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.
- B. Write an RQL query from the "Investigate" tab.
- C. Configure an Inventory report from the "Alerts" tab
- D. Generate a compliance report from the Compliance dashboard
Answer: A,B
NEW QUESTION 38
Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?
- A. Configure User-ID.
- B. Define enterprise settings.
- C. Whitelist IP addresses.
- D. Create alert rules.
Answer: B
Explanation:
Explanation
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-poli
NEW QUESTION 39
......
Dumps Brief Outline Of The PSE-PrismaCloud Exam: https://www.real4prep.com/PSE-PrismaCloud-exam.html
Use Real PSE-PrismaCloud - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1C05W0eeC6w8mSLSR1S52ReEXBXWDn30J