ExamDumpster

Free PSE-STRATA sample questions

Real questions from the Palo Alto Networks Systems Engineer Professional - Strata practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial institution is deploying Palo Alto Networks NGFWs in an Active/Passive HA pair. To ensure rapid failover, the security architect has configured path monitoring for critical upstream and downstream devices. The primary firewall's monitored IP addresses become unreachable, triggering a failover to the passive firewall. However, after the failover, users still cannot access the internet. A packet capture on the newly active firewall shows that it is not receiving any traffic on its external interface. Which configuration error is the most likely cause of this issue?

Question 2Choose one

A large enterprise uses Panorama to manage hundreds of firewalls across multiple geographic regions. An administrator needs to create a new security policy for all firewalls located in Europe that allows access to a specific SaaS application. However, the network subnets used for user access differ in each European country. Which Panorama feature should be used to create a single, scalable policy rule that accommodates these differing local subnets?

Question 3Choose 2

A hospital is implementing User-ID to enforce policies based on clinical staff roles. The primary source of user-to-IP mapping is the Active Directory domain controller, monitored by a PAN-OS integrated User-ID agent. However, a critical medical imaging application requires users to authenticate via a RADIUS server, and these logins are not captured from AD. To ensure complete user coverage, which two methods should be configured? (Select TWO)

Question 4Choose one

A security engineer is configuring SSL Forward Proxy decryption. To ensure corporate policy compliance, all decrypted traffic must be inspected for threats and sensitive data patterns. However, an explicit exception must be made for traffic destined for financial and healthcare domains to protect user privacy. Which configuration represents the best practice to achieve this goal?

Question 5Choose one

True or False: When configuring a Palo Alto Networks firewall in Virtual Wire mode, it is possible to apply App-ID, Content-ID, and User-ID inspection to the traffic passing through the virtual wire.

Question 6Choose one

An administrator is investigating a performance issue on a PA-5260 firewall. They run the CLI command `show session info` and receive the output below. Based on the output, what is the most likely cause of the performance degradation? ``` -------------------------------------------------------------------------------- Sess Alloc Max Util -------------------------------------------------------------------------------- session 487216 1000000 48% packet buffer 512000 512000 100% tcpssid 99999 100000 99% cps 14500 15000 96% -------------------------------------------------------------------------------- ```

Question 7Choose one

A retail company is deploying VM-Series firewalls in AWS to protect its e-commerce application. The architecture requires that the firewalls scale automatically based on traffic load. The company uses an AWS Network Load Balancer (NLB) to distribute traffic to the firewalls. Which interface type must be used on the VM-Series firewall to support this scalable, load-balanced design?

Question 8Choose one

When creating a custom application signature (App-ID), what is the primary purpose of defining a 'Parent App'?

Question 9Choose one

An administrator is configuring a destination NAT policy to translate a public IP address to an internal web server. The web server hosts multiple websites using different host headers on the same IP address and port (e.g., `www.company-a.com` and `www.company-b.com` both resolve to the same public IP). The administrator needs to ensure that after NAT, the original host header is preserved so the internal web server can route the request to the correct website. Which configuration option is required?

Question 10Choose one

A security team is analyzing firewall logs after a suspected data exfiltration event. They have identified the attacker's IP address and the timeframe of the attack. They need to find all files that were transferred from their internal network to the attacker's IP address during that time. Which log type and filter combination would most efficiently provide this information?

10 more free samples are waiting

Create a free account to unlock the whole PSE-STRATA sample bank, or get full access to all 233 practice questions in the simulator.

Create account