PSE StrataDC Free Questions Good Demo For Paloalto Networks PSE StrataDC Exam Palo Alto Networks Strata Data Center PSE StrataDC Study Guide 2021-9-24 1.Which feature removes the limitation of requiring the first interface to be management? A. Management interface swap B. Utilize a separate Load Balancer VM C. Utilize a separate NAT VM. D. Dataport interface switch Answer: B 2. In PAN-OS, which three NSX features can be pushed from Panorama? (Choose three) A. user IP mappings B. steering rules C. multiple authorization codes D. security group assignments of VMs E. security groups Answer: A,C,E 3. What is a company that is moving as much of its business as possible into Microsoft Azure trying to minimize? A. capital expenses B. operating expenses C. security exposure D. operating expenses and capital expenses Answer: B 4. How does Palo Alto Networks integrate with VXLAN tagging? A. does not integrate with VXLAN tagging, so virtual appliances cannot be provided, but hardware appliances can be offered at the data center gateway border B. integrates with VXLAN. but scripting is necessary, and Professional Services should be engaged C. integrates fully into VXLAN architectures if they are provided by VMware D. does not integrate natively with VXLAN tagging, network equipment can convert VXLAN flows to VLANs and send those VLANs to Palo Alto Networks firewalls Answer: C 5. When deploying VM series on Openstack platform, which statement is correct? A. Allow configuration of at least one interface B. OpenStack compute node could be installed on a hypervisor platform C. Accept the VM-Series OVA image Palo Alto Networks Strata Data Center PSE StrataDC Study Guide 2021-9-24 D. Set Instance type OS::Nova Server Answer: B 6. Which are two use cases for HSCI ports on the SMC module on PA-7000 Series? (Choose two) A. HA1 backup link in active/active HA B. HA1 link in active/passive HA C. HA3 link in active/active HA D. HA2 link in active/passive HA Answer: C,D Explanation: https://docs.paloaltonetworks.com/hardware/pa-7000-hardware-referenc e/pa-7000-series-module-and-interface-card-information/pa-7000-series-switch- management-card-smc/pa-7000-series-smc-component-descriptions 7. Which VM-Series can be deployed on VMware NSX? A. VM-100, VM-200, VM-300. VM-500. VM-1000-HV B. VM-50r VM-100, VM-200, VM-300, VM-500 C. VM-100, VM-200, VM-300, VM-500, VM-700 D. All VM Series Models can be deployed on VMware NSX Answer: A Explanation: https://docs.paloaltonetworks.com/vm-series/8-1/vm-series- deployment/about-the-vm-series-firewall/vm-series-models.html 8. What are the benefits of NSX-V? A. supports the Data Plane Development Kit (DPDK) libraries; enables Stackdnver Monitoring on the VMware Series Firewall; works with Cloud Launcher B. virt-manager wizard to help with the installation process; virsh command to deploy the VM-Series; virt-installcommand to install C. sturdier centralized management; automated deployment ease in administering tenants and dedicated compute infrastructure; tighter integration between virtual environment and security enforcement of dynamic security D. leverages Prism Central Answer: A 9. When deploying VM series on NSX platform to support micro-segmentation, which statement is NOT correct? A. VM-Series uses NetX API to receive and send packets Palo Alto Networks Strata Data Center PSE StrataDC Study Guide 2021-9-24 B. Traffic steering rules could be defined on Panorama and pushed to NSX Manager C. VM-Series provide Multi-tenancy support with multiple zones D. One panorama could support to connect with only one NSX manager Answer: A 10. Which is not a SaaS product? A. Yahoo Maps B. Microsoft Office 365 C. Microsoft Azure D. Google Docs Answer: C 11. What are two types of security that can be implemented across every phase of the Build, Ship, and Run lifecycle of a workload? (Choose two) A. Runtime Security B. Firewalling C. Vulnerability Management D. Compliance or Configuration Management Answer: C,D 12. Whichconfiguration is required in NSX for Panorama to use the tags from security groups in dynamic address groups? A. Create security groups only. B. Create security groups and mark them as exchangeable. C. Create security groups with tags marked as shareable. D. Create security groups and use them in an NSX-to-Palo Alto Networks redirection policy. Answer: A 13. Which configuration is requiredto share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall? A. notify device groups within VMware Services Manager B. a User-ID agent on a Windows domain server C. VMware Information Sources D. none, sharing happens by default Answer: B 14. Which environment is least likely to be placed on a public cloud by a hospital that has a large health information management application? A. production B. development C. testing D. QA Answer: B 15. A customer in a non-NSX VMware environment wants to add a VM-Series firewall and to partition an existing group of VMs in the same subnet into two groups. One group needs no additional security, but the second group requires substantially more security. How can this partition be accomplished without editing the IP addresses or the default gateways of any of the guest VMs? A. Create a new virtual switch and use the VM-Series firewall to separate virtual switches using Virtual Wire mode Then move the guests that require more security into the new virtual switch B. Edit the IP address of all of the affected VMs C. Send the VLAN out of the virtual environment into a hardware Palo Alto Networks firewall in Layer 3 mode. Use the same IP address as the old default gateway, then delete the old default gateway D. Create a Layer 3 interface in the same subnet as the VMs and configure proxy ARP Answer: D Go To PSE StrataDC Exam Questions Full Version