2023 Latest PSE-PrismaCloud DUMPS Q&As with Explanations Verified & Correct Answers [Q14-Q31]

Share

2023 Latest PSE-PrismaCloud DUMPS Q&As with Explanations Verified & Correct Answers

PSE-PrismaCloud dumps Exam Material with 62 Questions

NEW QUESTION # 14
Which two statements are true about CloudFormation? (Choose two.)

  • A. CloudFormation templates can be written in JSON or YAML
  • B. CloudFormation is a declarative orchestration tool.
  • C. CloudFormation is a procedural configuration management tool.
  • D. CloudFormation templates can be used on both Amazon Web Services and Microsoft Azure

Answer: A,D


NEW QUESTION # 15
Which RQL string returns a list of all Azure virtual machines that are not currently running?

  • A. config where api.name = 'azure-vm-list' AND json.rule = powerState does not contain "running"
  • B. config where api.name = 'azure-vm-list' AND json.rule = powerState contains "running"
  • C. config where api.name = 'azure-vm-list' AND json.rule = powerState = "off'
  • D. config where api.name = 'azure-vm-list' AND json.rule = powerState = "running"

Answer: B


NEW QUESTION # 16
Which option is defined by the creation and change of public cloud services managed in a repeatable and predictable fashion?

  • A. infrastructure as code
  • B. platform as a service
  • C. software as code
  • D. infrastructure as a service

Answer: D


NEW QUESTION # 17
What resource is required to receive inbound traffic from the internet to VM-Series NGFW deployed as a gateway for Azure Stack workloads?

  • A. Border Customer Network
  • B. NAT appliance
  • C. Public IP for the VM-Series NGFW
  • D. Azure Stack Edge Router

Answer: B


NEW QUESTION # 18
When an on-premises NGFW (customer gateway) is used to connect to the Virtual Gateway, which two IKE profiles cannot be used? (Choose two.)

  • A. Group2 / SHA-1 / AES-128-CBC / IKE-V1
  • B. Group2 / SHA-1 / AES-128-GCM / IKE-V1
  • C. Group14 / SHA-256 / AES-256-GCM / IKE-V1
  • D. Group2 / SHA-1 / AES-128-CBC
  • E. Group14 / SHA-256 / AES-256-CBC / IKE-V1

Answer: B,C,D


NEW QUESTION # 19
How can you modify a range of dates default policy in Prisma Public Cloud?

  • A. Override the value and commit the configuration.
  • B. Manually create the RQL statement.
  • C. Clone the existing policy and change the value.
  • D. Click the Gear icon next to the policy name to open the Edit Policy dialog

Answer: C


NEW QUESTION # 20
What is the default capacity license of a VM-Series NGFW being deployed from the Google Cloud Platform Marketplace?

  • A. VM-GCP
  • B. VM-100
  • C. VM-300
  • D. VM-500

Answer: C


NEW QUESTION # 21
Which three methods can provide application-level security for a web server instance on Amazon Web Services? (Choose three.)

  • A. VM-Series firewalls
  • B. Prisma SaaS
  • C. Security Groups
  • D. Traps
  • E. Amazon Web Services WAF

Answer: A,B,C


NEW QUESTION # 22
The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW.
Which component handles address translation?

  • A. The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.
  • B. The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses
  • C. The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.
  • D. The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.

Answer: C


NEW QUESTION # 23
Which regulatory framework in Prisma Public Cloud measures compliance with EU data privacy regulations in Amazon Web Services workloads?

  • A. Payment Card Industry 3.0
  • B. EU Data Protection Directive 95/46/EC
  • C. GDPR
  • D. ISO 27001

Answer: B


NEW QUESTION # 24
What is required for an EC2 instance to access the internet directly from an AWS VPC?

  • A. Virtual Private Gateway
  • B. Internet Gateway
  • C. Customer Gateway
  • D. Transit Gateway

Answer: D


NEW QUESTION # 25
What is the scope of the Amazon Web Services IAM Service?

  • A. VPC
  • B. regional
  • C. zonal
  • D. global

Answer: D


NEW QUESTION # 26
A customer has just launched a Palo Alto Networks VM-Series NGFW into an Amazon Web Services VPC to protect a cloud hosted application. They are experiencing unpredictable results and have identified that the interfaces on the firewall are in the incorrect order Which PAN-OS CLI command resolves this issue?

  • A. set mgmt-interface settings swap yes
  • B. set system setting mgmt-interface swap yes
  • C. set system setting mgmt-interface-swap enable yes
  • D. set mgmt-interface swap yes

Answer: C


NEW QUESTION # 27
Which RQL string searches for all EBS volumes that do not have a "DataClassification" tag?

  • A. config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*]key != DataClassification
  • B. config where api.name = 'aws-ec2-describe-volumes' AND json.rule = tags[*].key = 1
  • C. config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*].key exists
  • D. config where api.name = 'aws-ec2-describe-volumes, AND json.rule = tags[*]key contains DataClassification

Answer: A


NEW QUESTION # 28
Which two cloud providers support Load Balancers as next hop configurations for outbound connections?
(Choose two.)

  • A. Google Cloud Platform
  • B. Microsoft Azure
  • C. Oracle Cloud
  • D. Amazon Web Services

Answer: A,C


NEW QUESTION # 29
Which three types of security checks can Prisma Public Cloud perform? (Choose three.)

  • A. event where
  • B. compliance where
  • C. user where
  • D. config where
  • E. network where

Answer: A,D,E


NEW QUESTION # 30
What is the scope of the Amazon Web Services 1AM Service?

  • A. VPC
  • B. regional
  • C. zonal
  • D. global

Answer: D


NEW QUESTION # 31
......


Palo Alto Networks PSE-PrismaCloud (PSE Palo Alto Networks System Engineer Professional - Prisma Cloud) Exam is a certification exam designed for professionals who want to demonstrate their expertise in the deployment, management, and administration of the Prisma Cloud security platform. Prisma Cloud is a cloud security platform that provides comprehensive visibility and protection across the entire application lifecycle, from development to production.

 

Share Latest PSE-PrismaCloud DUMP Questions and Answers: https://actualtests.torrentexam.com/PSE-PrismaCloud-exam-latest-torrent.html