Palo Alto Networks Systems Engineer Professional - Strata Free Sample Questions

20 free sample questions233 in the full practice test

Try simulator

PSE-STRATA Sample Questions

  1. Question 1

    A financial institution is deploying Palo Alto Networks NGFWs in an Active/Passive HA pair. To ensure rapid failover, the security architect has configured path monitoring for critical upstream and downstream devices. The primary firewall's monitored IP addresses become unreachable, triggering a failover to the passive firewall. However, after the failover, users still cannot access the internet. A packet capture on the newly active firewall shows that it is not receiving any traffic on its external interface. Which configuration error is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    In an Active/Passive HA failover, the newly active firewall takes over the virtual MAC address and IP addresses of the interfaces. It sends a gratuitous ARP (GARP) request to update the ARP tables of adjacent network devices. If the upstream switch or router does not process this GARP correctly, it will continue sending traffic to the MAC address of the previously active firewall's physical port, causing traffic to be black-holed. This is a common real-world failover issue.

  2. Question 2

    A large enterprise uses Panorama to manage hundreds of firewalls across multiple geographic regions. An administrator needs to create a new security policy for all firewalls located in Europe that allows access to a specific SaaS application. However, the network subnets used for user access differ in each European country. Which Panorama feature should be used to create a single, scalable policy rule that accommodates these differing local subnets?

    Answer and explanation

    Correct answer: C

    Panorama variables allow administrators to create placeholder values in templates that are resolved on a per-firewall basis. By creating a variable (e.g., ${local_subnet}) in a template, assigning that template to all European firewalls, and then defining the specific subnet value for that variable on each individual firewall, a single shared address object and security policy rule can be used across the entire region. This is the most scalable and efficient method.

  3. Question 3

    Multiple answers

    A hospital is implementing User-ID to enforce policies based on clinical staff roles. The primary source of user-to-IP mapping is the Active Directory domain controller, monitored by a PAN-OS integrated User-ID agent. However, a critical medical imaging application requires users to authenticate via a RADIUS server, and these logins are not captured from AD. To ensure complete user coverage, which two methods should be configured? (Select TWO)

    Answer and explanation

    Correct answers: A, D

  4. Question 4

    A security engineer is configuring SSL Forward Proxy decryption. To ensure corporate policy compliance, all decrypted traffic must be inspected for threats and sensitive data patterns. However, an explicit exception must be made for traffic destined for financial and healthcare domains to protect user privacy. Which configuration represents the best practice to achieve this goal?

    Answer and explanation

    Correct answer: C

    The best practice for managing decryption exceptions is to use a dedicated Decryption policy rulebase. By placing a specific 'No Decrypt' rule at the top for sensitive categories (Financial Services, Health and Medicine), you ensure this traffic is explicitly bypassed. A second, broader rule below it can then enforce decryption for all other traffic. This provides clear, auditable policy control.

  5. Question 5

    True or False: When configuring a Palo Alto Networks firewall in Virtual Wire mode, it is possible to apply App-ID, Content-ID, and User-ID inspection to the traffic passing through the virtual wire.

    Answer and explanation

    Correct answer: A

    This statement is true. A key feature of the Virtual Wire deployment mode is its ability to be inserted into a network segment transparently (like a bump on the wire) while still providing full Layer 7 threat inspection capabilities. All traffic passing through the v-wire can be subjected to Security policies that leverage App-ID, Content-ID, and User-ID.

  6. Question 6

    An administrator is investigating a performance issue on a PA-5260 firewall. They run the CLI command show session info and receive the output below. Based on the output, what is the most likely cause of the performance degradation?

    --------------------------------------------------------------------------------
    Sess Alloc Max Util
    --------------------------------------------------------------------------------
    session 487216 1000000 48%
    packet buffer 512000 512000 100%
    tcpssid 99999 100000 99%
    cps 14500 15000 96%
    --------------------------------------------------------------------------------
    
    Answer and explanation

    Correct answer: C

    The output clearly shows 'packet buffer Util' at 100%. Packet buffers are used to temporarily store packets during processing. When they are exhausted, the firewall will start dropping packets, leading to significant performance degradation, retransmissions, and slow application response. This indicates the firewall is unable to process traffic as fast as it is arriving, often due to being undersized for the traffic load or a misconfiguration causing excessive buffering.

  7. Question 7

    A retail company is deploying VM-Series firewalls in AWS to protect its e-commerce application. The architecture requires that the firewalls scale automatically based on traffic load. The company uses an AWS Network Load Balancer (NLB) to distribute traffic to the firewalls. Which interface type must be used on the VM-Series firewall to support this scalable, load-balanced design?

    Answer and explanation

    Correct answer: D

    When deploying VM-Series firewalls behind a load balancer in a public cloud for auto-scaling, the firewalls must operate in Layer 3 mode. The NLB forwards traffic to the IP address of the firewall's Layer 3 interface. This allows the firewall to act as a routing hop, perform source NAT on the egress traffic to ensure symmetric return flows, and participate in the scalable architecture. Other modes like Virtual Wire or Layer 2 are not suitable for this cloud-native, load-balanced design.

  8. Question 8

    When creating a custom application signature (App-ID), what is the primary purpose of defining a 'Parent App'?

    Answer and explanation

    Correct answer: C

    The 'Parent App' setting is crucial for custom App-IDs. It tells the firewall which existing application decoder (e.g., ssl, http, ssh) to use to parse the traffic stream. The custom signature is then applied to the decoded application data. If the parent app is not correctly identified (e.g., setting it to 'http' for an SSL-encrypted app), the firewall cannot decrypt or decode the traffic, and the custom signature will never match.

  9. Question 9

    An administrator is configuring a destination NAT policy to translate a public IP address to an internal web server. The web server hosts multiple websites using different host headers on the same IP address and port (e.g., www.company-a.com and www.company-b.com both resolve to the same public IP). The administrator needs to ensure that after NAT, the original host header is preserved so the internal web server can route the request to the correct website. Which configuration option is required?

    Answer and explanation

    Correct answer: B

    When using destination NAT for services that rely on the HTTP Host Header (like virtual hosting), simply translating the IP address can cause issues. By setting the Translated Address type to 'FQDN' in the NAT policy, the firewall performs a DNS lookup for the FQDN and uses the result for the destination IP translation. Crucially, this mode ensures that the original Host Header from the client's request is preserved and passed to the internal server, allowing it to serve the correct website.

  10. Question 10

    A security team is analyzing firewall logs after a suspected data exfiltration event. They have identified the attacker's IP address and the timeframe of the attack. They need to find all files that were transferred from their internal network to the attacker's IP address during that time. Which log type and filter combination would most efficiently provide this information?

    Answer and explanation

    Correct answer: D

    The Data Filtering log is specifically designed to record instances where files or data patterns matching a Data Filtering profile are detected in traffic. To find files transferred outbound to an attacker, the correct approach is to query the Data Filtering log, filter for the attacker's destination IP (dst in 1.2.3.4), and specify the direction as 'upload' (from the perspective of the internal network). This provides the most direct and accurate list of potential exfiltration events.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 233 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon