Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which two design options address split brain when configuring high availability (HA)? (Choose two.)
Using the Heartbeat Backup:
The heartbeat backup is a mechanism that helps to prevent split-brain scenarios in a high availability (HA) configuration by providing an additional path for heartbeat communication. This ensures that both firewalls in the HA pair are aware of each other's status.
Palo Alto Networks HA Configuration Guide
Adding a Backup HA1 Interface:
Configuring a backup HA1 interface provides redundancy for the primary HA1 link, ensuring continued communication between HA peers even if the primary link fails. This setup is crucial for maintaining synchronization and preventing split-brain scenarios.
Palo Alto Networks HA Configuration
Which Palo Alto Networks firewall provides network security when deploying a microservices-based application?
The CN-Series firewalls are specifically designed to secure Kubernetes and containerized environments, making them ideal for protecting microservices-based applications. They provide network security by integrating directly with the container orchestration platform.
Palo Alto Networks CN-Series Documentation
Which PAN-OS feature allows for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment?
Dynamic Address Groups in PAN-OS allow for automated updates to address objects when VM-Series firewalls are set up as part of an NSX deployment. These address groups can dynamically include members based on criteria such as tags, enabling automated and flexible security policies that adjust to changes in the virtual environment.
Palo Alto Networks Dynamic Address Groups: Dynamic Address Groups
NSX and VM-Series Integration: NSX Integration Guide
Where do CN-Series devices obtain a VM-Series authorization key?
CN-Series devices obtain a VM-Series authorization key from Panorama. Panorama is the centralized management platform for Palo Alto Networks firewalls, including CN-Series and VM-Series. It provides the necessary authorization keys and other configurations to ensure proper deployment and operation of the firewalls.
Palo Alto Networks Panorama Documentation: Panorama Overview
Palo Alto Networks CN-Series Setup Guide: CN-Series Setup
How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?
In Cisco ACI, traffic is directed to a Palo Alto Networks firewall by creating contracts between endpoint groups (EPGs) that send traffic to the firewall. These contracts define the policy for communication between EPGs, ensuring that traffic is inspected and secured by the firewall before reaching its destination.
Cisco ACI and Palo Alto Networks Integration Guide: Contracts and Policies
Cisco ACI Fundamentals: ACI Contracts
Which two subscriptions should be recommended to a customer who is deploying VM-Series firewalls to a private data center but is concerned about protecting data-center resources from malware and lateral movement? (Choose two.)
For a customer deploying VM-Series firewalls in a private data center and concerned about protecting resources from malware and lateral movement, the following subscriptions are recommended:
Threat Prevention: This subscription provides comprehensive threat detection and prevention capabilities, including IPS, anti-virus, anti-spyware, and vulnerability protection.
WildFire: This advanced threat intelligence service analyzes suspicious files and identifies new malware, providing protection against zero-day exploits and threats.
Palo Alto Networks Threat Prevention: Threat Prevention
Palo Alto Networks WildFire: WildFire
7 domains from the Palo Alto Networks PSE-SoftwareFirewall exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
Covers software firewall types including Cloud-Delivered Security Services, cloud next-generation firewalls, VM-Series and CN-Series firewalls. Examines licensing options such as pay-as-you-go, Enterprise Licence Agreement subscriptions, and Flex licensing.
Sample question from this domain above: Q2
Focuses on methodologies for securing data centers including segmentation and virtualization. Covers application visibility and control plus VPN connectivity controls.
Examines popular centralized and distributed VM-Series deployment types. Describes how to use VM-Series firewalls in high availability scenarios and Google Cloud Platform deployments.
Sample question from this domain above: Q1
Covers software firewall management tools like Panorama, Helm charts, and cloud-specific interfaces. Describes automation tools such as Ansible, Terraform, and AWS CloudFormation templates.
Explains how Intelligent Traffic Offload integrates with VM-Series firewalls. Outlines the deployment process for VM-Series and CN-Series software firewalls using third-party marketplaces and Panorama.
Sample question from this domain above: Q4
Focuses on troubleshooting CN-Series and VM-Series software firewalls. Covers both deployment and traffic-related issues.
Describes Cloud NGFW log forwarding destinations for various cloud platforms. Covers the use of management plugins for public clouds, Kubernetes, and VMware environments.
Common questions about the exam itself