Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PSE-StrataDC Practice Exam with Questions & Answers | Set: 2

Questions 11

Is vulnerability analysis against images in the registry sufficient for security?

Options:
A.

Yes, containers do not have unique vulnerabilities.

B.

No, you should do vulnerability analysis only against the running containers, which are vulnerable.

C.

Yes, you are ensuring that the images the containers are based on are secure.

D.

No, you need to do analysis in the CI system, in the registry, and against instantiated containers

Questions 12

Which three software components have integration for deploying a VM-Series firewall in OpenStack? (Choose three)

Options:
A.

Mirantis OpenStack distribution

B.

Nuage VSP SDN controller

C.

VMWare NSX for OpenStack

D.

Cisco ACI

E.

Contrail SDN controller

Questions 13

How does Palo Alto Networks integrate with VXLAN tagging?

Options:
A.

does not integrate with VXLAN tagging, so virtual appliances cannot be provided, but hardware appliances can be offered at the data center gateway border

B.

integrates with VXLAN. but scripting is necessary, and Professional Services should be engaged

C.

integrates fully into VXLAN architectures if they are provided by VMware

D.

does not integrate natively with VXLAN tagging, network equipment can convert VXLAN flows to VLANs and send those VLANs to Palo Alto Networks firewalls

Questions 14

How does Palo Alto Networks VM orchestration help service providers automatically provision security instances and policies on demand? (Choose two.)

Options:
A.

Aperture Orchestration Engine (AOE)

B.

Support for Dynamic Address Groups

C.

Fully instrumented API

D.

VM Orchestration Policy Editor

Questions 15

Why are containers uniquely suitable for whitelist-based runtime security?

Options:
A.

Developers typically define the processes used in their containers within the Dockerfile

B.

Docker has a built-in runtime analysis capability to aid in whitelisting.

C.

Containers typically have only a few defined processes that should ever be executed.

D.

Operations teams typically know what processes are used within a container

Questions 16

How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

Options:
A.

by creating an access policy

B.

through a policy-based redirect (PBR)

C.

contracts between EPGs that send traffic to the firewall using a shared policy

D.

through a virtual machine monitor (VMM) domain

Questions 17

What are two ways to size a VM-Series firewall deployment to secure a VMware ESXi environment? (Choose two )

Options:
A.

one per virtual network

B.

one per vCenter server

C.

one per SaaS application in use

D.

one per ESXi host

Questions 18

In the following scenario, Route-based firewall redundancy is deployed in a Data Center, which statement is true?

PSE-StrataDC Question 18

Options:
A.

IP addresses of Firewall interfaces will move between devices when a firewall fails

B.

The 2 firewalls are in Active-Standby HA status

C.

Firewalls use dynamic routing protocols to determine the best path

D.

Floating IP addresses are necessary for HA configuration

Exam Code: PSE-StrataDC
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks System Engineer Professional - Strata Data Center
Last Update: Jul 15, 2025
Questions: 60