Palo Alto Networks
PSE-SASE
Q1:
In an SD-WAN deployment, what allows customers to modify resources in an automated fashion instead of logging on to a central controller or using command-line interface (CLI) to manage all their configurations?
○
A
dynamic user group (DUG)○
B
DNS server○
C
application programming interface (API)○
D
WildFire
Palo Alto Networks
PSE-SASE
Q2:
What is a disadvantage of proxy secure access service edge (SASE) when compared to an inline SASE solution?
○
A
Proxies force policy actions to be treated as business decisions instead of compromises due to technical limitations.○
B
Teams added additional tools to web proxies that promised to solve point problems, resulting in a fragmented and ineffective security architecture.○
C
Proxy solutions require an unprecedented level of interconnectivity.○
D
Exclusive use of web proxies leads to significant blind spots in traffic and an inability to identify applications and threats on non-standard ports or across multiple protocols.
Palo Alto Networks
PSE-SASE
Q3:
In which step of the Five-Step Methodology for implementing the Zero Trust model is the Kipling Method relevant?
○
A
Step 3: Architect a Zero Trust network○
B
Step 5: Monitor and maintain the network○
C
Step 4: Create the Zero Trust policy○
D
Step 2: Map the transaction flows
Palo Alto Networks
PSE-SASE
Q4:
Which type of access allows unmanaged endpoints to access secured on-premises applications?
○
A
manual external gateway○
B
secure web gateway (SWG)○
C
GlobalProtect VPN for remote access○
D
Prisma Access Clientless VPN
Palo Alto Networks
PSE-SASE
Q5:
What is an advantage of next-generation SD-WAN over legacy SD-WAN solutions?
○
A
It enables definition of the privileges and responsibilities of administrative users in a network.○
B
It allows configuration to forward logs to external logging destinations, such as syslog servers.○
C
It steers traffic and defines networking and security policies from an application-centric perspective, rather than a packet-based approach.○
D
It provides the ability to push common configurations, configuration updates, and software upgrades to all or a subset of the managed appliances.