Palo Alto Networks
PSE-StrataDC
Q1:
In the following scenario, Route-based firewall redundancy is deployed in a Data Center, which statement is true?

○
A
IP addresses of Firewall interfaces will move between devices when a firewall fails○
B
The 2 firewalls are in Active-Standby HA status○
C
Firewalls use dynamic routing protocols to determine the best path○
D
Floating IP addresses are necessary for HA configuration
Palo Alto Networks
PSE-StrataDC
Q2:
Which two methods provide a virtual IP address when implementing active/active HA? (Choose two )
☐
A
VRRP☐
B
HSRP☐
C
floating IP address☐
D
ARP load sharing
Palo Alto Networks
PSE-StrataDC
Q3:
In which two ways can micro-segmentation save money for the enterprise? (Choose two.)
☐
A
fewer capital expenses because fewer physical servers need to be bought☐
B
fewer operating expenses because a smaller data center is operated☐
C
fewer operating expenses because less public cloud capacity needs to be rented☐
D
fewer capital expenses because the same number of physical servers can be kept in a smaller space
Palo Alto Networks
PSE-StrataDC
Q4:
How does the Palo Alto Networks NGFW integrate with Arista Networks Macro-Segmentation Service?
○
A
Arista supports all hardware models of the Palo Alto Networks NGFW natively.○
B
Arista allows standalone non-HA firewalls to be attached to a service leaf switch. You must configure an Elastic Load Balancer to obtain fault tolerance.○
C
Arista CloudVision obtains relevant rules from Panorama through API and programs the Arista switches to steer intercepted east-west traffic to the Palo Alto Networks NGFW.○
D
Arista owns the Security policy. It can extend the concept of fine-grained intra-hypervisor security for VMs by enabling dynamic insertion of services for virtualized devices such as firewalls
Palo Alto Networks
PSE-StrataDC
Q5:
Which configuration is required in NSX for Panorama to use the tags from security groups in dynamic address groups?
○
A
Create security groups only.○
B
Create security groups and mark them as exchangeable.○
C
Create security groups with tags marked as shareable.○
D
Create security groups and use them in an NSX-to-Palo Alto Networks redirection policy.