PSE-STRATA Sample Questions

PSE-STRATA Sample Questions & Answers

Emphasizes security-profile settings tied with interface and zone configuration above everything, then advanced security subscriptions and remote access, PAN-OS basics and the broader product lineup, managing firewalls via Panorama, logging and high availability.

Launch the full PSE-STRATA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Manage and Operate · Troubleshooting Performance

    An administrator is investigating a performance issue on a PA-5260 firewall. They run the CLI command show session info and receive the output below. Based on the output, what is the most likely cause of the performance degradation?

    --------------------------------------------------------------------------------
    Sess Alloc Max Util
    --------------------------------------------------------------------------------
    session 487216 1000000 48%
    packet buffer 512000 512000 100%
    tcpssid 99999 100000 99%
    cps 14500 15000 96%
    --------------------------------------------------------------------------------
    
    Show answer & explanation

    Correct answer: C

    The output clearly shows 'packet buffer Util' at 100%. Packet buffers are used to temporarily store packets during processing. When they are exhausted, the firewall will start dropping packets, leading to significant performance degradation, retransmissions, and slow application response. This indicates the firewall is unable to process traffic as fast as it is arriving, often due to being undersized for the traffic load or a misconfiguration causing excessive buffering.

  2. Question 2Advanced

    Deploy and Configure Core Components · VM-Series Deployment

    A retail company is deploying VM-Series firewalls in AWS to protect its e-commerce application. The architecture requires that the firewalls scale automatically based on traffic load. The company uses an AWS Network Load Balancer (NLB) to distribute traffic to the firewalls. Which interface type must be used on the VM-Series firewall to support this scalable, load-balanced design?

    Show answer & explanation

    Correct answer: D

    When deploying VM-Series firewalls behind a load balancer in a public cloud for auto-scaling, the firewalls must operate in Layer 3 mode. The NLB forwards traffic to the IP address of the firewall's Layer 3 interface. This allows the firewall to act as a routing hop, perform source NAT on the egress traffic to ensure symmetric return flows, and participate in the scalable architecture. Other modes like Virtual Wire or Layer 2 are not suitable for this cloud-native, load-balanced design.

  3. Question 3Beginner

    Deploy and Configure Features and Subscriptions · Custom App-ID

    When creating a custom application signature (App-ID), what is the primary purpose of defining a 'Parent App'?

    Show answer & explanation

    Correct answer: C

    The 'Parent App' setting is crucial for custom App-IDs. It tells the firewall which existing application decoder (e.g., ssl, http, ssh) to use to parse the traffic stream. The custom signature is then applied to the decoded application data. If the parent app is not correctly identified (e.g., setting it to 'http' for an SSL-encrypted app), the firewall cannot decrypt or decode the traffic, and the custom signature will never match.

  4. Question 4Advanced

    Deploy and Configure Core Components · NAT Policy

    An administrator is configuring a destination NAT policy to translate a public IP address to an internal web server. The web server hosts multiple websites using different host headers on the same IP address and port (e.g., www.company-a.com and www.company-b.com both resolve to the same public IP). The administrator needs to ensure that after NAT, the original host header is preserved so the internal web server can route the request to the correct website. Which configuration option is required?

    Show answer & explanation

    Correct answer: B

    When using destination NAT for services that rely on the HTTP Host Header (like virtual hosting), simply translating the IP address can cause issues. By setting the Translated Address type to 'FQDN' in the NAT policy, the firewall performs a DNS lookup for the FQDN and uses the result for the destination IP translation. Crucially, this mode ensures that the original Host Header from the client's request is preserved and passed to the internal server, allowing it to serve the correct website.

  5. Question 5Intermediate

    Manage and Operate · Logging and Reporting

    A security team is analyzing firewall logs after a suspected data exfiltration event. They have identified the attacker's IP address and the timeframe of the attack. They need to find all files that were transferred from their internal network to the attacker's IP address during that time. Which log type and filter combination would most efficiently provide this information?

    Show answer & explanation

    Correct answer: D

    The Data Filtering log is specifically designed to record instances where files or data patterns matching a Data Filtering profile are detected in traffic. To find files transferred outbound to an attacker, the correct approach is to query the Data Filtering log, filter for the attacker's destination IP (dst in 1.2.3.4), and specify the direction as 'upload' (from the perspective of the internal network). This provides the most direct and accurate list of potential exfiltration events.

  6. Question 6Intermediate

    Deploy and Configure Features and Subscriptions · GlobalProtect

    During a GlobalProtect deployment, an engineer must ensure that only corporate-issued laptops that have the latest OS patches and disk encryption enabled can connect to the internal network. Laptops that do not meet these criteria should be placed in a quarantine zone with limited access to remediation servers. Which GlobalProtect feature is required to enforce this policy?

    Show answer & explanation

    Correct answer: C

    Host Information Profile (HIP) is the feature designed for this exact purpose. The GlobalProtect agent collects endpoint state information (like OS patch level, disk encryption status, antivirus version). This data is used to match against HIP Objects on the firewall. Security policies can then use these HIP Objects as match criteria to grant or deny access, or to direct non-compliant users to a specific quarantine zone.

  7. Question 7Intermediate

    Manage and Operate · CLI Commands

    What is the function of the target keyword when using the test security-policy-match CLI command?

    Show answer & explanation

    Correct answer: C

    On a multi-vsys firewall, security policies are unique to each virtual system. The test security-policy-match command requires the context of a specific vsys to perform its lookup. The target keyword and argument are used to specify which virtual system's policy rulebase should be evaluated for the simulated traffic.

  8. Question 8Advanced

    Manage and Operate · Security Policy Troubleshooting

    A company has a security policy that allows SSH traffic from the IT-Admin zone to the Servers zone. An administrator observes in the logs that some SSH sessions are being allowed, but others are being denied by the default interzone-deny rule. All servers are in the correct zone and all admin workstations have the correct source IP. What is the most likely reason for this inconsistent behavior?

    Show answer & explanation

    Correct answer: A

    This is a classic 'application-shift' scenario. A policy based on port (service-tcp-22) will allow the initial TCP handshake. However, once the firewall's App-ID engine inspects the payload and identifies the application as 'ssh', it re-evaluates the session against the security policy. If the policy only matches on the port and not the application, the session will no longer match the allow rule and will be dropped by a subsequent rule (often the default deny). The sessions that work may be from tools that don't fully establish an application session before being closed, while the failing sessions are legitimate, fully identified SSH traffic.

  9. Question 9Intermediate

    Deploy and Configure Firewalls Using Panorama · Variable Precedence

    In a Panorama template stack, variables can be defined at different levels (e.g., Template, Template Stack, Firewall). If a variable named ${gateway_ip} is defined with different values at all three levels for a specific firewall, which value will be used when the configuration is pushed to that firewall?

    Show answer & explanation

    Correct answer: C

    Panorama uses a specific order of precedence for resolving variable values. The most specific value always wins. The order is: Firewall > Template Stack > Template. Therefore, a value defined directly on the managed firewall object itself will override any values for the same variable defined at the higher Template Stack or Template levels.

  10. Question 10Beginner

    Core Concepts and Product Knowledge · Single-Pass Parallel Processing (SP3)

    A pre-sales engineer is presenting the Palo Alto Networks Strata platform to a potential customer. The customer is concerned about performance degradation when multiple security services like App-ID, IPS, and Antivirus are enabled simultaneously. Which core architectural component of PAN-OS addresses this concern by performing all analysis in a single, integrated scan?

    Show answer & explanation

    Correct answer: C

    The Single-Pass Parallel Processing (SP3) Architecture is a fundamental differentiator for Palo Alto Networks. Unlike other architectures that use separate engines or modules for each function (leading to multiple scans and latency), SP3 performs networking, policy lookup, and signature matching for all threats and content in a single pass. This dramatically reduces latency and ensures that performance remains high even with multiple security services enabled.

Ready for the real thing?

The full PSE-STRATA simulator has every exam-style question, timed mode, and instant scoring.