Palo Alto Networks PSE-Prisma-Pro-24 Exam
Palo Alto Networks System Engineer - Prisma Cloud Professional (Page 3 )

Updated On: 7-Feb-2026

Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)

  1. Excessive login failures
  2. Unusual user activity
  3. Denial-of-service activity
  4. Account hijacking attempts
  5. Suspicious file activity

Answer(s): A,B,D

Explanation:

Account hijacking attempts
--Detect potential account hijacking attempts discovered by identifying unusual login activities. These can happen if there are concurrent login attempts made in short duration from two different geographic locations, which is impossible time travel
, or login from a previously unknown browser, operating system, or location.
Excessive login failures
--Detect potential account hijacking attempts discovered by identifying brute force login attempts. Excessive login failure attempts are evaluated dynamically based on the models observed with continuous learning.

Unusual user activity
--Discover insider threat and an account compromise using advanced data science. The Prisma Cloud machine learning algorithm profiles a user's activities on the console, as well as the usage of access keys based on the location and the type of cloud resources. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud- policies/anomaly-policies.html



An administrator deploys a VM-Series firewall into Amazon Web Services.
Which attribute must be disabled on the data-plane elastic network interface for the instance to handle traffic that is not destined to its own IP address?

  1. security group
  2. tags
  3. elastic ip address
  4. source/destination checking

Answer(s): D

Explanation:

https://docs.paloaltonetworks.com/vm-series/8-1/vm-series-deployment/set-up-the-vm-series- firewall-on-aws/deploy-the-vm-series-firewall-on-aws/launch-the-vm-series-firewall-on-aws.html



Which Google Cloud Platform project shares its VPC networks with other projects?

  1. Service project
  2. Host project
  3. Admin project
  4. Subscribing project

Answer(s): B

Explanation:

Create a shared VPC using the Trust VPC created when you deployed the firewall template. Set up a shared VPC for the host (firewall) project:
gcloud compute shared-vpc enable HOST_PROJECT_ID

https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series- firewall-on-google-cloud-platform/autoscaling-on-google-cloud-platform/deploy-autoscaling-on- google-cloud.html



An administrator has deployed an AWS transit gateway and used multiple VPC spokes to segregate a multi-tier application. The administrator also created a security VPC with multiple VM-Series NGFWs in an active/active deployment model via ECMP using Amazon Web Services VPN-based attachments.
What must be configured on the firewall to avoid asymmetric routing?

  1. source address translation
  2. destination address translation
  3. port address translation
  4. source and destination address translation

Answer(s): A



Which two items are required when a VM-100 BYOL instance is upgraded to a VM-300 BYOL instance? (Choose two.)

  1. UUID
  2. new Auth Code
  3. CPU ID
  4. API Key

Answer(s): B,D

Explanation:

In a public cloud deployment, if your firewall is licensed with the BYOL option, you must Deactivate VM before you change the instance type or VM type and apply the license again on the firewall after you complete the model or instance upgrade.
When you change the instance type, because the firewall has a new UUID and CPU ID, the existing license will no longer be valid. https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series- firewall/upgrade-the-vm-series-firewall/upgrade-the-vm-series-model



Viewing page 3 of 24
Viewing questions 11 - 15 out of 115 questions



Post your Comments and Discuss Palo Alto Networks PSE-Prisma-Pro-24 exam prep with other Community members:

Join the PSE-Prisma-Pro-24 Discussion