Study Guide For SE Data Center Professional Exam (PSE: Data Center - P)
Study Guide For SE Data Center Professional Exam (PSE: Data Center - P)
Overview:
This
document
is
the
Study
Guide
for
the
Palo
Alto
Networks
Systems
Engineer:
Data
Center
–
Professional
Accreditation
Exam,
abbreviated
as
PSE:
Data
Center
–
P.
Prerequisites:
It’s
expected
that
you
will
have
met
three
prerequisites
before
attempting
this
exam:
• You
have
passed
the
Palo
Alto
Networks
Systems
Engineer:
Data
Center
–
Associate
Accreditation
Exam,
abbreviated
as
PSE:
Data
Center
–
A.
• You
have
passed
the
Palo
Alto
Networks
Systems
Engineer:
Platform
–
Professional
Accreditation
Exam,
abbreviated
as
PSE:
Platform
–
P.
• You
have
completed
a
year
of
full-‐time
experience
as
a
Palo
Alto
Networks
SE,
either
as
a
Palo
Alto
Networks
employee
SE
or
as
a
Partner
employee
SE.
Exam
Format:
The
test
format
is
approximately
40
items,
all
multiple-‐choice.
You
will
have
50
minutes
to
complete
the
items
for
English
speaking,
an
additional
30
minutes
for
non-‐native
English
speakers.
Sample Question: How many more NPCs can fit in a PA-‐7080 compared to a PA-‐7050?
A. Four
B. Six
C. Eight
D. It depends upon whether the front-‐to-‐back airflow duct is in use.
Answer: A
Sample
Question:
In
addition
to
the
expanded
capacity
for
NPCs,
what
else
is
improved
in
the
PA-‐7080
over
the
PA-‐7050?
D. Available 100Gbps interfaces, but only with PAN-‐OS 7.0 and higher
Answer: C
Objective DP-‐020: I can design a customer's implementation of Palo Alto Networks products.
Sample
Question:
What
is
the
maximum
number
of
QSFP+
interfaces
that
can
be
supported
in
a
PA-‐7080,
and
what
is
the
minimum
version
of
PAN-‐OS
required
to
support
them?
Answer: F
Objective DP-‐030: I can size Palo Alto Networks products to meet the customer's needs.
Sample
Question:
By
increasing
the
number
of
vCPUs
in
a
VM-‐Series
firewall
from
4
to
8,
by
what
factor
is
performance
expected
to
increase?
A.
By
approximately
a
factor
of
2
Answer: D
Sample Question: What is required to support the second generation NPCs on a PA-‐7050?
A. The PA-‐7050 cannot support the second generation NPCs; a PA-‐7080 is required.
D. The second generation NPCs must be installed in matched pairs.
Answer: C
Sample Question: Which of these statements is true about Dynamic Address Groups?
A.
They
allow
you
to
create
a
policy
that
automatically
adapts
to
changes—adds,
moves,
or
deletions
of
servers.
B.
They
enable
the
flexibility
to
apply
different
rules
to
the
same
server
based
on
tags
that
define
its
role
on
the
network,
the
operating
system,
or
the
different
kinds
of
traffic
it
processes.
C. A dynamic address group uses tags as a filtering criterion to determine its members.
D. The filtering criteria uses logical and, or, and not operators.
Sample Question: What is the difference between static and dynamic tags?
C.
Static
tags
are
part
of
the
configuration
on
the
firewall,
but
dynamic
tags
are
part
of
the
runtime
configuration.
D.
Static
tags
are
hard
coded
into
each
VM,
but
dynamic
tags
are
assigned
by
the
firewall
during
runtime.
Answer: C
Objective DP-‐230: I understand and can configure HA on VM-‐Series firewalls.
Sample
Question:
Which
statement
is
true
regarding
the
HA3
interface
on
VM-‐Series
firewalls
in
an
HA
configuration?
A.
The
second
VM-‐Series
firewall
should
be
in
a
different
host
and
the
HA3
connection
should
be
over
a
dedicated
high-‐speed
link.
B.
The
second
VM-‐Series
firewall
should
be
in
the
same
virtual
machine
so
the
HA3
connection
does
not
have
to
travel
over
a
physical
connection.
C. The HA3 connection should traverse no more than a single virtual switch.
Answer: D
Sample Question: Which three of these are valid profiles for configuring HA timers?
A. Recommended
B. Custom
C. Aggressive
D. Low-‐latency
E. Advanced
Sample Question: What is the default interval for the HA heartbeat?:
A. 100 milliseconds
B. 1000 milliseconds
C. 2 seconds
D. 5 seconds
Answer: B
Objective DP-‐260: I can configure a VM-‐Series firewall on supported virtualization platforms.
Study
Resources:
These
are
the
study
resources
for
this
exam.
Many
exam
items
are
taken
verbatim
from
these
resources.
General:
https://paloaltonetworks.com/resources/datasheets/product-‐summary-‐specsheet.html
PA-‐7000 Series:
https://www.paloaltonetworks.com/products/platforms/firewalls/pa-‐
7050/overview.html
https://www.paloaltonetworks.com/resources/datasheets/pa-‐7000-‐series.html
https://paloaltonetworks.com/content/campaigns/pa-‐7050/pa-‐7050/index.html
https://www.paloaltonetworks.com/content/dam/paloaltonetworks-‐
com/en_US/assets/pdf/technical-‐documentation/hardware-‐guides/PA-‐7050/PA-‐
7050_Hardware_Guide.pdf
Virtualized Firewalls:
https://www.paloaltonetworks.com/products/platforms/virtualized-‐firewalls/vm-‐
series/overview.html
VM-‐Series Datasheet:
https://www.paloaltonetworks.com/content/dam/paloaltonetworks-‐
com/en_US/assets/pdf/datasheets/vm-‐series/vm-‐series.pdf
https://www.paloaltonetworks.com/resources/techbriefs/vmware-‐nsx-‐solution-‐
brief.html
https://www.paloaltonetworks.com/resources/datasheets/vm-‐series-‐amazon-‐
web-‐services.html
https://www.paloaltonetworks.com/resources/datasheets/citrix-‐netscaler-‐
sdx.html
https://www.paloaltonetworks.com/resources/datasheets/vm-‐series-‐kvm.html
https://paloaltonetworks.app.box.com/s/1vexf3eps9d23r8f80zo