This is a non-comprehensive, personal reference for the Palo Alto PSE Software Firewall Professional certification exam.
The exam is broken into multiple domains:
- Domain 1: Technical Business Value
- Domain 2: Competitive Differentiators
- Domain 3: Architecture and Planning
- Domain 4: Demonstration and Evaluation
- Domain 5: Network Security Best Practices
Domain 1:
Technical Business Value
- Describe the requirements and components of auto scaling
- Explain the value and operational efficiency of dynamic address groups (DAGs)
- Describe various plugin options and deployment methods
- Describe the process of segmentation
- Describe centralized visibility and deployment models
- Explain how to realize return on investment (ROI) by leveraging Palo Alto Networks software next-generation firewall (NGFW)
- Identity the benefits of Palo Alto Networks solutions to address customer concerns or resistance
Domain 2:
Competitive Differentiators
- Compare and contrast the capabilities of cloud delivered NGFW, VM-Series, and CN-Series
- Create and apply flex credits to both VM-Series and CN-Series
- Describe the importance of third-party integrations
- Descibre the benefits of Cloud-Delivered Security Services (CDSS) and Advanced URL Filtering (AURLF)
- Decibe the benefits of automation as applied by Palo Alto Networks
- Terraform provider
- Ansible
- Dynamic responses to threats
Domain 3:
Architecture and Planning
- Describe CN-Series deployment tool options.
- YAML Ain’t Markup Language (YAML)
- Helm charts
- Terraform templates
- Differentiation
- Compare and contrast VM-Series deployment options
- Describe CN-Series sizing, capabilities, and features
- Describe various segmentation models, includeing East-West and North-South segmentation design per CNet, VNet, and pod
- Describe the concept of growth planning
- Describe placement considerations of Layer 2 and Layer 3 deployments
Domain 4:
Demonstration and Evaluation
- Create, apply, and upgrade licenses
- Execute a successful proof of concept (POC)
- Apply the appropriate deployment / configuration tools for various environments
- Use, deploy, and tag Panorama plugins
- Deploy CN-Series
- Spin up, locate, and demonstrate demon, lab, or Ultimate Test Drive (UTD) instances
Domain 5:
Network Security Best Practices
- Explain why intrazone policies in cloud are a best practice
- Describe the use of object tagging and DAGs
- Explain how Zero Trust relates to VM-Series and CN-Series cloud deployments
- Apply automation and automation tools to deploy Palo Alto Network solutions
- Compare and contrast Prisma Cloud Compute (PCC) and CN-Series