Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Paloalto Networks > Network Security Administrator > SSE-Engineer

SSE-Engineer Palo Alto Networks Security Service Edge Engineer Question and Answers

Question # 4

What is the purpose of embargo rules in Prisma Access?

A.

Rate-limiting connections originating from specific countries

B.

Allowing traffic only from specific countries

C.

Blocking connections from specific countries

D.

Blocking traffic from Russia, China, and North Korea only

Full Access
Question # 5

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Full Access
Question # 6

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario as above.] Which two options will allow the engineer to support the requirements? (Choose two.)

A.

Configure the CPE with Static Routes pointing to Prisma Access Infrastructure and Mobile User routes.

B.

Enable eBGP for dynamic routing and configure Remote Networks.

C.

Configure Remote Networks and define the branch IP subnets using Static Routes.

D.

Enable Remote Networks Advertise Default Route.

Full Access
Question # 7

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

A.

There is a misconfiguration in the DNS settings on the connector.

B.

The connector is deployed behind a double NAT.

C.

The connector is using a dynamic IP address.

D.

There is a high latency in the network connection.

Full Access
Question # 8

An engineer is troubleshooting split-tunneling on a Palo Alto Networks VPN client. The local LAN interface is on the 192.168.1.0/24 network, and the Prisma Access Mobile User IP Pool is configured as 172.16.72.0/23 in Strata Cloud Manager (SCM). Based on the image below, which statement regarding the split-tunneling configuration for the VPN client is valid?

A.

9.9.9.9/32 has been explicitly configured as an include route.

B.

192.168.5.95/32 has been explicitly configured as an exclude route.

C.

10.10.10.10/32 has been explicitly configured as an include route.

D.

172.16.73.1/32 has been explicitly configured as an exclude route.

Full Access
Question # 9

A large retailer has deployed all of its stores with the same IP address subnet. An engineer is onboarding these stores as Remote Networks in Prisma Access. While onboarding each store, the engineer selects the " Overlapping Subnets " checkbox. Which Remote Network flow is supported after onboarding in this scenario?

A.

To private applications

B.

To the internet

C.

To remote network

D.

To mobile users

Full Access
Question # 10

What are two advantages the Prisma Access Browser (PAB) offers in providing consistent security for accessing web-based resources across corporate-managed laptops and personal devices, as well as contractors using devices issued by third parties? (Choose two.)

A.

It enforces SSL Forward Proxy decryption to enable inspection of encrypted traffic, allowing for enhanced security and threat prevention capabilities.

B.

It provides all users on any devices secure access to the internet with enhanced security and threat prevention capabilities for encrypted traffic.

C.

It routes all traffic to Prisma Access to perform deep packet inspection of encrypted traffic, allowing for enhanced security and threat prevention capabilities.

D.

It applies an encryption layer to protect all browser assets with a trusted encryption chain that is independent of the operating system.

Full Access
Question # 11

A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access. What are two reasons for this behavior? (Choose two.)

A.

" Collect HIP data " needs to be enabled in the configuration.

B.

User mapping is learned from sources other than gateway authentication.

C.

Firewall loses user mapping due to missed HIP report checks.

D.

HIP-enforced policy is scheduled for certain hours of the day.

Full Access
Question # 12

A company has four branch offices between Canada Central and Canada East which use the same IPSec termination node and have QoS configured with customized bandwidth per site. An engineer wants to onboard a new branch office on the same IPSec termination node. What is the QoS behavior for the new branch office?

A.

Automatically distributed to 25% for each site

B.

Unallocated until manually assigned

C.

Automatically distributed to 20% for each site

D.

Cannot be added to existing QoS configuration

Full Access
Question # 13

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

A.

The Remote Network Security policy source zone is configured as " Untrust. "

B.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

C.

The " Allow inbound flows to other Remote Networks over the Prisma Access backbone " checkbox is selected.

D.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.

Full Access
Question # 14

When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by showing only unique devices?

A.

Add the duplicate entries to the ignore list in IoT Security.

B.

Merge individual devices into a single device with multiple interfaces.

C.

Create a custom role to merge devices with the same hostname and operating system.

D.

Delete all duplicate devices, keeping only those discovered using their management IP addresses.

Full Access
Question # 15

Which feature within Strata Cloud Manager (SCM) allows an operations team to view applications, threats, and user insights for branch locations for both NGFW and Prisma Access simultaneously?

A.

Command Center

B.

Log Viewer

C.

Branch Site Monitor

D.

SASE Health Dashboard

Full Access
Question # 16

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Full Access
Question # 17

A financial institution needs to prevent employees from easily moving textual information from secure financial portals accessed using Prisma Access Browser (PAB) directly into other applications on their workstations. The goal is to stop the practice of selecting data within the browser and then inserting that selected content into external documents or programs. Which PAB control should be configured to disable this particular method of data transference?

A.

Data loss prevention (DLP)

B.

Data Transfer

C.

Clipboard

D.

Webpage Data Masking

Full Access
Question # 18

Which advanced AI-powered functionality does Strata Copilot provide to enhance the capabilities of Prisma Access security teams?

A.

Real-time traffic analysis for automated threat prevention

B.

Initial configuration of Prisma Access using a natural language interface

C.

Customized guidance for resolving issues through recommended next steps

D.

Automated remediation of misconfigured security policies

Full Access
Question # 19

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to its data centers. [Scenario as before, with overlapping prefixes advertised by B2B partners.] Which two actions will meet the customer requirements for the B2B connections? (Choose two.)

A.

Advertise the corresponding network prefixes using eBGP or static routes.

B.

Configure remote networks with NAT pools for each of the B2B connections.

C.

Configure service connections for data center connectivity.

D.

NAT the traffic at the customer premises equipment (CPE).

Full Access
Question # 20

When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?

A.

A URL access management profile with site access set to " Isolate " applied to a Security policy

B.

A DNS Security profile applied to a Security policy with the action of " Isolate " for the target remote browser DNS categories

C.

An RBI profile applied to the URL access management profile

D.

A Security policy with the target URL categories and set the action to " Isolate "

Full Access