Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Paloalto Networks > Network Security Administrator > SSE-Engineer

SSE-Engineer Palo Alto Networks Security Service Edge Engineer Question and Answers

Question # 4

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

A.

There is a misconfiguration in the DNS settings on the connector.

B.

The connector is deployed behind a double NAT.

C.

The connector is using a dynamic IP address.

D.

There is a high latency in the network connection.

Full Access
Question # 5

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy.

Which statement explains the branch traffic behavior?

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as “Trust.”

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Full Access
Question # 6

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications.

What is a reason for this issue?

A.

The rule was created with improper threat management settings.

B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.

C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.

D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.

Full Access
Question # 7

What is the flow impact of updating the Cloud Services plugin on existing traffic flows in Prisma Access?

A.

They willexperience latency during the plugin upgrade process.

B.

They will automatically terminate when the upgrade begins.

C.

They will be unaffected because the plugin upgrade is transparent to users.

D.

They will be unaffected only if Panorama is deployed in high availability (HA) mode.

Full Access
Question # 8

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

A.

Verify from the routing table.

B.

Enable dump level logs on GlobalProtect Application.

C.

Verify zoom.us is resolved by the tunnel assigned DNS server.

D.

Ping zoom.us from the CLI.

Full Access
Question # 9

Which two configurations must be enabled to allow App Acceleration for SaaS applications? (Choose two.)

A.

Acceleration agent for the client machines

B.

QoS for user traffic

C.

Trusted Root CA for the CA certificate

D.

Forward Trust Certificate for the CA certificate

Full Access
Question # 10

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers.

The solution must meet these requirements:

The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.

The branch locations must have internet filtering and data center connectivity.

The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.

The security team must have access to manage the mobile user and access to branch locations.

The network team must have access to manage only the partner access.

How can the engineer configure mobile users and branch locations to meet the requirements?

A.

Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

B.

Use Explicit Proxy to filter internet traffic and provide access to data center resources using service connections.

C.

Use GlobalProtect to filter internet traffic and provide access to data center resources using service connections.

D.

Use Explicit Proxy and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

Full Access
Question # 11

An engineer has configured IPSec tunnels for two remote network locations; however, users are experiencing intermittent connectivity issues across the tunnels.

What action will allow the engineer to receive notifications when the IPSec tunnels are down or experiencing instability?

A.

Create a new notification profile specifying conditions for remote network IPSec tunnels.

B.

Create a tunnel log notification rule to alert on specified remote network IPSec tunnel conditions.

C.

Set up the operational health dashboard to email alerts for remote Network IPSec tunnel issues.

D.

Select the IPSec tunnel monitoring and notifications checkbox when configuring the remote network IPSec tunnels.

Full Access
Question # 12

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Full Access
Question # 13

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

A.

Specified internal security appliance

B.

Dedicated cloud storage location

C.

Panorama

D.

Strata Cloud Manager (SCM)

Full Access
Question # 14

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header.

Which option will prevent this form of attack?

A.

Advanced Threat Prevention option to block “Domain Fronting”

B.

Advanced URL Filtering and block the “Malicious Behavior” category

C.

Advanced URL Filtering and block “SNI mismatch with Server Certificate (SAN/CN)”

D.

SSL Decryption to “Block sessions on SNI mismatch with Server Certificate (SAN/CN)”

Full Access
Question # 15

Which feature will fetch user and group information to verify whether a group from the Cloud Identity Engine is present on a security processing node (SPN)?

A.

SASE Health Dashboard

B.

User Activity Insights

C.

Prisma Access Locations

D.

Region Activity Insights

Full Access