Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Paloalto Networks SSE-Engineer Dumps Questions Answers

Palo Alto Networks Security Service Edge Engineer Questions and Answers

Question 1

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Options:

A.

The rule was created with improper threat management settings.

B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.

C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.

D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.

Buy Now
Question 2

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

Options:

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Question 3

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

Options:

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.

B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.

C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.

D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.

Question 4

What must be configured to accurately report an application ' s availability when onboarding a discovered application for ZTNA Connector?

Options:

A.

icmp ping

B.

https ping

C.

tcp ping

D.

udp ping

Question 5

How can a network security team be granted full administrative access to a tenant ' s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

Options:

A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant ' s scope and assign it to the security team ' s user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team ' s user accounts.

D.

Set the administrative accounts for the security team to the " Superuser " role.

Question 6

Which feature within Strata Cloud Manager (SCM) allows an operations team to view applications, threats, and user insights for branch locations for both NGFW and Prisma Access simultaneously?

Options:

A.

Command Center

B.

Log Viewer

C.

Branch Site Monitor

D.

SASE Health Dashboard

Question 7

An employee is traveling to a country where their employer has not deployed a Prisma Access gateway. Which two mobile user gateways will the VPN client connect to automatically? (Choose two.)

Options:

A.

Backup

B.

Global fallback

C.

Regional fallback

D.

Local zone

Question 8

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario.] Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)

Options:

A.

ZTNA Connector

B.

SD-WAN Connector

C.

Service connections

D.

Colo-Connect

Question 9

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. The solution must meet these requirements: The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations. The branch locations must have internet filtering and data center connectivity. The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports. The security team must have access to manage the mobile user and access to branch locations. The network team must have access to manage only the partner access. How can the engineer configure mobile users and branch locations to meet the requirements?

Options:

A.

Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

B.

Use Explicit Proxy to filter internet traffic and provide access to data center resources using service connections.

C.

Use GlobalProtect to filter internet traffic and provide access to data center resources using service connections.

D.

Use Explicit Proxy and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

Question 10

Which advanced AI-powered functionality does Strata Copilot provide to enhance the capabilities of Prisma Access security teams?

Options:

A.

Real-time traffic analysis for automated threat prevention

B.

Initial configuration of Prisma Access using a natural language interface

C.

Customized guidance for resolving issues through recommended next steps

D.

Automated remediation of misconfigured security policies

Question 11

A customer using Prisma Access (Managed by Panorama) wants to monitor traffic patterns across all remote networks and use Strata Logging Service to gather insights on network usage. An engineer notices that some network data is missing from the Application Command Center (ACC). What should the engineer do to ensure complete data visibility?

Options:

A.

Reconfigure the Prisma Access remote networks to log directly to Panorama instead of using Strata Logging Service.

B.

Verify that the Panorama web interface has been configured to aggregate logs from both the Panorama data and RN-SPNs.

C.

Enable the " Use Data for Pre-Defined Reports " setting in the Logging and Reporting configuration on Panorama.

D.

Ensure that log forwarding profiles are applied to all Prisma Access policies and directed to Strata Logging Service.

Question 12

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to its data centers. [Scenario as before, with overlapping prefixes advertised by B2B partners.] Which two actions will meet the customer requirements for the B2B connections? (Choose two.)

Options:

A.

Advertise the corresponding network prefixes using eBGP or static routes.

B.

Configure remote networks with NAT pools for each of the B2B connections.

C.

Configure service connections for data center connectivity.

D.

NAT the traffic at the customer premises equipment (CPE).

Question 13

An administrator needs to enforce access to all applications via Prisma Access Browser (PAB) for unmanaged or non-compliant devices. Configuration of which two enforcement actions will ensure all access to applications only happens through PAB? (Choose two.)

Options:

A.

For SSO-enabled applications, configure Enforce SSO.

B.

Use Account Protection for non SSO-enabled applications.

C.

Use the PAB Extension to redirect traffic through Prisma Access.

D.

Use Device Posture to allow or block traffic.

Question 14

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

Options:

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Question 15

How can the Prisma Access Browser (PAB) Extension extend an organization ' s web security posture to managed devices that are not connected to a VPN for browser-based access to company-sanctioned web applications?

Options:

A.

It enforces consistent web access and data control policies directly within the browser, regardless of device management status.

B.

It tunnels all endpoint traffic on unmanaged devices, ensuring all device traffic is secured.

C.

It incorporates remote browser isolation (RBI) for the endpoint, running web sessions in a contained environment on any browser.

D.

It optimizes network performance for browser traffic to Prisma Access for all operating systems and browsers.

Question 16

An organization deploys the Prisma Access Browser (PAB) to secure web access from diverse endpoints, including personal devices where IT has limited control. To maintain a strong and proactive security posture across these varied environments, why is the use of PAB device posture attributes, such as OS version, file system encryption, and device type, considered essential?

Options:

A.

It permits PAB to function as a standalone endpoint detection and response (EDR) solution.

B.

It provides the administrators of PAB the ability to enable disk encryption on all endpoints.

C.

It allows administrators to identify and restrict access based on OS version and browser type on unmanaged devices.

D.

It enables the administrators of PAB to independently perform OS and browser patching on unmanaged devices.

Question 17

An employee reports being unable to use any video conferencing features across various web-based collaboration tools. However, colleagues not using the Prisma Access Browser (PAB) can use these features without any problem. Which two policy rule types or categories control this configuration? (Choose two.)

Options:

A.

Browser Security Controls

B.

Browser Customization Controls

C.

Access & Data Controls

D.

Network Security Controls

Question 18

A large retailer has deployed all of its stores with the same IP address subnet. An engineer is onboarding these stores as Remote Networks in Prisma Access. While onboarding each store, the engineer selects the " Overlapping Subnets " checkbox. Which Remote Network flow is supported after onboarding in this scenario?

Options:

A.

To private applications

B.

To the internet

C.

To remote network

D.

To mobile users

Question 19

How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage the Security policy in a single tenant while restricting access to other tenants in a multitenant deployment?

Options:

A.

Add the team to the Parent Tenant, select the Prisma Access Configuration Scope, and set the role to Security Administrator.

B.

Add the team to the Child Tenant, select All Apps & Services, and set the role to Security Administrator.

C.

Add the team to the Parent Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

D.

Add the team to the Child Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

Question 20

In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?

Options:

A.

LDAP

B.

Kerberos

C.

SAML

D.

SSO