Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75only

Paloalto Networks SSE-Engineer Palo Alto Networks Security Service Edge Engineer Exam Practice Test

Demo: 20 questions
Total 73 questions

Palo Alto Networks Security Service Edge Engineer Questions and Answers

Question 1

Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?

Options:

A.

Geneve

B.

IPSec

C.

GRE

D.

DTLS

Question 2

A customer using Prisma Access (Managed by Panorama) wants to monitor traffic patterns across all remote networks and use Strata Logging Service to gather insights on network usage. An engineer notices that some network data is missing from the Application Command Center (ACC). What should the engineer do to ensure complete data visibility?

Options:

A.

Reconfigure the Prisma Access remote networks to log directly to Panorama instead of using Strata Logging Service.

B.

Verify that the Panorama web interface has been configured to aggregate logs from both the Panorama data and RN-SPNs.

C.

Enable the " Use Data for Pre-Defined Reports " setting in the Logging and Reporting configuration on Panorama.

D.

Ensure that log forwarding profiles are applied to all Prisma Access policies and directed to Strata Logging Service.

Question 3

In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?

Options:

A.

LDAP

B.

Kerberos

C.

SAML

D.

SSO

Question 4

Which two Prisma Access Browser (PAB) configurations will provide a contractor SSH access to an internal system? (Choose two.)

Options:

A.

Configure Internal Application entries, Configure Access & Data Control policy

B.

Enable Remote Connections

C.

Configure Remote Connection Application entries, Configure Access & Data Control policy

D.

Enable Internal Connections

Question 5

Which feature within Strata Cloud Manager (SCM) allows an operations team to view applications, threats, and user insights for branch locations for both NGFW and Prisma Access simultaneously?

Options:

A.

Command Center

B.

Log Viewer

C.

Branch Site Monitor

D.

SASE Health Dashboard

Question 6

How can an engineer verify that only the intended changes will be applied when modifying Prisma Access policy configuration in Strata Cloud Manager (SCM)?

Options:

A.

Review the SCM portal for blue circular indicators next to each configuration menu item and ensure only the intended areas of configuration have this indicator.

B.

Compare the candidate configuration and the most recent version under " Config Version Snapshots. "

C.

Select the most recent job under Operations > Push Status to view the pending changes that would apply to Prisma Access.

D.

Open the push dialogue in SCM to preview all changes which would be pushed to Prisma Access.

Question 7

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

Options:

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Question 8

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to its data centers. [Scenario as before, with overlapping prefixes advertised by B2B partners.] Which two actions will meet the customer requirements for the B2B connections? (Choose two.)

Options:

A.

Advertise the corresponding network prefixes using eBGP or static routes.

B.

Configure remote networks with NAT pools for each of the B2B connections.

C.

Configure service connections for data center connectivity.

D.

NAT the traffic at the customer premises equipment (CPE).

Question 9

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario.] Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)

Options:

A.

ZTNA Connector

B.

SD-WAN Connector

C.

Service connections

D.

Colo-Connect

Question 10

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?

Options:

A.

Advanced Threat Prevention option to block " Domain Fronting "

B.

Advanced URL Filtering and block the " Malicious Behavior " category

C.

Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "

D.

SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "

Question 11

An organization deploys the Prisma Access Browser (PAB) to secure web access from diverse endpoints, including personal devices where IT has limited control. To maintain a strong and proactive security posture across these varied environments, why is the use of PAB device posture attributes, such as OS version, file system encryption, and device type, considered essential?

Options:

A.

It permits PAB to function as a standalone endpoint detection and response (EDR) solution.

B.

It provides the administrators of PAB the ability to enable disk encryption on all endpoints.

C.

It allows administrators to identify and restrict access based on OS version and browser type on unmanaged devices.

D.

It enables the administrators of PAB to independently perform OS and browser patching on unmanaged devices.

Question 12

Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)

Options:

A.

Configure a webhook to receive notifications of IP address changes.

B.

Copy the Egress IP API Key in the service infrastructure settings.

C.

Enable the Egress IP API endpoint in Prisma Access.

D.

Download a client certificate to authenticate to the Egress IP API.

Question 13

A network administrator is enabling users, via Prisma Access Browser (PAB), to securely access internal web applications hosted exclusively within the organization ' s private data center. Which two Prisma Access infrastructure components are primarily configured to establish the necessary connection pathways from Prisma Access to these internal data center resources? (Choose two.)

Options:

A.

Explicit Proxy

B.

ZTNA Connector

C.

Privileged Remote Access

D.

Service Connection

Question 14

A financial institution needs to prevent employees from easily moving textual information from secure financial portals accessed using Prisma Access Browser (PAB) directly into other applications on their workstations. The goal is to stop the practice of selecting data within the browser and then inserting that selected content into external documents or programs. Which PAB control should be configured to disable this particular method of data transference?

Options:

A.

Data loss prevention (DLP)

B.

Data Transfer

C.

Clipboard

D.

Webpage Data Masking

Question 15

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. The solution must meet these requirements: The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations. The branch locations must have internet filtering and data center connectivity. The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports. The security team must have access to manage the mobile user and access to branch locations. The network team must have access to manage only the partner access. How can the engineer configure mobile users and branch locations to meet the requirements?

Options:

A.

Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

B.

Use Explicit Proxy to filter internet traffic and provide access to data center resources using service connections.

C.

Use GlobalProtect to filter internet traffic and provide access to data center resources using service connections.

D.

Use Explicit Proxy and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

Question 16

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their credentials on the Identity Provider (IdP) login page, they are redirected to the Prisma Access portal without successful authentication, and they receive this error message: Error: Prisma Access Portal Authentication Failed using CIE-SAML with message " 400 Bad Request " . Which action will identify the root cause of this error? URLs and certificates are correctly configured.

Options:

A.

Verify the SAML metadata configuration in both Strata Cloud Manager and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.

B.

Examine the Security policy rules in Prisma Access to ensure that traffic from the IdP is allowed and not blocked.

C.

Verify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.

D.

Review the Authentication logs in Strata Cloud Manager to check for any SAML error messages or authentication failures.

Question 17

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Options:

A.

Specified internal security appliance

B.

Dedicated cloud storage location

C.

Panorama

D.

Strata Cloud Manager (SCM)

Question 18

A company is using Prisma Access with Cloud Identity Engine for user-based policies. Which two system configurations will dynamically grant users access to specific projects based on their group membership in Microsoft Entra ID? (Choose two.)

Options:

A.

Configure Dynamic Privilege Access settings in Prisma Access and associate the user groups with the corresponding project IP address pools.

B.

Create a custom application in Microsoft Entra ID representing each project and configure SSO with the Cloud Identity Engine.

C.

Implement an authentication sequence in Prisma Access that prioritizes Cloud Identity Engine authentication for users belonging to project-specific groups.

D.

In the Cloud Identity Engine, add the Microsoft Entra ID directory as an IdP and configure the required user group mappings for each project.

Question 19

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

Options:

A.

There is a misconfiguration in the DNS settings on the connector.

B.

The connector is deployed behind a double NAT.

C.

The connector is using a dynamic IP address.

D.

There is a high latency in the network connection.

Question 20

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Options:

A.

Verify from the routing table.

B.

Enable dump level logs on Global Protect Application.

C.

Verify zoom.us is resolved by the tunnel assigned DNS server.

D.

Ping zoom.us from the CLI.

Demo: 20 questions
Total 73 questions