Easter Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks SSE-Engineer Palo Alto Networks Security Service Edge Engineer Exam Practice Test

Page: 1 / 5
Total 50 questions

Palo Alto Networks Security Service Edge Engineer Questions and Answers

Question 1

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers.

The solution must meet these requirements:

The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.

The branch locations must have internet filtering and data center connectivity.

The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.

The security team must have access to manage the mobile user and access to branch locations.

The network team must have access to manage only the partner access.

Which two options will allow the engineer to support the requirements? (Choose two.)

Options:

A.

Configure the CPE with Static Routes pointing to Prisma Access Infrastructure and Mobile User routes.

B.

Enable eBGP for dynamic routing and configure RemoteNetworks.

C.

Configure Remote Networks and define the branch IP subnets using Static Routes.

D.

Enable Remote Networks Advertise Default Route.

Question 2

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Options:

A.

Specified internal security appliance

B.

Dedicated cloud storage location

C.

Panorama

D.

Strata Cloud Manager (SCM)

Question 3

What is the impact of selecting the “Disable Server Response Inspection” checkbox after confirming that a Security policy rule has a threat protection profile configured?

Options:

A.

Only HTTP traffic from the server to the client will bypass threat inspection.

B.

The threat protection profile will override the 'Disable Server Response Inspection1 only for HTTP traffic from the server to the client.

C.

All traffic from the server to the client will bypass threat inspection.

D.

The threat protection profile will override the 'Disable Server Response Inspection1 for all traffic from the server to the client.

Question 4

Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)

Options:

A.

Configure a webhook to receive notifications of IP address changes.

B.

Copy the Egress IP API Key in the service infrastructure settings.

C.

Enable the Egress IP API endpoint in Prisma Access.

D.

Download a client certificate to authenticate to the Egress IP API.

Question 5

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy.

Which statement explains the branch traffic behavior?

Options:

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as “Trust.”

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Question 6

An engineer has configured IPSec tunnels for two remote network locations; however, users are experiencing intermittent connectivity issues across the tunnels.

What action will allow the engineer to receive notifications when the IPSec tunnels are down or experiencing instability?

Options:

A.

Create a new notification profile specifying conditions for remote network IPSec tunnels.

B.

Create a tunnel log notification rule to alert on specified remote network IPSec tunnel conditions.

C.

Set up the operational health dashboard to email alerts for remote Network IPSec tunnel issues.

D.

Select the IPSec tunnel monitoring and notifications checkbox when configuring the remote network IPSec tunnels.

Question 7

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their credentials on the Identity Provider (IdP) login page, they are redirected to the Prisma Access portal without successful authentication, and they receive this error message:

Error: Prisma Access Portal Authentication Failed using CIE-SAML with message “400 Bad Request”

Which action will identify the root cause of this error?

Options:

A.

Verify the SAML metadata configuration in both Strata Cloud Manager and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.

B.

Examine the Security policy rules in Prisma Access to ensure that traffic from the IdP is allowed and not blocked.

C.

Verify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.

D.

Review the Authentication logs in Strata Cloud Manager to check for any SAML error messages or authentication failures.

Question 8

In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?

Options:

A.

Apply File Blocking to stop file uploads containing financial information.

B.

Configure an Enterprise DLP rule to block uploads containing financial information.

C.

Add the ChatGPT domains using URL Filtering to block uploads containing financial information.

D.

Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.

Question 9

Which statement applies when enabling multitenancy in Prisma Access (Managed by Panorama)?

Options:

A.

Service connection licenses will be assigned only to the first tenant, and these service connections can be shared with the other tenants.

B.

A single tenant cannot consist solely of mobile users or solely of remote networks.

C.

Each tenant is allocated its own dedicated Prisma Access instances, with compute resources that are not shared across tenants.

D.

There is flexibility to manage different tenants using separate Panoramas, which allows for better organization and management of the multiple tenants.

Question 10

A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links.

With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?

Options:

A.

Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string attribute on the mobile user prefixes in its respective Prisma Access region.

B.

Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.

C.

Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile user prefixes in its respective Prisma Access region.

D.

Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes originating from the other region.

Question 11

What is the flow impact of updating the Cloud Services plugin on existing traffic flows in Prisma Access?

Options:

A.

They willexperience latency during the plugin upgrade process.

B.

They will automatically terminate when the upgrade begins.

C.

They will be unaffected because the plugin upgrade is transparent to users.

D.

They will be unaffected only if Panorama is deployed in high availability (HA) mode.

Question 12

Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?

Options:

A.

Geneve

B.

IPSec

C.

GRE

D.

DTLS

Question 13

An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up.

Which two elements must the engineer validate to solve the issue? (Choose two.)

Options:

A.

Secret

B.

MRAI Timers

C.

Peer AS Number

D.

Advertise Default Route Checkbox

Question 14

What must be configured to accurately report an application's availability when onboarding a discovered application for ZTNA Connector?

Options:

A.

icmp ping

B.

https ping

C.

tcp ping

D.

udp ping

Question 15

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy.

Which statement explains the branch traffic behavior?

Options:

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as “Trust.”

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Page: 1 / 5
Total 50 questions