Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Palo Alto Networks Security Service Edge Engineer SSE-Engineer Exam Questions

Page: 1 / 7 Total 68 questions

Want more questions? Get Premium Access.

Question 1

Which statement applies when enabling multitenancy in Prisma Access (Managed by Panorama)?

Correct Answer: C. Each tenant is allocated its own dedicated Prisma Access instances, with compute resources that are not shared across tenants.

Question 2

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

Correct Answer: D. Dedicated IP addresses

Question 3

How can a senior engineer use Strata Cloud Manager (SCM) to ensure that junior engineers are able to create compliant policies while preventing the creation of policies that may result in security gaps?

Correct Answer: A. Use security checks under posture settings and set the action to ''deny'' for all checks that do not meet the compliance standards.

Question 4

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Correct Answer: B. Enable dump level logs on Global Protect Application.

Question 5

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their credentials on the Identity Provider (IdP) login page, they are redirected to the Prisma Access portal without successful authentication, and they receive this error message: Error: Prisma Access Portal Authentication Failed using CIE-SAML with message ''400 Bad Request''. Which action will identify the root cause of this error? URLs and certificates are correctly configured.

Correct Answer: C. Verify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to confirm that the endpoint

Question 6

During a deployment of Prisma Access (Managed by Strata Cloud Manager) for mobile users, a SAML authentication type and authentication profile in the Cloud Identity Engine application is successfully created. Using this SAML authentication, what is a valid next step to configure authentication for mobile users?

Correct Answer: D. Create a SAML authentication profile in Strata Cloud Manager and link it to the Cloud Identity Engine profile.

Question 7

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Correct Answer: B. Dedicated cloud storage location

Question 8

A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links. With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?

Correct Answer: B. Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.

Question 9

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

Correct Answer: B. Source NAT is enabled, but the branch location's CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

Question 10

An organization deploys the Prisma Access Browser (PAB) to secure web access from diverse endpoints, including personal devices where IT has limited control. To maintain a strong and proactive security posture across these varied environments, why is the use of PAB device posture attributes, such as OS version, file system encryption, and device type, considered essential?

Correct Answer: C. It allows administrators to identify and restrict access based on OS version and browser type on unmanaged devices.