Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks SSE-Engineer Palo Alto Networks Security Service Edge Engineer Exam Practice Test

Palo Alto Networks Security Service Edge Engineer Questions and Answers

Question 1

An administrator needs to enforce access to all applications via Prisma Access Browser (PAB) for unmanaged or non-compliant devices. Configuration of which two enforcement actions will ensure all access to applications only happens through PAB? (Choose two.)

Options:

A.

For SSO-enabled applications, configure Enforce SSO.

B.

Use Account Protection for non SSO-enabled applications.

C.

Use the PAB Extension to redirect traffic through Prisma Access.

D.

Use Device Posture to allow or block traffic.

Question 2

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

Options:

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Question 3

In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?

Options:

A.

Apply File Blocking to stop file uploads containing financial information.

B.

Configure an Enterprise DLP rule to block uploads containing financial information.

C.

Add the ChatGPT domains using URL Filtering to block uploads containing financial information.

D.

Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.

Question 4

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

Question # 4

Options:

A.

The Remote Network Security policy source zone is configured as " Untrust. "

B.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

C.

The " Allow inbound flows to other Remote Networks over the Prisma Access backbone " checkbox is selected.

D.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.

Question 5

Which two configurations must be enabled to allow App Acceleration for SaaS applications? (Choose two.)

Options:

A.

Acceleration agent for the client machines

B.

QoS for user traffic

C.

Trusted Root CA for the CA certificate

D.

Forward Trust Certificate for the CA certificate

Question 6

How can the Prisma Access Browser (PAB) Extension extend an organization ' s web security posture to managed devices that are not connected to a VPN for browser-based access to company-sanctioned web applications?

Options:

A.

It enforces consistent web access and data control policies directly within the browser, regardless of device management status.

B.

It tunnels all endpoint traffic on unmanaged devices, ensuring all device traffic is secured.

C.

It incorporates remote browser isolation (RBI) for the endpoint, running web sessions in a contained environment on any browser.

D.

It optimizes network performance for browser traffic to Prisma Access for all operating systems and browsers.

Question 7

Based on the image below, which two statements describe the reason and action required to resolve the errors? (Choose two.)

Question # 7

Options:

A.

The client is misconfigured.

B.

Create a do not decrypt rule for the hostname " google.com. "

C.

The server has pinned certificates.

D.

Create a do not decrypt rule for the hostname " certificates.godaddy.com. "

Question 8

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

Options:

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Question 9

An organization wants Prisma Access Browser (PAB) users to authenticate to public cloud services, such as Microsoft 365, using its existing corporate IdP (e.g., Azure AD). Which integration is essential to enable this automated single sign-on (SSO) experience for public cloud applications accessed via PAB?

Options:

A.

Direct integration of the browser with Microsoft ' s Conditional Access policies

B.

Deployment of a browser-specific SSO extension

C.

Configuration of individual user authentication tokens within the PAB profile

D.

Cloud Identity Engine integration with the corporate IdP

Question 10

What must be configured to accurately report an application ' s availability when onboarding a discovered application for ZTNA Connector?

Options:

A.

icmp ping

B.

https ping

C.

tcp ping

D.

udp ping

Question 11

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?

Options:

A.

Advanced Threat Prevention option to block " Domain Fronting "

B.

Advanced URL Filtering and block the " Malicious Behavior " category

C.

Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "

D.

SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "

Question 12

A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links. With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?

Options:

A.

Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string attribute on the mobile user prefixes in its respective Prisma Access region.

B.

Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.

C.

Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile user prefixes in its respective Prisma Access region.

D.

Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes originating from the other region.

Question 13

Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?

Options:

A.

Geneve

B.

IPSec

C.

GRE

D.

DTLS

Question 14

How can a senior engineer use Strata Cloud Manager (SCM) to ensure that junior engineers are able to create compliant policies while preventing the creation of policies that may result in security gaps?

Options:

A.

Use security checks under posture settings and set the action to " deny " for all checks that do not meet the compliance standards.

B.

Configure role-based access controls (RBACs) for all junior engineers to limit them to creating policies in a disabled state, manually review the policies, and enable them using a senior engineer role.

C.

Configure an auto tagging rule in SCM to trigger a Security policy review workflow based on a security rule tag, then instruct junior engineers to use this tag for all new Security policies.

D.

Use a proxy tagging methodology to onboard using firewall management.

Question 15

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario.] Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)

Options:

A.

ZTNA Connector

B.

SD-WAN Connector

C.

Service connections

D.

Colo-Connect

Question 16

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Options:

A.

The rule was created with improper threat management settings.

B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.

C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.

D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.

Question 17

What is the impact of selecting the " Disable Server Response Inspection " checkbox after confirming that a Security policy rule has a threat protection profile configured?

Options:

A.

Only HTTP traffic from the server to the client will bypass threat inspection.

B.

The threat protection profile will override the " Disable Server Response Inspection " only for HTTP traffic from the server to the client.

C.

All traffic from the server to the client will bypass threat inspection.

D.

The threat protection profile will override the " Disable Server Response Inspection " for all traffic from the server to the client.

Question 18

During a deployment of Prisma Access (Managed by Strata Cloud Manager) for mobile users, a SAML authentication type and authentication profile in the Cloud Identity Engine application is successfully created. Using this SAML authentication, what is a valid next step to configure authentication for mobile users?

Options:

A.

Perform a full commit to Strata Cloud Manager so the Cloud Identity Engine profiles get synchronized from the application.

B.

Permit the Cloud Identity Engine service account RBAC access to the mobile user folder in Strata Cloud Manager.

C.

In Strata Cloud Manager, create a new authentication type of " Cloud Identity Engine. "

D.

Create a SAML authentication profile in Strata Cloud Manager and link it to the Cloud Identity Engine profile.

Question 19

An organization deploys the Prisma Access Browser (PAB) to secure web access from diverse endpoints, including personal devices where IT has limited control. To maintain a strong and proactive security posture across these varied environments, why is the use of PAB device posture attributes, such as OS version, file system encryption, and device type, considered essential?

Options:

A.

It permits PAB to function as a standalone endpoint detection and response (EDR) solution.

B.

It provides the administrators of PAB the ability to enable disk encryption on all endpoints.

C.

It allows administrators to identify and restrict access based on OS version and browser type on unmanaged devices.

D.

It enables the administrators of PAB to independently perform OS and browser patching on unmanaged devices.

Question 20

A company has four branch offices between Canada Central and Canada East which use the same IPSec termination node and have QoS configured with customized bandwidth per site. An engineer wants to onboard a new branch office on the same IPSec termination node. What is the QoS behavior for the new branch office?

Options:

A.

Automatically distributed to 25% for each site

B.

Unallocated until manually assigned

C.

Automatically distributed to 20% for each site

D.

Cannot be added to existing QoS configuration