Practice SSE-Engineer Prisma Access Administration And Operation questions with full explanations on every answer.
Start practicing
Prisma Access Administration And Operation — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator is troubleshooting a HIP (Host Information Profile) check failure for mobile users. Where can the administrator view the collected HIP reports and check compliance status in real-time?
2Where do administrators configure service connections in Prisma Access to connect the cloud security infrastructure to the organization's data center or headquarters?
3An administrator needs to ensure that mobile users connecting via Prisma Access resolve internal domain names using the corporate DNS servers rather than public resolvers. Where is this configured?
4An administrator notices that specific applications identified via App-ID are failing decryption inspection in Prisma Access because the server uses an unsupported cipher suite. Where can the administrator adjust the SSL decryption profile to resolve handshake failures?
5An organization requires that specific SaaS applications are accessed only by corporate-managed devices that pass a specific HIP check. Which policy type should the administrator configure?
6An administrator needs to configure remote networks in Prisma Access to connect branch locations. Where is this configuration primarily managed within the Prisma Access architecture?
7A network administrator wants to enable User-ID for mobile users connecting via GlobalProtect in Prisma Access. Which component should be configured to map users to IP addresses when using the Cloud Identity Engine?
8A Prisma Access administrator notices that remote network traffic destined for another remote network (branch-to-branch traffic) is being dropped or failing to establish. What is the required configuration to allow branch-to-branch traffic?
9An administrator wants to configure authentication for mobile users using SAML 2.0 with Prisma Access. Where is the identity provider (IdP) metadata imported and configured?
10A security engineer needs to configure a Security policy rule in Prisma Access that targets users belonging to a specific Active Directory group synced via the Cloud Identity Engine. How should the source user be specified in the Security rule?
11Which pane in the Prisma Access monitoring interface provides an overview of active mobile users, connection status, and geographical distribution?
12An administrator wants to inspect outbound web traffic from mobile users for malware and spyware using Prisma Access. Which security profile type must be attached to the Security policy rule?
13Which action should an administrator take to update the Prisma Access software and plugin versions across the deployment?
14A Prisma Access mobile user reports that they cannot access internal resources, and the GlobalProtect app status shows 'Connected' but with an internal IP address assigned from the reserve pool. What is the most likely cause of routing failure?
15Which tool provides end-to-end visibility into Prisma Access performance, user experience metrics, and digital experience monitoring (DEM)?
16An administrator needs to configure secure access for remote networks using dynamic routing (BGP). Where are the BGP peer parameters, local AS number, and peer AS configured in Prisma Access?
17An administrator is troubleshooting connectivity issues for a remote network connected to Prisma Access via IPsec VPN. Which TWO checks should be performed to verify tunnel health and status? (Choose two)
18When configuring Security policy rules in Prisma Access, which THREE types of criteria can be used to control traffic traversing the cloud infrastructure? (Choose three)
19An administrator wants to ensure that mobile users comply with security posture policies before accessing corporate applications. Which TWO elements are required to enforce HIP (Host Information Profile) checking? (Choose two)
20An administrator is configuring Mobile Users in Prisma Access and needs to set up user authentication. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)
21An administrator is setting up the Cloud Identity Engine (CIE) to support user mapping and authentication for Prisma Access. Which THREE components or steps are required for a successful CIE deployment? (Choose three)
22An administrator is configuring security policies in Prisma Access and wants to ensure comprehensive protection against unknown threats and malware. Which TWO security profile types should be applied to outbound and internet-bound rules? (Choose two)
23An administrator needs to optimize mobile user traffic performance and reduce latency in Prisma Access. Which THREE features or configurations can be utilized to achieve this? (Choose three)
24When designing high availability and redundancy for Prisma Access Remote Networks, which THREE considerations or practices are essential? (Choose three)
25An administrator is reviewing the operational health and logs of Prisma Access. Which TWO monitoring tools or log types are available within Panorama for troubleshooting security events and traffic flows? (Choose two)
26An administrator is configuring Remote Networks in Prisma Access for a branch office using Internet Key Exchange Version 2 (IKEv2). During the configuration in Panorama, which component must be deployed on the branch office router to ensure proper IPsec tunnel establishment with the Prisma Access Service Connections and Remote Networks nodes?
27An enterprise using Prisma Access Mobile Users needs to enforce Host Information Profile (HIP) checks to ensure that endpoints have an active and updated corporate antimalware solution before granting access to internal applications. Which workflow must an administrator complete to successfully enforce this requirement?
28An administrator wants to view real-time metrics, node status, and active connection counts for Prisma Access Mobile Users and Remote Networks directly from Panorama. Which tool within Panorama should the administrator access?
29An organization is migrating its identity provider integration to the Cloud Identity Engine (CIE) to support Prisma Access authentication and User-ID. When configuring the connection between CIE and the enterprise Active Directory, which component is required on-premises to sync directory objects securely without opening inbound firewall ports?
30An administrator configures Decryption Policies in Prisma Access to inspect inbound traffic destined for internal applications published via Service Connections. Users report that certain internal web applications using custom internal Certificate Authorities (CAs) are failing TLS handshakes. Where should the administrator check and install the enterprise internal CA certificate to resolve this inspection issue?
31An administrator is troubleshooting a scenario where remote users connected via Prisma Access Mobile Users cannot access a specific newly added subnet behind a Remote Network location. Which configuration check should the administrator perform first in Panorama?
32An administrator is configuring User-ID and authentication for Prisma Access using the Cloud Identity Engine (CIE). Which TWO actions must be performed to ensure successful authentication and group-based policy enforcement? (Choose two)
33You are troubleshooting a Mobile User connectivity issue where users cannot access internal resources. The Cloud Identity Engine (CIE) shows the user as authenticated, but the Security Policy log shows the traffic is dropped with 'policy-deny'. What is the most likely cause?
34An administrator is reviewing the status of Remote Networks in Prisma Access and notices that an IPsec tunnel has failed to establish. Which THREE diagnostic steps or verifications should the administrator perform in Panorama or Prisma Access Insights? (Choose three)
35When designing Security and Inspection Policies for Prisma Access, an administrator needs to ensure optimal performance and security coverage. Which THREE best practices should the administrator follow when implementing Security Policy rules in Panorama for Prisma Access? (Choose three)
36A network administrator needs to restrict access for remote users to a specific SaaS application based on their device's security posture. Which configuration sequence allows this in Prisma Access?
37Which component in Prisma Access is responsible for performing decryption, content inspection, and threat prevention for mobile users?
38When configuring a Remote Network (RN) connection to an on-premises data center, which parameter is required to ensure proper routing of internal traffic via the IPSec tunnel?
39You are deploying Prisma Access and need to ensure that traffic from mobile users accessing the internet is inspected by a specific set of security profiles. Where should these profiles be applied?
40What is the primary function of the GlobalProtect Portal in a Prisma Access deployment?
41A user is experiencing 'Gateway not found' errors. Which troubleshooting step is most effective for verifying if the GlobalProtect Gateway is reachable?
42When using Cloud Identity Engine (CIE) for authentication, which method allows for the most seamless user experience for mobile users?
43Which object type should be used to restrict access to a specific internal application for Remote Network users while ensuring the policy is scalable?
44What is the benefit of using Prisma Access for Remote Networks instead of traditional site-to-site VPNs?
45Which TWO of the following are prerequisites for setting up Cloud Identity Engine (CIE) with Prisma Access?
46Which THREE items must be configured to successfully enforce HIP-based security policies for mobile users?
47When managing Security Policies in Prisma Access, which TWO components are essential to ensure that policies are correctly applied to traffic?
48Which THREE factors influence the selection of a Compute Location in a Prisma Access deployment?
49Which TWO configuration steps are required to allow internet access for Remote Network users?
The Prisma Access Administration And Operation domain covers the key concepts tested in this area of the SSE-Engineer exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SSE-Engineer domains — no account required.
The Courseiva SSE-Engineer question bank contains 49 questions in the Prisma Access Administration And Operation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Prisma Access Administration And Operation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included