Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An organization requires that Prisma Access Secure Web Gateway inspects all inbound and outbound TLS traffic for employees browsing external websites. However, HR and healthcare applications must be bypassed due to privacy regulations. Where in Panorama must the administrator configure the exception for these categories?
Policies -> Decryption
Decryption policies contain rules that define which traffic to decrypt, block, or no-decrypt based on URL categories.
Panorama -> Cloud Services -> User Access
Network Services -> Prisma Access -> Decryption Bypass
Objects -> Custom URL Category
A network engineer is configuring a Service Connection in Prisma Access to connect the cloud security infrastructure back to the corporate data center. Which routing protocol is supported natively by Prisma Access to dynamically exchange routes over the IPsec VPN tunnel?
BGP
BGP is the industry standard dynamic routing protocol supported across Prisma Access IPsec connections.
EIGRP
RIPv2
OSPF
An administrator wants to deploy Secure Web Gateway (SWG) capabilities in Prisma Access to prevent users from uploading company proprietary data to unauthorized cloud storage applications. Which Prisma Access profile type should be applied to the Security Policy rules to achieve this?
Zone Protection profile
Antivirus profile
Data Filtering profile
Data Filtering profiles inspect content for patterns such as credit cards, SSNs, or custom data patterns to block unauthorized uploads.
URL Filtering profile
An administrator notices that certain mobile users connecting via Prisma Access are experiencing intermittent authentication timeouts when authenticating via SAML 2.0. Where should the administrator check to verify the Identity Provider (IdP) connectivity status and SAML assertion errors within Panorama?
Monitor -> Traffic -> Session End
Objects -> Authentication -> SAML Test
Monitor -> Logs -> Authentication
The Authentication log in Panorama provides detailed records of user login attempts, SAML response parsing, and IdP communication status.
Panorama -> Cloud Services -> Health -> Infrastructure
A security engineer is troubleshooting a ZTNA connection issue where remote users running GlobalProtect are unable to reach internal applications hosted behind a Prisma Access Remote Network. The mobile users and remote networks are in the same region, but direct branch-to-branch routing is failing. Which Prisma Access feature must be verified to ensure direct traffic flow between mobile users and remote networks without backhauling to the cloud service nodes?
Explicit Proxy PAC file redirect
Prisma Access Insights Regional Peering
Mobile User to Remote Network direct routing
This feature allows sessions between mobile users and remote networks to bypass unnecessary cloud node processing when co-located in the same region.
Clean Pipe architecture
An enterprise wants to implement Firewall as a Service (FWaaS) using Prisma Access to protect inter-branch traffic and internet traffic. Which Panorama template type is primarily used to push network and device configurations to Prisma Access nodes?
Stack templates
Prisma Access Global templates
Cloud Services templates
Cloud Services templates are specifically designed to configure Prisma Access Remote Networks, Mobile Users, and Service Connections.
Mobile User dynamic templates
Want more Prisma Access Services practice?
Practice this domainAn administrator implements a new Decryption policy in Prisma Access to inspect inbound traffic to a public-facing application hosted behind a Prisma Access Public IP. After deployment, users report receiving certificate warning errors. What should the administrator inspect first to resolve the warning?
Check whether the GlobalProtect client version on the user's laptop is up to date.
Ensure that WildFire analysis is disabled for inbound decrypted traffic.
Verify that the correct server certificate and private key are imported into Panorama and bound to the Inbound Decryption rule.
If the firewall does not present the correct server certificate to the client, a trust mismatch warning occurs immediately.
Verify the OCSP responder settings under Device > Setup > Sessions.
A Prisma Access engineer is troubleshooting an issue where users in a specific Remote Network location cannot authenticate against an on-premises LDAP server because the Service Connection is dropping packets. What is the recommended Panorama CLI command to test connectivity to the LDAP server through the Service Connection?
Execute 'ping source <dataplane-interface> host <ldap-server-ip>' from the specific Prisma Access node or use operational commands via Panorama.
Sourcing pings from the specific data plane interface ensures traffic correctly traverses the Service Connection tunnel.
Run 'show system resources' to check CPU utilization of the Panorama VM.
SSH to the Prisma Access node or use the Panorama CLI to run 'test security-policy-match' for the LDAP traffic.
Use the CLI command 'ping source <service-connection-ip> <ldap-server-ip>' from the Panorama management plane.
A security administrator needs to check real-time threat logs for a specific Prisma Access mobile user who reports being blocked from accessing a malicious file. Which Panorama menu path provides the most direct access to these logs?
Panorama > Cloud Services > Setup > Management.
Prisma Access > Service Setup > Locations.
Policies > Security.
Monitor > Logs > Threat.
The Threat log viewer in Panorama aggregates security events, WildFire blocks, and anti-spyware alerts across all Prisma Access nodes.
An organization uses SAML authentication with Prisma Access for mobile users. Users report an intermittent 'Authentication Failed' error when trying to establish a GlobalProtect connection. The Identity Provider (IdP) logs show successful authentication, but Prisma Access logs indicate a failure. What is the most likely cause of this discrepancy?
The GlobalProtect client software license has expired on Panorama.
Clock skew between the SAML Identity Provider and the Prisma Access service nodes exceeding the allowed tolerance window.
SAML assertions have strict validity timestamps (NotBefore and NotOnOrAfter); significant clock skew causes the firewall to reject the assertion.
The User-ID agent service on the Panorama management server is stopped.
WildFire cloud subscription has lapsed.
An administrator notices that a subset of mobile users connecting via GlobalProtect in Prisma Access cannot resolve internal corporate hostnames, while external websites load normally. The split-tunnel configuration includes the corporate domain. Where should the administrator check first in Panorama to troubleshoot this DNS resolution failure?
Panorama > Prisma Access > Service Setup > Mobile Users > GlobalProtect Client Settings > Client Config > DNS and-or WINS.
The DNS server IPs and primary/secondary suffixes assigned to GlobalProtect clients are configured and pushed via the Client Settings in Panorama.
Panorama > Prisma Access > Monitoring > ACC.
Panorama > Cloud Services > Status > Traffic Log.
Panorama > Firewall > Network Profiles > Interface.
A network engineer is configuring Prisma Access and needs to verify the status of deployed Mobile User nodes across different regions. Which Panorama workspace is dedicated to displaying the overall health and status of Prisma Access infrastructure?
Panorama > Cloud Services > Status.
The Status tab in Cloud Services shows the operational health of Mobile Users, Remote Networks, and Service Connections.
Objects > Certificates.
Policies > QoS.
Monitor > Managed Devices.
Want more Prisma Access Troubleshooting practice?
Practice this domainAn enterprise is planning a Prisma Access Remote Networks deployment with overlapping RFC 1918 IP address spaces across several acquired branch offices. Which Prisma Access feature must the architect implement to successfully route traffic without changing the local branch IP schemes?
Destination NAT rules on the Service Connections
GRE tunneling with static default routes
Source NAT (SNAT) configured for Remote Networks traffic
Source NAT allows Prisma Access to translate overlapping local branch IPs to non-overlapping allocated IP pools.
BGP AS-Path Prepending across all branch tunnels
When planning a Prisma Access deployment for Mobile Users, which IP address allocation method is recommended and most commonly used for assigning virtual IP addresses to GlobalProtect clients?
Static IP assignment per user via Active Directory attributes
Static IP assignment via local DHCP server in each branch office
Manual entry by users upon connection
Automatic IP address allocation managed by Prisma Access
Prisma Access automatically assigns IP addresses from its managed pool to GlobalProtect clients.
During the initial deployment of Prisma Access for remote networks, an administrator needs to define the bandwidth allocation for a specific compute location. Which tool is used to manage and push this bandwidth allocation?
Panorama
Panorama provides the centralized interface to configure Prisma Access locations and bandwidth.
Prisma SD-WAN Cloud Controller
Prisma Access Plugin for AWS Console
GlobalProtect Portal standalone web GUI
An organization requires traffic from remote users to specific SaaS applications to bypass the Prisma Access cloud security processing nodes and go directly to the internet. Which feature should the administrator configure?
Explicit Proxy PAC file routing
SD-WAN Traffic Steering Policies
GlobalProtect Split Tunneling based on Access Routes and Domains
Split tunneling configuration allows specific traffic domains to bypass the GlobalProtect tunnel.
SSL Decryption Exclusion Objects
An architect is designing a Prisma Access deployment for a global enterprise that requires low-latency connectivity for remote workers across North America, Europe, and Asia. Which component should the architect deploy to ensure traffic processing occurs closest to the user's geographical location?
A dedicated hardware Panorama appliance in each branch office
Prisma SD-WAN appliances at every remote user laptop
A single centralized Prisma Access parent node in the headquarters region
Multiple Security Processing Nodes (SPNs) distributed across multiple geographic regions
Deploying SPNs across multiple cloud regions ensures users connect to the nearest compute location.
An administrator needs to configure secure connectivity between a corporate data center and Prisma Access for headquarters-bound traffic. Which type of connection object should be created in Panorama?
Prisma SD-WAN Hub Integration
GlobalProtect Gateway Connection
Remote Network Connection
Service Connection
Service Connections connect enterprise datacenters and headquarters to Prisma Access.
Want more Prisma Access Planning And Deployment practice?
Practice this domainAn administrator is troubleshooting a HIP (Host Information Profile) check failure for mobile users. Where can the administrator view the collected HIP reports and check compliance status in real-time?
Monitor > Logs > HIP Matches
The HIP Matches log displays detailed information about host information profiles reported by GlobalProtect clients.
Device > Certificate Management > HIP
Panorama > Cloud Services > Status > HIP
GlobalProtect > Gateway > Agent > HIP Objects
Where do administrators configure service connections in Prisma Access to connect the cloud security infrastructure to the organization's data center or headquarters?
Network > Interfaces > Tunnel
Policies > QoS > Service Connections
Panorama > Cloud Services > Configuration > Service Connections
This menu path is used to define service connections, including peer IP addresses, BGP settings, and bandwidth.
Device > Cloud Services > GlobalProtect
An administrator needs to ensure that mobile users connecting via Prisma Access resolve internal domain names using the corporate DNS servers rather than public resolvers. Where is this configured?
Objects > GlobalProtect > DNS Profile
Panorama > Cloud Services > Configuration > Mobile Users > Client Settings
Client settings allow administrators to push network parameters, such as internal DNS and IP addresses, to the GlobalProtect app.
Device > Setup > Services > DNS
Network > GlobalProtect > Gateway > DNS
An administrator notices that specific applications identified via App-ID are failing decryption inspection in Prisma Access because the server uses an unsupported cipher suite. Where can the administrator adjust the SSL decryption profile to resolve handshake failures?
Panorama > Cloud Services > Global Settings > Decryption
Device > Certificate Management > SSL Policy
Policies > Decryption > Settings
Objects > Decryption > SSL Decryption Profile
SSL Decryption profiles define which TLS versions, cipher suites, and handling methods are applied during traffic inspection.
An organization requires that specific SaaS applications are accessed only by corporate-managed devices that pass a specific HIP check. Which policy type should the administrator configure?
Security Policy Rule referencing the HIP Profile
Security rules allow administrators to enforce access restrictions based on whether a device matches a specific HIP Profile.
Decryption Policy applying inbound SSL decryption
QoS Policy referencing the HIP Object
Authentication Policy enforcing GlobalProtect gateway authentication
An administrator needs to configure remote networks in Prisma Access to connect branch locations. Where is this configuration primarily managed within the Prisma Access architecture?
Prisma Access App > Traffic Steering > Remote Networks
Panorama > Cloud Services > Configuration > Remote Networks
This is the correct navigation path in Panorama to configure remote network locations, bandwidth allocations, and IPsec tunnels.
Policies > Security > Remote Networks
Device > Setup > Operations > Remote Networks
Want more Prisma Access Administration And Operation practice?
Practice this domainThe SSE-Engineer exam has 200 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Prisma Access Services, Prisma Access Troubleshooting, Prisma Access Planning And Deployment, Prisma Access Administration And Operation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks SSE-Engineer exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.