Courseiva

Certified Security Service Edge Engineer (SSE-Engineer) (SSE-Engineer) — Questions 175

203 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selectmedium

An administrator wants to ensure that mobile users comply with security posture policies before accessing corporate applications. Which TWO elements are required to enforce HIP (Host Information Profile) checking? (Choose two)

Select 2 answers
A.Enable HIP data collection on the GlobalProtect agent settings.
B.Configure static ARP entries on the GlobalProtect gateway.
C.Reference the created HIP Object or Profile within Security policy rules.
D.Deploy WildFire appliance hardware at every branch location.
E.Install a local proxy server on every mobile device.
AnswersA, C

The GlobalProtect agent must be configured to gather endpoint security posture data (patches, antivirus, disk encryption).

Why this answer

HIP enforcement requires collecting profiles via the GlobalProtect agent and enforcing them in Security rules.

2
MCQhard

An enterprise deployment of Prisma Access uses explicit proxy. Users report that authentication prompts appear repeatedly when browsing internal web applications. What is the most likely cause of this authentication looping in an explicit proxy setup?

A.The BGP hold timer is set too low on the Service Connection.
B.Missing proxy bypass entries for authentication provider login pages or incorrect cookie persistence settings in the explicit proxy profile.
C.SSL Forward Proxy decryption is disabled on the untrust zone.
D.The GlobalProtect agent version is incompatible with explicit proxy.
AnswerB

If the browser cannot persist authentication credentials or if authentication requests are endlessly proxied back to the login portal without bypass, infinite loops occur.

Why this answer

Authentication loops in explicit proxy often stem from misconfigured authentication profiles, persistent cookie settings, or incorrect proxy bypass rules for authentication endpoints.

3
MCQhard

An enterprise has deployed Prisma Access with explicit proxy and transparent proxy configurations. Users are reporting that applications using custom non-standard TCP ports are failing to connect through the Remote Network node. What feature should the engineer inspect to ensure the ports are allowed through App-ID inspection?

A.Inspect the custom application definitions and ensure Custom App-IDs are mapped to the correct non-standard ports, and that security rules permit those ports.
B.Configure a static NAT rule for the non-standard ports on the service connection.
C.Disable GlobalProtect pre-logon mode.
D.Enable SSL Forward Proxy on the destination zones.
AnswerA

By default, App-ID identifies applications regardless of port, but custom applications or strict service object definitions require explicit configuration in policies.

Why this answer

App-ID inspects traffic dynamically, but if custom ports are used, Custom App-IDs or Service objects must be correctly configured in security policies.

4
MCQeasy

A remote user reports that their GlobalProtect connection connects successfully to Prisma Access, but they cannot resolve internal fully qualified domain names (FQDNs). Where should the administrator check to ensure DNS server IP addresses are correctly pushed to the GlobalProtect client?

A.Panorama > Prisma Access > Setup > Portal > Agent > Client Settings.
B.Prisma Access > Cloud Services > Status.
C.Panorama > Managed Devices > Remote Networks.
D.Panorama > Policy > Security.
AnswerA

Client Settings within the GlobalProtect Portal configuration define the DNS servers pushed to endpoints upon connection.

Why this answer

GlobalProtect client settings, including internal DNS server addresses, are pushed via the GlobalProtect Agent configuration in Panorama.

5
Multi-Selecthard

An administrator is troubleshooting a Prisma Access deployment experiencing intermittent packet drops and high latency across remote branches. Which THREE diagnostic steps or tools should be used? (Choose three)

Select 3 answers
A.Modify the administrative administrator accounts in Panorama.
B.Check IPsec tunnel monitoring statistics and DPD settings for packet loss and tunnel flapping.
C.Check the GlobalProtect portal certificate expiration date.
D.Verify TCP MSS clamping and MTU configurations across the IPsec tunnels to prevent packet fragmentation.
E.Review QoS bandwidth allocation and utilization to ensure critical traffic is not being dropped due to congestion.
AnswersB, D, E

Tunnel monitoring and DPD statistics reveal unstable IPsec connections.

Why this answer

Troubleshooting packet drops and latency involves checking MTU/MSS settings, interface statistics, IPsec tunnel monitoring, and QoS profiles.

6
Multi-Selectmedium

Which TWO of the following are prerequisites for setting up Cloud Identity Engine (CIE) with Prisma Access?

Select 2 answers
A.Active Directory Domain Controller installation on Prisma Access.
B.Configuring DNS on the local workstation.
C.An identity provider (IdP) integration, such as Azure AD or Okta.
D.Deploying a hardware firewall at every branch.
E.Enabling the Cloud Identity Engine service in the Prisma Access tenant.
AnswersC, E

This is the core identity source for CIE.

Why this answer

CIE requires an identity source integration and the enablement of the CIE service on the tenant.

7
MCQeasy

Which administrative role or tool is primarily used to monitor the status, health, and aggregate traffic statistics of a Prisma Access deployment across all regions?

A.Prisma Cloud Compute Console
B.Prisma Access Insights
C.WildFire portal
D.Cortex XDR incident management console
AnswerB

Prisma Access Insights provides visibility into service health, bandwidth usage, and deployment status.

Why this answer

Prisma Access Insights is the cloud-managed dashboard used to monitor health, status, and analytics of the Prisma Access deployment.

8
MCQmedium

An enterprise requires mobile users connecting via Prisma Access to authenticate using an external SAML 2.0 Identity Provider (IdP) such as Okta or Azure AD. Where is this authentication profile referenced in Panorama for mobile users?

A.In the Panorama Log Forwarding profile
B.In the Prisma Access Remote Network BGP peer settings
C.In the Service Connection QoS profile
D.In the GlobalProtect Portal configuration under Authentication
AnswerD

GlobalProtect Portal handles user authentication via SAML authentication profiles.

Why this answer

SAML authentication for mobile users is configured and referenced within the GlobalProtect Portal external authentication settings.

9
Multi-Selectmedium

Which TWO actions should an administrator take when troubleshooting high CPU utilization on Prisma Access cloud infrastructure nodes? (Choose two)

Select 2 answers
A.Check ACC and Traffic/Threat logs to identify traffic spikes, unusual session volumes, or potential security attacks.
B.Modify the GlobalProtect client portal authentication profile.
C.Generate and analyze a Tech Support File (TSF) specifically for Prisma Access via Panorama to review system resource allocation and daemon status.
D.Update the Antivirus dynamic signature version.
E.Restart the customer CPE device at the branch location.
AnswersA, C

Sudden traffic surges or attack traffic heavily utilize CPU resources for inspection and session handling.

Why this answer

High CPU troubleshooting involves analyzing threat/traffic log volumes, checking for traffic storms or DoS attacks, and reviewing system diagnostic files.

10
Multi-Selecthard

An enterprise is implementing Prisma Access and wants to ensure strict security governance. Which THREE capabilities are provided natively by Prisma Access security processing nodes (SPNs)? (Choose three)

Select 3 answers
A.URL Filtering with real-time category lookups
B.WildFire cloud-based malware analysis
C.Local enterprise data center physical power failover management
D.Threat Prevention (IPS, Anti-Spyware, and Antivirus)
E.Physical rack-and-stack server hardware maintenance by the customer
AnswersA, B, D

URL Filtering inspects web traffic across all mobile users and remote networks.

Why this answer

Prisma Access provides comprehensive cloud-delivered security services including Threat Prevention, URL Filtering, and WildFire malware analysis natively on SPNs.

11
MCQhard

An administrator notices that certain mobile users connecting via Prisma Access are experiencing intermittent authentication timeouts when authenticating via SAML 2.0. Where should the administrator check to verify the Identity Provider (IdP) connectivity status and SAML assertion errors within Panorama?

A.Monitor -> Traffic -> Session End
B.Objects -> Authentication -> SAML Test
C.Monitor -> Logs -> Authentication
D.Panorama -> Cloud Services -> Health -> Infrastructure
AnswerC

The Authentication log in Panorama provides detailed records of user login attempts, SAML response parsing, and IdP communication status.

Why this answer

Prisma Access status and operational logs related to user authentication and SAML can be monitored via Panorama operational commands and SaaS / User-ID status dashboards.

12
MCQeasy

An administrator is investigating a security alert in Prisma Access triggered by an Anti-Spyware profile. Which log contains the detailed packet capture (pcap) or attack details for this specific event?

A.Monitor > Logs > HIP Match.
B.Monitor > Logs > Threat.
C.Panorama > Cloud Services > Audit Log.
D.Monitor > Logs > URL Filtering.
AnswerB

Threat logs capture vulnerability, anti-spyware, and antivirus events with detailed attack information.

Why this answer

Threat logs contain detailed information on anti-spyware, antivirus, and vulnerability alerts, often including packet captures.

13
MCQmedium

An administrator needs to verify whether a Prisma Access Remote Network is successfully exchanging routes with the customer CPE router over BGP. Where can the real-time BGP peer state be checked?

A.Review the System log for BGP daemon errors.
B.Examine the Traffic log for BGP port 179 sessions.
C.Check the GlobalProtect gateway log.
D.Run operational CLI commands such as 'show routing protocol bgp peer' or check the routing status in the Prisma Access monitoring dashboard.
AnswerD

BGP operational commands show whether the peer state is Established, Active, or Idle, along with received and advertised routes.

Why this answer

BGP peer state and routing tables can be checked via operational CLI commands on Prisma Access nodes or monitoring dashboards.

14
Multi-Selecthard

An architect is designing a high-availability Remote Network location for Prisma Access. Which TWO methods can be used to ensure redundancy for branch office traffic connecting to Prisma Access? (Choose two)

Select 2 answers
A.Deploy dual branch routers establishing independent IPSec tunnels to Prisma Access
B.Enable VRRP directly across the Prisma Access cloud gateway public IP addresses
C.Configure redundant IPSec tunnels terminating on separate Prisma Access SPNs with BGP path selection
D.Configure Spanning Tree Protocol (STP) across the IPSec tunnel interfaces
E.Use L2TPv3 link aggregation across the cloud service edge
AnswersA, C

Dual branch routers provide hardware-level redundancy at the branch site.

Why this answer

Branch office redundancy in Prisma Access can be achieved by deploying redundant IPSec tunnels from the branch router to Prisma Access and utilizing BGP path selection, or by deploying redundant branch hardware devices.

15
MCQmedium

A Prisma Access engineer is troubleshooting an issue where users in a specific Remote Network location cannot authenticate against an on-premises LDAP server because the Service Connection is dropping packets. What is the recommended Panorama CLI command to test connectivity to the LDAP server through the Service Connection?

A.Execute 'ping source <dataplane-interface> host <ldap-server-ip>' from the specific Prisma Access node or use operational commands via Panorama.
B.Run 'show system resources' to check CPU utilization of the Panorama VM.
C.SSH to the Prisma Access node or use the Panorama CLI to run 'test security-policy-match' for the LDAP traffic.
D.Use the CLI command 'ping source <service-connection-ip> <ldap-server-ip>' from the Panorama management plane.
AnswerA

Sourcing pings from the specific data plane interface ensures traffic correctly traverses the Service Connection tunnel.

Why this answer

The test command 'test aaa-server login' or ping utilities executed from the appropriate Prisma Access node CLI help diagnose connectivity and authentication issues.

16
MCQmedium

A security team reports that threat prevention signatures are not updating on Prisma Access nodes. Where in Panorama should the administrator verify the scheduling and status of dynamic updates for Prisma Access?

A.Panorama > Cloud Services > Setup > Dynamic Updates.
B.Prisma Access > Service Setup > Threat Prevention.
C.Panorama > Device Deployment > Dynamic Updates.
D.Monitor > Dynamic Updates > Status.
AnswerC

Panorama manages antivirus, WildFire, and threat signatures and pushes them to Prisma Access nodes based on scheduled configurations.

Why this answer

Dynamic updates for Prisma Access are managed via Panorama under Panorama > Device Deployment > Dynamic Updates or Cloud Services dynamic update schedules.

17
MCQhard

You are troubleshooting a Mobile User connectivity issue where users cannot access internal resources. The Cloud Identity Engine (CIE) shows the user as authenticated, but the Security Policy log shows the traffic is dropped with 'policy-deny'. What is the most likely cause?

A.The Security Policy rule source zone or user-group mapping does not match the incoming traffic flow.
B.The GlobalProtect portal is down.
C.The CIE directory sync is failing.
D.The Prisma Access license has expired.
AnswerA

This is a common cause for 'policy-deny' when identity is confirmed but access is blocked.

Why this answer

When the user is authenticated but traffic is dropped by policy, it usually indicates that the source user or group mapping is not being correctly identified in the Security Policy, or the specific traffic rule is missing.

18
MCQeasy

An administrator needs to configure remote networks in Prisma Access to connect branch locations. Where is this configuration primarily managed within the Prisma Access architecture?

A.Prisma Access App > Traffic Steering > Remote Networks
B.Panorama > Cloud Services > Configuration > Remote Networks
C.Policies > Security > Remote Networks
D.Device > Setup > Operations > Remote Networks
AnswerB

This is the correct navigation path in Panorama to configure remote network locations, bandwidth allocations, and IPsec tunnels.

Why this answer

Prisma Access remote networks and mobile user configurations are managed centrally through Panorama using the Cloud Services plugin.

19
MCQeasy

An administrator wants to check the status of active IPsec tunnels for a Prisma Access Remote Network location. Which Panorama menu path provides the most direct overview of IPsec tunnel health?

A.Policies > Security.
B.Device > High Availability.
C.Monitor > Traffic.
D.Panorama > Cloud Services > Status > Remote Networks.
AnswerD

The Remote Networks status tab displays tunnel status, peer IP addresses, and operational metrics.

Why this answer

Panorama > Cloud Services > Status provides overview metrics for IPsec tunnels associated with Remote Networks.

20
MCQmedium

An organization requires that specific SaaS applications are accessed only by corporate-managed devices that pass a specific HIP check. Which policy type should the administrator configure?

A.Security Policy Rule referencing the HIP Profile
B.Decryption Policy applying inbound SSL decryption
C.QoS Policy referencing the HIP Object
D.Authentication Policy enforcing GlobalProtect gateway authentication
AnswerA

Security rules allow administrators to enforce access restrictions based on whether a device matches a specific HIP Profile.

Why this answer

HIP checks are enforced within Security Policy rules by referencing the desired HIP Object or HIP Profile in the rule's criteria.

21
Multi-Selecthard

An enterprise network team is troubleshooting a Prisma Access Remote Network deployment where DNS queries from branch offices are failing to resolve internal resources. Which THREE components should be inspected? (Choose three)

Select 3 answers
A.Check the Service Connection routing configuration to ensure DNS traffic destined for internal DNS servers is correctly routed across the Service Connection tunnel.
B.Examine Security Policy rules to ensure that DNS traffic (Port 53 TCP/UDP) is permitted between the branch zone and the Service Connection / internal zones.
C.Verify the GlobalProtect client portal certificate.
D.Check the WildFire threat prevention subscription license key.
E.Verify that the primary and secondary DNS server IP addresses are correctly configured in the Remote Network settings in Panorama.
AnswersA, B, E

If internal DNS queries are not routed over the Service Connection, queries fail to reach the corporate DNS servers.

Why this answer

Troubleshooting branch office DNS resolution involves checking DNS server IP configuration in remote network settings, Service Connection routing for DNS traffic, and security rules allowing DNS.

22
MCQmedium

An administrator needs to ensure that mobile users connecting via Prisma Access resolve internal domain names using the corporate DNS servers rather than public resolvers. Where is this configured?

A.Objects > GlobalProtect > DNS Profile
B.Panorama > Cloud Services > Configuration > Mobile Users > Client Settings
C.Device > Setup > Services > DNS
D.Network > GlobalProtect > Gateway > DNS
AnswerB

Client settings allow administrators to push network parameters, such as internal DNS and IP addresses, to the GlobalProtect app.

Why this answer

GlobalProtect client settings, including primary and secondary DNS servers assigned to mobile users, are configured within the GlobalProtect Client Settings in Panorama.

23
Multi-Selectmedium

Which TWO tools or logs in Panorama should an administrator use when troubleshooting a security policy rule that is unexpectedly dropping legitimate user traffic in Prisma Access? (Choose two)

Select 2 answers
A.Monitor > Logs > Traffic to identify sessions marked with a 'deny' action and note the matching rule name.
B.Device > High Availability status.
C.The CLI command 'test security-policy-match' to simulate traffic and verify rule evaluation.
D.Monitor > Dynamic Updates > Status.
E.Panorama > Cloud Services > Audit Log.
AnswersA, C

Traffic logs record dropped sessions, showing the exact rule ID that blocked the connection.

Why this answer

Debugging dropped traffic involves examining Traffic logs for session deny actions and using the test security-policy-match command to evaluate rule logic.

24
MCQmedium

An administrator is configuring Remote Networks in Prisma Access for a branch office using Internet Key Exchange Version 2 (IKEv2). During the configuration in Panorama, which component must be deployed on the branch office router to ensure proper IPsec tunnel establishment with the Prisma Access Service Connections and Remote Networks nodes?

A.The GlobalProtect app configured in manual gateway connection mode.
B.An active Prisma Access Insights API token for dynamic routing updates.
C.The Cloud Identity Engine agent installed locally on the branch router's operating system.
D.A valid public IP address and a pre-shared key matching the IKE gateway configuration defined in Panorama.
AnswerD

Prisma Access requires the branch router to have a static public IP and matching authentication credentials (such as a pre-shared key) to authenticate the IKEv2 gateway.

Why this answer

To establish a secure IPsec tunnel between a branch office and Prisma Access, the branch office router must be configured with a public IP address, support IKEv2, and use a pre-shared key or certificate matching the Panorama Remote Networks configuration.

25
MCQeasy

An administrator wants to verify that threat prevention signatures are actively blocking simulated malicious traffic in a Prisma Access environment. Which testing tool or procedure is standard for verifying threat signatures safely?

A.Perform a Denial of Service attack against the Prisma Access public IP.
B.Disable SSL decryption across all security rules.
C.Restart the Panorama management server.
D.Use standardized test payloads or URLs (such as the EICAR string for antivirus or PANW test URLs) and check the Threat log.
AnswerD

EICAR and PANW test URLs trigger signature alerts safely without causing real damage, which can then be verified in Threat logs.

Why this answer

The standard testing method for Palo Alto Networks threat signatures is using standardized test files (e.g., EICAR for antivirus) or benign test URLs (e.g., panacea.threat.com).

26
MCQeasy

Which Prisma Access feature enables enterprises to inspect and secure traffic between different virtual networks or cloud environments connected to the cloud service?

A.CASB API scanning
B.Prisma Access Insights
C.GlobalProtect Portal
D.Firewall as a Service (FWaaS)
AnswerD

FWaaS provides cloud-delivered network security and stateful inspection for all traffic flows across Prisma Access.

Why this answer

Firewall as a Service (FWaaS) provides comprehensive Layer 7 inspection for all traffic traversing Prisma Access.

27
MCQmedium

A remote network user in a Prisma Access deployment is experiencing intermittent packet loss and slow application performance over the IPsec tunnel to the Remote Network (RN) node. Upon checking the system logs, the network engineer notices repetitive IKE rekey negotiations. Which troubleshooting step should be taken first to identify the root cause?

A.Disable SSL decryption on the Security Predefined Policy.
B.Change the mobile user portal authentication profile.
C.Verify that Dead Peer Detection (DPD) intervals match between the CPE device and Prisma Access node, and check tunnel monitoring statistics.
D.Restart the GlobalProtect service on the remote user's endpoint.
AnswerC

Mismatched DPD timers can cause premature tearing down of IPsec SAs, leading to intermittent packet loss and rekey storms.

Why this answer

Checking the IPsec and IKE tunnel status via the Prisma Access CLI or Panorama status monitor helps identify cryptographic mismatch or dead peer detection (DPD) timeouts causing flapping.

28
MCQeasy

An organization is migrating their branch offices to Prisma Access Firewall as a Service (FWaaS). What is the primary method used to connect a physical branch office location to the Prisma Access cloud infrastructure securely?

A.Direct peering via AWS Direct Connect without any encapsulation
B.GlobalProtect client software installed on every desktop in the branch
C.IPsec VPN tunnels from the branch office router or firewall to Prisma Access Remote Networks
D.Explicit HTTP proxy configuration pushed via browser group policy
AnswerC

Branch offices use standard IPsec VPN connections terminating at the nearest Prisma Access Remote Networks node to secure traffic to and from the cloud.

Why this answer

Remote Networks (RN) in Prisma Access connect physical branch offices and headquarters to the cloud service using standard IPsec VPN tunnels terminated on Prisma Access service nodes.

29
MCQeasy

When configuring Prisma Access via Panorama, which administrative role or permission is required to push configuration changes to the cloud infrastructure?

A.Panorama Administrator role with Cloud Services plugin permissions
B.Network Administrator without Cloud Services access
C.Prisma Cloud Administrator
D.GlobalProtect Read-Only Operator
AnswerA

Managing Prisma Access requires specific administrator privileges covering Panorama Cloud Services plugins and configuration push capabilities.

Why this answer

Administrators require appropriate Panorama roles with permissions to commit and push changes to Cloud Services templates and device groups.

30
MCQmedium

An administrator wants to inspect outbound web traffic from mobile users for malware and spyware using Prisma Access. Which security profile type must be attached to the Security policy rule?

A.Antivirus and Anti-Spyware profiles
B.Decryption profile and URL filtering profile only
C.QoS Profile and Zone Protection profile
D.HIP Profile and WildFire analysis profile
AnswerA

Antivirus profiles protect against file-based malware, and anti-spyware profiles protect against malicious callbacks.

Why this answer

Antivirus and Anti-Spyware profiles inspect traffic passing through security rules for known malware and command-and-control signatures.

31
MCQhard

An administrator notices that a subset of mobile users connecting via GlobalProtect in Prisma Access cannot resolve internal corporate hostnames, while external websites load normally. The split-tunnel configuration includes the corporate domain. Where should the administrator check first in Panorama to troubleshoot this DNS resolution failure?

A.Panorama > Prisma Access > Service Setup > Mobile Users > GlobalProtect Client Settings > Client Config > DNS and-or WINS.
B.Panorama > Prisma Access > Monitoring > ACC.
C.Panorama > Cloud Services > Status > Traffic Log.
D.Panorama > Firewall > Network Profiles > Interface.
AnswerA

The DNS server IPs and primary/secondary suffixes assigned to GlobalProtect clients are configured and pushed via the Client Settings in Panorama.

Why this answer

In Prisma Access, DNS server assignments for mobile users are pushed via the GlobalProtect Agent configuration under Network > GlobalProtect > Client Settings.

32
MCQeasy

When planning a Prisma Access deployment for Mobile Users, which IP address allocation method is recommended and most commonly used for assigning virtual IP addresses to GlobalProtect clients?

A.Static IP assignment per user via Active Directory attributes
B.Static IP assignment via local DHCP server in each branch office
C.Manual entry by users upon connection
D.Automatic IP address allocation managed by Prisma Access
AnswerD

Prisma Access automatically assigns IP addresses from its managed pool to GlobalProtect clients.

Why this answer

Prisma Access automatically manages and allocates dynamic IP pools for mobile users via Panorama.

33
MCQmedium

An administrator configuring Prisma Access ZTNA wants to view real-time metrics regarding active mobile user connections, bandwidth consumption per region, and tunnel status. Which tool provides this specific operational dashboard?

A.Prisma Access Insights
B.Panorama Traffic Logs
C.Command Line Interface (CLI) via SSH to Prisma Access nodes
D.Prisma Cloud Compute console
AnswerA

Prisma Access Insights offers visibility into active users, bandwidth usage, service uptime, and tenant metrics.

Why this answer

Prisma Access Insights provides operational dashboards for bandwidth, active users, and tenant health.

34
Multi-Selecthard

Which THREE factors influence the selection of a Compute Location in a Prisma Access deployment?

Select 3 answers
A.The number of users in the local branch.
B.Local ISP latency and bandwidth.
C.Geographic proximity to the mobile user.
D.Available capacity in the compute location.
E.The color of the hardware appliance.
AnswersB, C, D

Network performance is a key factor.

Why this answer

Compute locations are chosen based on proximity to users, licensing availability, and the specific traffic type.

35
MCQeasy

An administrator wants to view real-time metrics, node status, and active connection counts for Prisma Access Mobile Users and Remote Networks directly from Panorama. Which tool within Panorama should the administrator access?

A.GlobalProtect Portal Diagnostics Tool
B.Command Center CLI
C.Prisma Access Insights
D.Cloud Identity Engine Console
AnswerC

Prisma Access Insights is the native dashboard and monitoring tool built into Panorama for operational visibility.

Why this answer

Prisma Access Insights provides a centralized dashboard in Panorama for monitoring service health, bandwidth utilization, and active connections.

36
Multi-Selecthard

An administrator is designing a Prisma Access Secure Web Gateway (SWG) and CASB architecture. Which THREE capabilities can be enforced natively through Prisma Access SWG and inline CASB policies? (Choose three)

Select 3 answers
A.Granular action control such as allowing read-only access while blocking file uploads to sanctioned or unsanctioned SaaS tenants
B.Direct peer-to-peer BGP routing exchanges with external public web servers
C.URL filtering based on threat risk categories and web categories
D.Local BIOS firmware flashing and motherboard diagnostics for remote client laptops
E.Data Filtering to detect and block the exfiltration of sensitive data such as credit card numbers or PII
AnswersA, C, E

Inline CASB capabilities in Prisma Access allow precise activity control over SaaS applications (upload, download, share).

Why this answer

Prisma Access SWG and inline CASB allow administrators to control specific application actions (e.g., block uploads), inspect traffic using URL filtering categories, and enforce data loss prevention via Data Filtering profiles.

37
Multi-Selecthard

An administrator is troubleshooting connectivity issues for a remote network connected to Prisma Access via IPsec VPN. Which TWO checks should be performed to verify tunnel health and status? (Choose two)

Select 2 answers
A.Inspect the GlobalProtect client runtime logs on the mobile user's laptop.
B.Check the IPsec tunnel status under Panorama > Cloud Services > Status > Remote Networks.
C.Check the DNS resolver settings in the local device setup tab.
D.Run a physical cable test from the Prisma Access cloud node to the carrier router.
E.Verify IKE and IPsec cryptographic and phase settings match on both the Prisma Access side and the customer edge router.
AnswersB, E

This status view displays real-time IPsec tunnel establishment and connection health for remote networks.

Why this answer

IPsec tunnel status can be validated via cloud status monitors and standard tunnel monitoring logs.

38
MCQeasy

Which Prisma Access service capability provides secure, least-privilege remote access for third-party contractors who cannot install the GlobalProtect agent on their managed or unmanaged devices?

A.Prisma Access Remote Network IPsec
B.Prisma Access Browser
C.Explicit Proxy Forwarding
D.GlobalProtect Client-less VPN
AnswerD

Client-less VPN allows users to securely access internal web applications directly from a standard web browser.

Why this answer

GlobalProtect Client-less VPN provides browser-based access to internal web applications without requiring an endpoint client.

39
MCQmedium

While troubleshooting a Prisma Access Remote Network deployment, an engineer notices that routes advertised via BGP from the customer's data center are not appearing in the Prisma Access routing table. Where can the engineer view BGP peer status and learned routes in Panorama?

A.Panorama > Cloud Services > Status > BGP Peers.
B.Monitor > Dynamic Updates > BGP.
C.Policies > NAT.
D.Prisma Access > Service Setup > Routing > BGP Status, or by viewing runtime stats via the Prisma Access monitoring dashboard in Panorama.
AnswerD

Runtime stats and monitoring dashboards in Panorama display active BGP peering states and routing tables.

Why this answer

BGP routing status can be monitored via Runtime Stats in the Prisma Access monitoring tools or CLI.

40
MCQmedium

An administrator needs to verify whether Host Information Profile (HIP) checks are failing for a specific mobile user attempting to connect to Prisma Access. Which log should the administrator review in Panorama?

A.Monitor > Logs > Threat.
B.Monitor > Logs > System.
C.Panorama > Cloud Services > Audit Log.
D.Monitor > Logs > HIP Match.
AnswerD

HIP match logs track successful and failed Host Information Profile evaluations for GlobalProtect clients.

Why this answer

HIP match logs record whether endpoints meet the defined security criteria (OS version, patch level, anti-malware status).

41
MCQeasy

An administrator wants to view historical bandwidth utilization trends for a specific Remote Network location over the past 30 days. Which Panorama monitoring workspace provides this historical reporting?

A.Device > Setup > Management.
B.Panorama > Cloud Services > Audit Log.
C.Monitor > Reports.
D.Policies > QoS.
AnswerC

Preset and custom scheduled reports in Panorama provide long-term historical analysis of bandwidth, threats, and traffic.

Why this answer

Panorama > Monitor > Reports or ACC provides historical reporting capabilities.

42
MCQmedium

An administrator has deployed Prisma Access Remote Networks, but traffic from a branch office is failing to pass through the IPsec tunnel to Prisma Access. The IKE phase 1 negotiation is failing. Which Prisma Access operational command should the administrator run via the CLI to check the IPsec tunnel status and IKE SA parameters?

A.show globalprotect-gateway current-users
B.show vpn ike-sa gateway <gateway-name>
C.show system info
D.show running resource-monitor
AnswerB

This command displays the status of the IKE Security Associations, helping identify phase 1 mismatch issues.

Why this answer

To troubleshoot IPsec VPN tunnels and IKE negotiations on Prisma Access remote networks or service connections, administrators use the CLI command 'show vpn ike-sa' or 'show vpn flow'.

43
Multi-Selectmedium

An administrator is configuring Source NAT (SNAT) for Prisma Access Remote Networks. Which TWO reasons explain why SNAT is necessary in certain network designs? (Choose two)

Select 2 answers
A.To authenticate GlobalProtect users against Active Directory
B.To resolve overlapping IP address spaces between multiple branch offices
C.To replace the requirement for BGP routing over Service Connections
D.To present a consistent source IP address when branch traffic exits to external SaaS applications
E.To assign dynamic IPv6 addresses to individual remote worker laptops
AnswersB, D

SNAT translates overlapping private subnets to unique allocated IP pools.

Why this answer

SNAT is used to prevent IP address overlapping between branch sites and to hide internal network structures when accessing external destinations.

44
MCQhard

You are deploying Prisma Access and need to ensure that traffic from mobile users accessing the internet is inspected by a specific set of security profiles. Where should these profiles be applied?

A.In the GlobalProtect Gateway settings.
B.In the Service Connection configuration.
C.In the Cloud Identity Engine configuration.
D.In the Panorama Security Policy rule matching the traffic.
AnswerD

Security Policies are where you link Security Profiles to traffic.

Why this answer

Security Profiles must be attached to the Security Policy rules that govern the specific traffic flow.

45
MCQmedium

An organization is migrating its identity provider integration to the Cloud Identity Engine (CIE) to support Prisma Access authentication and User-ID. When configuring the connection between CIE and the enterprise Active Directory, which component is required on-premises to sync directory objects securely without opening inbound firewall ports?

A.Prisma Access User-ID Syslog Listener
B.GlobalProtect Gateway Proxy
C.Cloud Identity Engine Agent
D.Panorama Log Collector
AnswerC

The CIE Agent initiates an outbound connection to the cloud service, allowing secure directory synchronization without inbound firewall rules.

Why this answer

The Cloud Identity Engine Agent runs on-premises and establishes an outbound secure connection to CIE, synchronizing directory data without requiring inbound firewall changes.

46
MCQhard

A security engineer needs to configure a Security policy rule in Prisma Access that targets users belonging to a specific Active Directory group synced via the Cloud Identity Engine. How should the source user be specified in the Security rule?

A.In the Source Device field, select the Cloud Identity Engine connector object.
B.In the IP/Netmask field, enter the subnet assigned by the CIE connector.
C.In the Destination field, specify the LDAP server IP address.
D.In the Source User field, add the fully qualified group name provided by CIE.
AnswerD

Security rules evaluate user and group identity directly when placed in the Source User/Group field of the rule.

Why this answer

When using CIE or User-ID, security rules reference group objects directly using the format domain\group or the discovered group name.

47
MCQmedium

An organization requires that Prisma Access Secure Web Gateway inspects all inbound and outbound TLS traffic for employees browsing external websites. However, HR and healthcare applications must be bypassed due to privacy regulations. Where in Panorama must the administrator configure the exception for these categories?

A.Policies -> Decryption
B.Panorama -> Cloud Services -> User Access
C.Network Services -> Prisma Access -> Decryption Bypass
D.Objects -> Custom URL Category
AnswerA

Decryption policies contain rules that define which traffic to decrypt, block, or no-decrypt based on URL categories.

Why this answer

Decryption policy rules in Panorama allow administrators to bypass decryption based on URL categories such as healthcare and financial services.

48
Multi-Selectmedium

An administrator is configuring authentication for Prisma Access mobile users. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)

Select 2 answers
A.Local plaintext password files stored on user endpoint hard drives
B.RADIUS and LDAP authentication servers
C.Peer-to-peer certificate exchange without an authentication authority
D.Hardcoded pre-shared keys without user credentials
E.SAML 2.0 Identity Provider integration (e.g., Okta, Microsoft Entra ID, Ping Identity)
AnswersB, E

RADIUS and LDAP profiles allow direct integration with directory services and MFA radius servers.

Why this answer

Prisma Access supports SAML 2.0 and RADIUS/LDAP authentication methods for mobile users.

49
Multi-Selecthard

An enterprise is deploying Prisma Access Service Connections to connect corporate data centers to the cloud security platform. Which THREE configuration parameters must be correctly specified on Panorama for a Service Connection? (Choose three)

Select 3 answers
A.GlobalProtect client software download URLs for mobile endpoints.
B.BGP peer AS number and peering IP addresses for dynamic route exchange.
C.WMI probing schedules for Active Directory domain discovery.
D.IPsec Crypto Profile and IKE Crypto Profile settings.
E.Peer IP address of the enterprise data center VPN gateway.
AnswersB, D, E

BGP configuration is necessary to exchange routing prefixes between the data center and Prisma Access.

Why this answer

Service Connections require defining the remote peer IP address, IPsec crypto settings, and BGP peering parameters for routing.

50
MCQmedium

A network engineer is troubleshooting user identification issues in Prisma Access where security policies relying on user groups are not matching traffic. Which troubleshooting command or Panorama feature should be used to verify if User-ID mappings are correctly populated for mobile users?

A.Use the CLI operational command 'show user ip-user-mapping all' or check User-ID status in the Prisma Access monitoring dashboard.
B.Check the GlobalProtect Gateway tunnel status.
C.Run 'show system software status'.
D.Verify the SSL Decryption certificate expiration date.
AnswerA

Viewing active IP-to-user mappings confirms whether User-ID agents or GlobalProtect has successfully resolved the user identity.

Why this answer

Panorama operational commands or the User-ID status monitoring tool show active user-to-IP mappings.

51
Multi-Selectmedium

Which TWO actions should an administrator take to troubleshoot an authentication failure when mobile users attempt to log into Prisma Access using SAML? (Choose two)

Select 2 answers
A.Modify the NAT policy rules.
B.Check the URL Filtering category for the IdP login domain.
C.Restart the physical firewall in the branch office.
D.Verify that the SAML Identity Provider (IdP) signing certificate imported into Panorama matches the active IdP certificate.
E.Check for clock skew between the SAML IdP and Prisma Access service nodes.
AnswersD, E

Mismatched or expired IdP certificates cause signature validation failures.

Why this answer

Troubleshooting SAML authentication involves verifying clock skew, IdP metadata/certificates, and authentication profile configuration.

52
MCQhard

A Prisma Access deployment has multiple Remote Networks and Mobile Users. An administrator implements Quality of Service (QoS) to prioritize VoIP traffic over bulk file transfers. After applying the QoS profile, VoIP performance does not improve. What should the administrator verify first in the Prisma Access QoS configuration?

A.Verify the BGP AS number on the customer CPE.
B.Check the expiration date of the GlobalProtect gateway SSL certificate.
C.Verify that the QoS profile is applied to the correct security policy rules and that the guaranteed bandwidth settings align with the provisioned Prisma Access node bandwidth limits.
D.Ensure that GlobalProtect pre-logon mode is disabled.
AnswerC

If QoS classes are not referenced in security rules or if bandwidth allocations exceed provisioned node limits, QoS prioritization will not take effect.

Why this answer

Prisma Access QoS relies on correct classification of traffic via security policies and proper bandwidth allocation profiles matching the provisioned bandwidth of the egress node.

53
MCQhard

An administrator is troubleshooting a Prisma Access deployment where mobile users are intermittently disconnected when moving between trusted Wi-Fi networks and cellular connections. Which GlobalProtect client setting in Prisma Access helps maintain session persistence and fast reconnection during network roaming?

A.Explicit Proxy PAC file fallback mode
B.GlobalProtect App configuration with seamless tunnel reconnection and 'Always On' mode
C.BGP route dampening on the Service Connection
D.IPsec Dead Peer Detection (DPD) timer set to zero
AnswerB

Seamless tunnel reconnection allows the GlobalProtect client to re-establish secure sessions automatically when network interfaces change.

Why this answer

GlobalProtect app settings such as 'Connect Method' set to 'Always On' or 'Pre-Logon' along with seamless tunnel reconnection settings ensure persistent connections.

54
Multi-Selecthard

An administrator is investigating intermittent authentication failures for remote users connecting via GlobalProtect to Prisma Access using SAML. Which THREE log sources or troubleshooting commands can assist in identifying the root cause? (Choose three)

Select 3 answers
A.authd.log on Panorama/Prisma Access
B.Data-plane packet capture (pcap) of HTTP/2 server streams
C.GlobalProtect app debug logs on the client endpoint
D.globalProtectPortal.log
E.Panorama ACC threat widget counters
AnswersA, C, D

The authd log contains details regarding SAML authentication requests, assertions, and IdP communication errors.

Why this answer

SAML authentication troubleshooting in Prisma Access requires inspecting authentication daemon logs, GlobalProtect portal logs for connection handshakes, and client-side debug logs.

55
MCQmedium

Which object type should be used to restrict access to a specific internal application for Remote Network users while ensuring the policy is scalable?

A.URL filtering category.
B.Address objects or Address Groups.
C.Service objects based on port numbers only.
D.Interface-based rules.
AnswerB

Objects allow for scalable and manageable policy definitions.

Why this answer

Address objects or Address Groups allow for efficient grouping and reuse in security policies.

56
MCQhard

When troubleshooting a Prisma Access deployment using SAML authentication, an administrator notices that users are successfully authenticated by the IdP, but the GlobalProtect client displays an error stating 'Invalid SAML Response: Signature Validation Failed'. What is the most likely root cause?

A.The decryption policy is blocking HTTPS traffic to the IdP.
B.The IdP signing certificate imported into the Prisma Access authentication profile does not match the active certificate currently used by the IdP.
C.The User-ID agent service on Panorama has crashed.
D.The GlobalProtect client version is outdated and does not support SAML.
AnswerB

If the IdP rolled over its signing certificate without updating the certificate in Panorama, Prisma Access cannot validate the SAML response signature.

Why this answer

Signature validation failure indicates a mismatch or expiration of the IdP signing certificate configured in the Prisma Access SAML Identity Provider profile.

57
MCQhard

An organization notices that certain cloud-based SaaS applications are experiencing performance bottlenecks when accessed through Prisma Access mobile users. The administrator wants to configure explicit SaaS application traffic steering or bypass. Where is this configured in Panorama for Prisma Access?

A.Panorama > Cloud Services > Prisma Access > Mobile Users > Traffic Steering / QoS or GlobalProtect Client Settings.
B.Device > Setup > Content ID.
C.Policies > Decryption.
D.Objects > Custom Objects > URL Filtering.
AnswerA

Traffic steering rules and explicit proxy bypasses for SaaS applications are configured within the Mobile Users configuration workflows in Prisma Access.

Why this answer

SaaS Security and traffic steering / explicit proxy / Prisma Access application steering configurations are managed under Cloud Services or GlobalProtect client settings.

58
Multi-Selectmedium

An administrator is reviewing the status of Remote Networks in Prisma Access and notices that an IPsec tunnel has failed to establish. Which THREE diagnostic steps or verifications should the administrator perform in Panorama or Prisma Access Insights? (Choose three)

Select 3 answers
A.Modify the GlobalProtect client configuration to force internal DNS resolution.
B.Reboot the Cloud Identity Engine container to clear stale routing cache entries.
C.Verify that the peer public IP address configured in Panorama matches the public IP of the branch office router.
D.Check that IKE Phase 1 and Phase 2 cryptographic proposals (encryption, authentication, DH group) match on both the Prisma Access side and the branch router.
E.Review Prisma Access Insights to check tunnel status, error logs, and event details.
AnswersC, D, E

An incorrect peer IP address will prevent the IKE security association from initiating successfully.

Why this answer

Troubleshooting IPsec tunnels in Prisma Access involves verifying pre-shared keys or certificates, checking public IP settings, confirming correct Phase 1/Phase 2 proposal settings, and examining system logs via Prisma Access Insights.

59
MCQmedium

When configuring a Remote Network (RN) connection to an on-premises data center, which parameter is required to ensure proper routing of internal traffic via the IPSec tunnel?

A.Primary and Secondary IKE gateways.
B.The User-ID agent IP address.
C.The BGP peer IP address or static routes defining the internal subnets.
D.The GlobalProtect Gateway IP.
AnswerC

Static or dynamic routing is essential for traffic to reach internal resources.

Why this answer

The BGP peer configuration or static routes within the Remote Network settings ensure the Prisma Access cloud knows which subnets to route through the tunnel.

60
Multi-Selecthard

An enterprise network administrator is troubleshooting an IPsec tunnel failure between a remote network and Prisma Access where Dead Peer Detection (DPD) keeps tearing down the tunnel. Which THREE potential causes should be investigated? (Choose three)

Select 3 answers
A.The GlobalProtect client software license is expired on Panorama.
B.Mismatched DPD interval and retry timer settings between the customer CPE and the Prisma Access node.
C.Intermediate network devices dropping UDP or ICMP keepalive packets required for DPD.
D.WildFire cloud analysis subscription has lapsed.
E.High packet loss or extreme latency on the transport path causing DPD timeouts.
AnswersB, C, E

If one peer expects DPD acknowledgments faster than the other is configured to respond, the tunnel flaps.

Why this answer

DPD teardown issues stem from mismatched timer configurations, packet drops along the path, or unresponsive peers.

61
Multi-Selectmedium

When configuring GlobalProtect mobile users in Prisma Access, which THREE settings are typically defined within the GlobalProtect Client Settings configuration? (Choose three)

Select 3 answers
A.Connect method (e.g., On-Demand, Always-On)
B.GlobalProtect Gateway preference list
C.Prisma Access Remote Network BGP ASN
D.Internal DNS server IP addresses
E.Service Connection public gateway IP address
AnswersA, B, D

The connection method is configured within the client settings.

Why this answer

GlobalProtect Client Settings define client behavior such as internal DNS servers, gateway preferences, and connection modes.

62
Multi-Selectmedium

An administrator is configuring Prisma Access Remote Networks to connect branch offices to the cloud security backbone. Which TWO configuration steps are required on Panorama to establish a functional Remote Network connection? (Choose two)

Select 2 answers
A.Upload customer SAML metadata files to the GlobalProtect Portal.
B.Configure IPsec Crypto Profiles and Tunnel settings for the Remote Network connection.
C.Configure the Remote Network general settings including region, bandwidth, and public IP address of the CPE device.
D.Configure WMI probing credentials for Active Directory domain controllers.
E.Install the GlobalProtect agent software on all CPE branch routers.
AnswersB, C

IPsec crypto and tunnel settings define the cryptographic parameters used to secure the tunnel to Prisma Access.

Why this answer

Configuring Remote Networks requires defining the remote network location with public IP/bandwidth and creating IPsec tunnel parameters to establish the secure connection.

63
MCQhard

An administrator is setting up Prisma Access and needs to ensure that mobile users connecting from managed corporate laptops can access internal resources, while unmanaged contractor laptops are restricted to web-based applications only. Which Prisma Access mechanism distinguishes between managed and unmanaged endpoints during connection?

A.SAML Identity Provider group claims
B.Active Directory Security Group membership only
C.GlobalProtect HIP (Host Information Profile) checks
D.Prisma Access Explicit Proxy PAC file routing
AnswerC

HIP checks inspect the endpoint for specific software, certificates, or registry keys to determine if it is a managed corporate device.

Why this answer

GlobalProtect HIP (Host Information Profile) checks evaluate the endpoint state upon connection to verify if it meets corporate security requirements.

64
MCQeasy

An administrator needs to verify the exact version of Prisma Access running on the cloud infrastructure. Where in Panorama is this version information displayed?

A.Policies > Security.
B.Device > Certificates.
C.Monitor > Dynamic Updates.
D.Panorama > Cloud Services > Setup > Infrastructure / Status.
AnswerD

The Cloud Services setup and status pages display the active Prisma Access plugin and software versions.

Why this answer

Panorama > Cloud Services > Status or Setup displays the Prisma Access software and plugin version.

65
Multi-Selectmedium

An administrator is configuring security policies in Prisma Access and wants to ensure comprehensive protection against unknown threats and malware. Which TWO security profile types should be applied to outbound and internet-bound rules? (Choose two)

Select 2 answers
A.Vulnerability Protection profile
B.WildFire Analysis profile
C.Decryption profile assigned directly to the threat engine
D.Zone Protection profile
E.QoS profile for traffic shaping
AnswersA, B

Vulnerability protection blocks network-based exploits targeting known software bugs and vulnerabilities.

Why this answer

WildFire and Vulnerability Protection profiles defend against zero-day exploits and known vulnerabilities.

66
Multi-Selectmedium

When configuring Security policy rules in Prisma Access, which THREE types of criteria can be used to control traffic traversing the cloud infrastructure? (Choose three)

Select 3 answers
A.Source and destination security zones
B.Local physical switch port numbers on the cloud node
C.Applications identified via App-ID
D.Hardware motherboard serial numbers of client machines
E.User and Group identities via User-ID or CIE
AnswersA, C, E

Security zones (such as remote-network, mobile-user, or trust zones) are fundamental match criteria.

Why this answer

Prisma Access security policies support standard PAN-OS match criteria including applications, users, zones, and regions.

67
Multi-Selectmedium

An administrator is configuring Prisma Access Secure Web Gateway and wants to restrict access to high-risk web categories. Which TWO options represent configurable actions within a Prisma Access URL Filtering profile? (Choose two)

Select 2 answers
A.Decrypt
B.Continue
C.Sandbox
D.Block
E.Quarantine
AnswersB, D

Continue displays a warning page allowing the user to proceed by clicking through.

Why this answer

URL Filtering profiles support multiple actions per category, including Allow, Block, Alert, Continue, and Override.

68
Multi-Selectmedium

Which TWO actions should an administrator perform when troubleshooting User-ID mapping failures for mobile users in Prisma Access? (Choose two)

Select 2 answers
A.Verify that GlobalProtect is configured to report user mappings and check authentication log status.
B.Restart the physical firewall hardware in the branch office.
C.Change the WildFire signature update schedule.
D.Modify the QoS bandwidth allocation profile.
E.Use the CLI command 'show user ip-user-mapping all' to verify if active user-to-IP mappings are populated.
AnswersA, E

GlobalProtect gateways must report user logins to build accurate User-ID tables.

Why this answer

Troubleshooting User-ID involves verifying GlobalProtect authentication mapping, User-ID agent/Panorama polling status, and IP-user mapping operational tables.

69
MCQmedium

A remote network connected via Prisma Access is experiencing packet drops due to Maximum Transmission Unit (MTU) size mismatches. Which troubleshooting technique or configuration should be verified to resolve IP packet fragmentation issues?

A.Change the mobile user authentication type from SAML to RADIUS.
B.Enable TCP MSS clamping on the IPsec tunnel settings or ensure the local CPE device correctly handles ICMP Destination Unreachable messages.
C.Configure a WildFire analysis profile to bypass large files.
D.Increase the GlobalProtect client idle timeout value to 3600 seconds.
AnswerB

Adjusting TCP Maximum Segment Size (MSS) prevents packets from exceeding the tunnel MTU, avoiding fragmentation drops.

Why this answer

Path MTU Discovery and MSS clamping configurations on the IPsec tunnel help prevent packet fragmentation issues across Prisma Access tunnels.

70
Multi-Selectmedium

Which TWO logs should an administrator check in Panorama when troubleshooting a mobile user who reports that their connection keeps dropping after a short period of time? (Choose two)

Select 2 answers
A.Monitor > Logs > Traffic to check for session timeouts, TCP resets, or security policy drops.
B.Monitor > Logs > Threat.
C.Monitor > Logs > GlobalProtect to view client connection events, gateway reconnects, and error messages.
D.Panorama > Cloud Services > Audit Log.
E.Monitor > Logs > Data Filtering.
AnswersA, C

Traffic logs show whether sessions were closed normally, reset by peer, or dropped by policy.

Why this answer

GlobalProtect connection drops are investigated using GlobalProtect connection/system logs and Traffic logs showing session timeouts or resets.

71
MCQhard

A Prisma Access mobile user experiences a scenario where specific internal domains fail to resolve when connected via GlobalProtect, while other internal domains resolve successfully. The split-DNS configuration in Panorama lists multiple domains. What is the most likely reason for this partial DNS failure?

A.The GlobalProtect portal SSL certificate is expired.
B.WildFire cloud connectivity is down.
C.BGP route reflection is misconfigured on the Service Connection.
D.Improperly formatted domain suffixes or exceeding the maximum number of supported split-DNS search domains for the client operating system.
AnswerD

Client OS DNS resolvers have strict syntax requirements and limits on search domains pushed by GlobalProtect.

Why this answer

Client operating systems handle DNS suffix search lists differently, and some OS clients have limitations on the number of suffixes or fail when wildcard domains are improperly formatted in GlobalProtect client settings.

72
MCQmedium

An administrator is troubleshooting a scenario where remote users connected via Prisma Access Mobile Users cannot access a specific newly added subnet behind a Remote Network location. Which configuration check should the administrator perform first in Panorama?

A.Restart the Cloud Identity Engine agent on the domain controller to refresh IP-to-user mappings.
B.Verify that Security Policy rules permit traffic from the Mobile Users zone to the Remote Networks zone, and that the remote subnet is included in the Remote Network configuration.
C.Reinstall the GlobalProtect agent on all remote user machines to update the gateway list.
D.Generate a new API key in Prisma Access Insights to force a routing table recalculation.
AnswerB

Inter-zone traffic must be explicitly allowed by Security Policy rules, and Remote Networks must advertise the correct subnets so Prisma Access routing knows how to forward the packets.

Why this answer

To allow communication between different Prisma Access access types (such as Mobile Users to Remote Networks), the administrator must ensure that inter-zone traffic is permitted and that routing/address spaces are properly advertised in Panorama.

73
MCQeasy

Which cloud infrastructure providers host the backend Security Processing Nodes (SPNs) used by Prisma Access?

A.Oracle Cloud Infrastructure (OCI) and IBM Cloud
B.Microsoft Azure only
C.AWS and Google Cloud Platform (GCP)
D.On-premises enterprise datacenters exclusively
AnswerC

Prisma Access leverages AWS and GCP to provide global scale and low latency.

Why this answer

Prisma Access is built on leading hyper-scaler cloud infrastructure, specifically AWS and Google Cloud Platform (GCP).

74
MCQeasy

What is the benefit of using Prisma Access for Remote Networks instead of traditional site-to-site VPNs?

A.It allows local traffic to bypass security inspection entirely.
B.It provides centralized, unified security policy management and inspection.
C.It eliminates the need for internet connectivity at the branch.
D.It removes the need for any internal firewalls.
AnswerB

The main benefit is centralizing security and inspection.

Why this answer

Prisma Access simplifies management and provides consistent security policy enforcement across all locations.

75
Multi-Selectmedium

An administrator is configuring Mobile Users in Prisma Access and needs to set up user authentication. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)

Select 2 answers
A.Local database accounts stored on the individual Prisma Access cloud nodes
B.WPA3 Enterprise 802.1X enterprise tunneling
C.IPsec Pre-Shared Key user authentication
D.LDAP directory authentication
E.SAML 2.0 identity provider integration
AnswersD, E

LDAP server profiles allow direct authentication against Active Directory or LDAP directories.

Why this answer

Prisma Access supports multiple authentication mechanisms including SAML 2.0 and LDAP/RADIUS via authentication profiles.

Page 1 of 3

Page 2

All pages