Courseiva

Certified Security Service Edge Engineer (SSE-Engineer) (SSE-Engineer) — Questions 76150

203 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQhard

An administrator implements a new Decryption policy in Prisma Access to inspect inbound traffic to a public-facing application hosted behind a Prisma Access Public IP. After deployment, users report receiving certificate warning errors. What should the administrator inspect first to resolve the warning?

A.Check whether the GlobalProtect client version on the user's laptop is up to date.
B.Ensure that WildFire analysis is disabled for inbound decrypted traffic.
C.Verify that the correct server certificate and private key are imported into Panorama and bound to the Inbound Decryption rule.
D.Verify the OCSP responder settings under Device > Setup > Sessions.
AnswerC

If the firewall does not present the correct server certificate to the client, a trust mismatch warning occurs immediately.

Why this answer

Inbound SSL decryption requires the specific server certificate and private key to be imported into Panorama and referenced in the Decryption policy.

77
Multi-Selecthard

A security architect is designing a Prisma Access FWaaS deployment and needs to ensure robust security posture across all zones (Mobile Users, Remote Networks, Service Connections, and Internet). Which THREE security profile types should be attached to Security Policy rules to ensure comprehensive threat prevention? (Choose three)

Select 3 answers
A.GlobalProtect Portal Configuration Profile
B.Vulnerability Protection Security Profile
C.Antivirus Security Profile
D.Cloud Services Dynamic Template
E.WildFire Analysis Security Profile
AnswersB, C, E

Vulnerability Protection blocks known exploit attempts and protocol anomalies.

Why this answer

Comprehensive threat prevention in PAN-OS / Prisma Access relies on Antivirus, Vulnerability Protection, and WildFire Analysis profiles.

78
MCQeasy

Which tool provides end-to-end visibility into Prisma Access performance, user experience metrics, and digital experience monitoring (DEM)?

A.WildFire Portal reporting
B.Panorama Packet Capture utility
C.Prisma Access ADEM (Autonomous Digital Experience Management)
D.GlobalProtect Syslog Analyzer
AnswerC

ADEM provides telemetry and troubleshooting data regarding endpoint, Wi-Fi, and cloud path performance for Prisma Access users.

Why this answer

Autonomous DEM (ADEM) for Prisma Access provides visibility into end-user experience, endpoint health, and path performance.

79
MCQmedium

An administrator is configuring Prisma Access Firewall as a Service (FWaaS) to protect outbound internet traffic from remote networks. They want to ensure that known command-and-control (C2) traffic and vulnerability exploits are blocked dynamically in real time. Which security profile should be applied to the security policy rules?

A.URL Filtering and Decryption profiles only
B.Data Filtering and File Blocking profiles only
C.User-ID and Device-ID mapping policies
D.Anti-Spyware and Vulnerability Protection profiles
AnswerD

Anti-Spyware profiles detect C2 traffic, and Vulnerability Protection profiles block known exploits, providing core FWaaS threat prevention.

Why this answer

Anti-Spyware and Vulnerability Protection profiles inspect traffic passing through Prisma Access FWaaS to detect and block C2 callbacks, malware downloads, and exploit attempts.

80
MCQhard

An administrator configures Decryption Policies in Prisma Access to inspect inbound traffic destined for internal applications published via Service Connections. Users report that certain internal web applications using custom internal Certificate Authorities (CAs) are failing TLS handshakes. Where should the administrator check and install the enterprise internal CA certificate to resolve this inspection issue?

A.GlobalProtect Portal > Client Settings > Authentication, and push the CA via client configuration.
B.Panorama > Certificate Management > Certificates, and ensure the internal CA is imported and trusted for SSL decryption.
C.Cloud Identity Engine > Settings > Trusted Roots, and sync the certificate via LDAP.
D.Prisma Access Insights > Policies > Decryption, and toggle the 'Bypass Internal CA' switch.
AnswerB

Importing the internal CA into Panorama and setting the trust flags allows Prisma Access nodes to validate and decrypt traffic destined for internal resources securely.

Why this answer

For Prisma Access to successfully issue forward proxy certificates or trust internal servers during SSL decryption, the internal enterprise CA certificate must be imported into the Certificate Management store in Panorama and marked as a trusted root CA.

81
MCQhard

A security architect is designing a CASB inline policy in Prisma Access. The requirement is to restrict corporate users from logging into personal instances of sanctioned SaaS applications (e.g., personal Microsoft 365 or Google Workspace) while allowing access to corporate-owned tenants. Which feature enables this control?

A.Prisma Access DNS Security sinking
B.HTTP Header Insertion / Restricted Tenant Access
C.GlobalProtect Client-less VPN rewriting rules
D.SaaS Security API inline scanning
AnswerB

Prisma Access can insert specific HTTP headers (such as Restricted-Access-Current-Tenant) into outbound requests to cloud services, forcing corporate tenants only.

Why this answer

App-ID SaaS Security controls and HTTP header insertion (specifically restricted domains/tenant restriction headers) allow Prisma Access to enforce access only to approved enterprise tenants.

82
MCQhard

An enterprise is planning a Prisma Access Remote Networks deployment with overlapping RFC 1918 IP address spaces across several acquired branch offices. Which Prisma Access feature must the architect implement to successfully route traffic without changing the local branch IP schemes?

A.Destination NAT rules on the Service Connections
B.GRE tunneling with static default routes
C.Source NAT (SNAT) configured for Remote Networks traffic
D.BGP AS-Path Prepending across all branch tunnels
AnswerC

Source NAT allows Prisma Access to translate overlapping local branch IPs to non-overlapping allocated IP pools.

Why this answer

Source NAT (SNAT) or Network Address Translation mechanisms must be used to handle overlapping IP spaces when connecting multiple remote networks to Prisma Access.

83
MCQeasy

A network administrator wants to enable User-ID for mobile users connecting via GlobalProtect in Prisma Access. Which component should be configured to map users to IP addresses when using the Cloud Identity Engine?

A.Configure a User-ID agent on every branch router.
B.Install the GlobalProtect agent with local syslog forwarding.
C.Enable captive portal authentication on all remote network firewalls.
D.Configure Cloud Identity Engine (CIE) settings in Panorama to sync directory services.
AnswerD

CIE integrates with enterprise directory services to provide seamless user and group mapping for Prisma Access.

Why this answer

The Cloud Identity Engine (CIE) acts as the directory sync mechanism to gather user and group mapping information for Prisma Access.

84
MCQmedium

An organization wants to restrict access to a sensitive internal financial database so that only users belonging to the 'Finance-Dept' Active Directory group and connecting from compliant corporate laptops can access it. Which Prisma Access security feature combines user identity, device posture, and application access control?

A.URL Filtering Custom Categories
B.Zone Protection profiles
C.HIP (Host Information Profile) matching in Security Policies
D.CASB Inline Policy Rules
AnswerC

HIP profiles collect endpoint security state (antivirus, disk encryption, OS patch level) and are referenced in Security policy rules to grant or deny access.

Why this answer

Prisma Access ZTNA policy enforcement leverages User-ID, HIP (Host Information Profile) checks, and App-ID to enforce least-privilege access.

85
MCQmedium

A network engineer is configuring a new Remote Network in Prisma Access and needs to ensure that traffic from the branch office to the internet is breakout locally rather than backhauled to headquarters. How is local internet breakout verified in Prisma Access?

A.Verify the BGP AS number on the Service Connection.
B.Verify that 'Local Internet Breakout' is enabled in the Remote Network configuration and examine Traffic logs to confirm internet-bound sessions egress through the Remote Network's assigned public IP.
C.Ensure SSL Forward Proxy is disabled on the Security Policy.
D.Check the GlobalProtect Portal client configuration settings.
AnswerB

Enabling local breakout routes internet traffic directly out of the Prisma Access node associated with that location, which can be confirmed in traffic logs.

Why this answer

Local internet breakout is configured in the Remote Network settings and verified through traffic logs showing local egress IP addresses.

86
MCQhard

A Prisma Access deployment utilizes Service Connections to connect to a corporate data center. An administrator notices that traffic destined for internal data center subnets is being sent out to the internet instead of the Service Connection. What is the most likely cause of this routing misconfiguration?

A.WildFire inspection is enabled on the security policy rule.
B.Missing or incorrect static routes / BGP route advertisements for the internal subnets in the Service Connection routing configuration.
C.The Security Predefined Policy rule order is incorrect.
D.The GlobalProtect Portal client timeout is set too low.
AnswerB

If internal subnets are not explicitly advertised or routed toward the Service Connection, Prisma Access defaults to forwarding them via the internet egress.

Why this answer

Incorrect static or dynamic routing advertisements (such as missing or overlapping static routes / BGP prefixes) cause traffic to take the default internet route instead of the Service Connection.

87
MCQmedium

A security engineer is configuring a Prisma Access Remote Network location with redundant IPsec tunnels to ensure high availability. What configuration requirement must be met on the customer premise equipment (CPE) router to support dynamic routing over these redundant tunnels?

A.Static floating routes with identical metrics must be used.
B.BGP peering must be established across both tunnels with the Prisma Access service node.
C.OSPF area 0 must be configured on the CPE interface.
D.GRE encapsulation must wrap the IPsec packets.
AnswerB

Dynamic routing with BGP over IPsec enables automatic failover between redundant tunnels.

Why this answer

BGP peering must be configured over both IPsec tunnels, with appropriate path metrics or AS path prepending to manage active/backup or active/active flow.

88
Multi-Selectmedium

An administrator is planning a Prisma Access deployment and needs to configure Service Connections to connect the enterprise data center to the cloud. Which TWO requirements must be met for a successful BGP peering session over a Service Connection? (Choose two)

Select 2 answers
A.Deploy a physical hardware firewall inside the AWS cloud VPC
B.Configure LACP active-active bonding on the Service Connection tunnel interfaces
C.Ensure the advertised BGP routes do not overlap with Prisma Access internal reserved subnets
D.Enable static default routing without configuring any routing protocols
E.Configure a unique Local ASN on the Panorama Service Connection settings
AnswersC, E

Overlapping routes with internal Prisma Access subnets will cause routing failures.

Why this answer

Service Connections require a valid BGP Autonomous System Number (ASN) and proper IP subnet addressing that does not conflict with Prisma Access reserved ranges.

89
MCQeasy

Which log category in Prisma Access records events when a user's host information profile (HIP) changes or fails a compliance check?

A.System log
B.HIP Match log
C.Configuration log
D.User-ID log
AnswerB

HIP Match logs store records of endpoint evaluations against defined Host Information Profiles.

Why this answer

HIP Match logs record endpoint compliance evaluation results.

90
MCQeasy

An enterprise wants to implement Firewall as a Service (FWaaS) using Prisma Access to protect inter-branch traffic and internet traffic. Which Panorama template type is primarily used to push network and device configurations to Prisma Access nodes?

A.Stack templates
B.Prisma Access Global templates
C.Cloud Services templates
D.Mobile User dynamic templates
AnswerC

Cloud Services templates are specifically designed to configure Prisma Access Remote Networks, Mobile Users, and Service Connections.

Why this answer

Panorama uses Cloud Services templates to manage network, interface, and routing settings for Prisma Access locations.

91
Multi-Selectmedium

An administrator needs to configure Prisma Access ZTNA to verify endpoint hygiene before granting access to internal applications. Which TWO posture checks can be evaluated using GlobalProtect Host Information Profiles (HIP)? (Choose two)

Select 2 answers
A.Active Directory group membership hierarchy
B.BGP route advertisement metrics
C.Antivirus presence and definition update status
D.SAML Identity Provider multi-factor authentication token validity
E.Disk encryption status (e.g., FileVault or BitLocker enabled)
AnswersC, E

HIP profiles verify that antivirus software is installed, running, and up to date.

Why this answer

HIP profiles evaluate endpoint security parameters including disk encryption status, antivirus installation, OS patch levels, and software inventory.

92
Multi-Selectmedium

Which TWO logs or monitoring views in Panorama are essential when troubleshooting a remote network user's inability to reach a specific cloud application via Prisma Access? (Choose two)

Select 2 answers
A.Panorama > Cloud Services > Audit Log.
B.Device > Setup > Management.
C.Monitor > ACC (Application Command Center) to analyze application traffic behavior and usage trends.
D.Objects > Addresses.
E.Monitor > Logs > Traffic to verify if sessions are allowed, denied, or timed out.
AnswersC, E

ACC helps visualize whether traffic for the specific application is successfully traversing the network.

Why this answer

Troubleshooting application reachability requires examining Traffic logs for drops and ACC/Threat logs for security blocks.

93
MCQeasy

An administrator needs to review configuration changes made to Prisma Access settings in Panorama over the past week to determine who modified a security policy. Which log should the administrator examine?

A.Monitor > Logs > Threat.
B.Monitor > Logs > Config.
C.Monitor > Logs > Data Filtering.
D.Monitor > Logs > Traffic.
AnswerB

Config logs track administrative actions, including who made changes, when, and what objects were modified.

Why this answer

Configuration logs record all changes made to configurations in Panorama.

94
MCQhard

A deployment of Prisma Access requires ZTNA 2.0 posture check enforcement for remote users. The administrator must ensure that mobile devices attempting to connect to internal corporate apps are evaluated for disk encryption and active endpoint protection agents prior to tunnel establishment. Which component performs this real-time device posture assessment?

A.Remote Networks (RN) node
B.GlobalProtect app using Host Information Profile (HIP) reporting
C.Cloud Secure Web Gateway (SWG) explicit proxy listener
D.Cloud Managed Services (CMS) collector
AnswerB

The GlobalProtect app gathers host information (HIP data) such as disk encryption and antivirus status, reporting it to Prisma Access to dynamically enforce access controls.

Why this answer

Prisma Access integrates with Cortex XDR and Prisma Access Browser/GlobalProtect app to perform device posture checks via Host Information Profile (HIP) matching. HIP checks evaluate the security posture of the endpoint and feed directly into Security Policy rules enforcing ZTNA.

95
MCQmedium

An administrator needs to configure secure connectivity between a corporate data center and Prisma Access for headquarters-bound traffic. Which type of connection object should be created in Panorama?

A.Prisma SD-WAN Hub Integration
B.GlobalProtect Gateway Connection
C.Remote Network Connection
D.Service Connection
AnswerD

Service Connections connect enterprise datacenters and headquarters to Prisma Access.

Why this answer

A Service Connection is used to connect enterprise headquarters or data centers to Prisma Access.

96
MCQeasy

Which component of Prisma Access is responsible for providing centralized management, monitoring, and reporting for all SWG, ZTNA, CASB, and FWaaS features?

A.Panorama
B.Prisma Access Insights
C.GlobalProtect App
D.Prisma Cloud
AnswerA

Panorama provides a single pane of glass to configure, manage, and view logs for all Prisma Access components.

Why this answer

Panorama is the centralized management and logging platform for Prisma Access.

97
Multi-Selectmedium

Which TWO methods can an administrator use to monitor the health and operational status of Prisma Access Service Connections in Panorama? (Choose two)

Select 2 answers
A.Panorama > Cloud Services > Status > Service Connections dashboard.
B.Objects > Custom Objects > URL Filtering.
C.Policies > NAT configuration view.
D.Device > Log Settings forwarding profiles.
E.Operational CLI commands and monitoring tools showing tunnel interface statistics and BGP/static route status.
AnswersA, E

This dashboard displays active status, tunnel health, and routing details for Service Connections.

Why this answer

Service connection health can be monitored via Cloud Services Status dashboards and operational CLI commands or system monitoring tools.

98
MCQmedium

A network engineer is troubleshooting why a specific security policy rule configured in Panorama is not matching traffic in a Prisma Access environment. Which Panorama testing tool simulates traffic against security rules to verify rule evaluation?

A.Review the Audit log for policy changes.
B.Check the ACC top threats widget.
C.Run 'show system state'.
D.Use the Panorama CLI command 'test security-policy-match source <ip> destination <ip> application <app>'
AnswerD

This command evaluates traffic attributes against the security policy table and returns the matching rule name.

Why this answer

The 'test security-policy-match' CLI command tests policy evaluation for given parameters (source, destination, user, app).

99
Multi-Selectmedium

Which TWO configuration steps should an administrator verify when troubleshooting an issue where Panorama cannot push updates or configurations to Prisma Access nodes? (Choose two)

Select 2 answers
A.Check Panorama > Job Status to review specific error codes and failed configuration push tasks.
B.Verify that Panorama has active cloud services communication and valid management certificates to reach Prisma Access cloud infrastructure.
C.Restart the CPE device at the branch office.
D.Update the URL Filtering database manually.
E.Modify the NAT policy rules on the remote firewall.
AnswersA, B

Job status provides detailed failure reasons for rejected configuration pushes.

Why this answer

Troubleshooting Panorama-to-Prisma Access communication involves checking management plane connectivity, service setup status, and job status error messages.

100
Multi-Selecthard

An organization is deploying Prisma Access CASB and Secure Web Gateway features. Which THREE capabilities are provided by Prisma Access Inline CASB compared to out-of-band SaaS Security API? (Choose three)

Select 3 answers
A.Deep historical scanning of files at rest stored within cloud SaaS storage repositories.
B.Out-of-band remediation of externally shared links via API webhooks.
C.Real-time blocking of unauthorized data uploads to sanctioned and unsanctioned cloud applications.
D.Enforcement of tenant restriction headers (HTTP header insertion) for enterprise cloud apps.
E.Immediate prevention of malware downloads from cloud storage platforms during user browsing.
AnswersC, D, E

Inline CASB blocks traffic as it passes through the proxy/firewall engine in real time.

Why this answer

Inline CASB inspects traffic in real time, blocks unauthorized uploads/downloads immediately, and enforces tenant restriction headers.

101
MCQeasy

During the initial deployment of Prisma Access for remote networks, an administrator needs to define the bandwidth allocation for a specific compute location. Which tool is used to manage and push this bandwidth allocation?

A.Panorama
B.Prisma SD-WAN Cloud Controller
C.Prisma Access Plugin for AWS Console
D.GlobalProtect Portal standalone web GUI
AnswerA

Panorama provides the centralized interface to configure Prisma Access locations and bandwidth.

Why this answer

Panorama is the centralized management tool used to configure and push Prisma Access settings, including bandwidth allocation for remote networks and mobile users.

102
MCQmedium

An administrator is troubleshooting a Prisma Access mobile user environment where users report that authentication via RADIUS is failing. Where should the administrator check for RADIUS communication errors and timeout events in Panorama?

A.Policies > NAT.
B.Panorama > Cloud Services > Audit Log.
C.Monitor > Logs > System or Authentication logs in Panorama.
D.Monitor > Logs > Threat.
AnswerC

System and authentication logs record connectivity issues, timeouts, and responses from external RADIUS authentication servers.

Why this answer

System logs and Authentication logs record RADIUS server communication errors and timeouts.

103
MCQeasy

Which pane in the Prisma Access monitoring interface provides an overview of active mobile users, connection status, and geographical distribution?

A.Policies > Security > Status
B.Network > GlobalProtect > Runtime
C.Monitor > ACC or the Prisma Access App dashboard
D.Device > Status > Active Users
AnswerC

The ACC and Prisma Access App dashboards display graphical summaries of active mobile users, locations, and traffic.

Why this answer

The Prisma Access monitoring app and Panorama's ACC provide real-time dashboards for mobile user connectivity.

104
MCQhard

A Prisma Access administrator needs to implement ZTNA 2.0 continuous trust verification for mobile users accessing internal private applications. Which feature ensures that continuous validation of both user identity and device posture occurs throughout the session, rather than only at initial authentication?

A.Continuous Trust Verification via periodic Host Information Profile (HIP) re-evaluation and app-connector telemetry
B.Pre-logon GlobalProtect connection mode
C.Explicit proxy PAC file auto-discovery
D.RADIUS single sign-on (SSO) integration with Multi-Factor Authentication
AnswerA

ZTNA 2.0 continuously verifies trust by periodically re-evaluating HIP reports and monitoring application behavior to revoke access immediately if risk increases.

Why this answer

ZTNA 2.0 in Prisma Access enforces continuous trust verification by re-evaluating device posture (HIP checks) and user context periodically during active sessions, cutting off access if conditions change.

105
MCQeasy

A security administrator needs to check real-time threat logs for a specific Prisma Access mobile user who reports being blocked from accessing a malicious file. Which Panorama menu path provides the most direct access to these logs?

A.Panorama > Cloud Services > Setup > Management.
B.Prisma Access > Service Setup > Locations.
C.Policies > Security.
D.Monitor > Logs > Threat.
AnswerD

The Threat log viewer in Panorama aggregates security events, WildFire blocks, and anti-spyware alerts across all Prisma Access nodes.

Why this answer

Threat logs in Prisma Access are viewed centrally in Panorama under Monitor > Logs > Threat.

106
MCQhard

A security engineer is troubleshooting a ZTNA connection issue where remote users running GlobalProtect are unable to reach internal applications hosted behind a Prisma Access Remote Network. The mobile users and remote networks are in the same region, but direct branch-to-branch routing is failing. Which Prisma Access feature must be verified to ensure direct traffic flow between mobile users and remote networks without backhauling to the cloud service nodes?

A.Explicit Proxy PAC file redirect
B.Prisma Access Insights Regional Peering
C.Mobile User to Remote Network direct routing
D.Clean Pipe architecture
AnswerC

This feature allows sessions between mobile users and remote networks to bypass unnecessary cloud node processing when co-located in the same region.

Why this answer

Prisma Access supports Mobile User to Remote Network (MU-to-RN) direct traffic routing, which allows traffic to flow between mobile users and remote networks directly when both are connected to the same service node location.

107
MCQmedium

A security analyst is investigating a Prisma Access FWaaS alert indicating a brute-force attack against an internal server published via a Service Connection. Which security profile should be tuned to detect and block this network-layer attack signature?

A.Vulnerability Protection Profile
B.Antivirus Profile
C.Data Filtering Profile
D.URL Filtering Profile
AnswerA

Vulnerability Protection profiles detect and prevent network exploitation attempts, including brute-force attacks and buffer overflows.

Why this answer

Vulnerability Protection profiles inspect network traffic for known exploit signatures, including brute-force attempts and protocol anomalies.

108
Multi-Selectmedium

Which TWO troubleshooting methods are effective when verifying whether Host Information Profile (HIP) checks are operating correctly for Prisma Access mobile users? (Choose two)

Select 2 answers
A.Modify the NAT policy rules.
B.Restart the physical branch firewall.
C.Check GlobalProtect client settings in Panorama to ensure HIP report generation and submission intervals are correctly configured.
D.Monitor > Logs > HIP Match to review successful and failed compliance evaluations.
E.Update the URL Filtering database.
AnswersC, D

Gateways must be configured to request and process HIP reports from agents at regular intervals.

Why this answer

HIP check troubleshooting involves reviewing HIP match logs and checking GlobalProtect agent settings for HIP report submission intervals.

109
MCQmedium

An administrator is configuring Prisma Access Secure Web Gateway and wants to ensure that newly registered malicious domains are blocked automatically without waiting for manual signature updates. Which Palo Alto Networks security service provides real-time IP and domain threat intelligence to Prisma Access?

A.Prisma Access Insights
B.DNS Security
C.SaaS Security API
D.GlobalProtect Cloud Service Agent
AnswerB

DNS Security uses machine learning and predictive analytics to block newly registered domains (NRDs) and command-and-control (C2) domains in real time.

Why this answer

WildFire and DNS Security provide real-time threat intelligence and automated threat prevention across Prisma Access.

110
Multi-Selecthard

When designing high availability and redundancy for Prisma Access Remote Networks, which THREE considerations or practices are essential? (Choose three)

Select 3 answers
A.Cluster physical firewalls in an Active-Active HA pair inside the Prisma Access cloud infrastructure.
B.Implement dynamic routing protocols (BGP) over the IPsec tunnels to facilitate automatic failover.
C.Deploy dual customer edge routers at the branch location connecting to Prisma Access.
D.Configure redundant IPsec tunnels from customer premises equipment (CPE) to diverse Prisma Access gateways.
E.Manually update static routes on employee laptops whenever a remote network link fails.
AnswersB, C, D

BGP allows routers to dynamically adjust paths and switch traffic to secondary tunnels upon link failure.

Why this answer

Remote network redundancy relies on redundant IPsec tunnels, BGP multipath/failover, and dual edge routers.

111
MCQmedium

An administrator notices that users connecting via Prisma Access Remote Networks are unable to reach a specific internal application hosted in the corporate datacenter. The traffic is dropped by Prisma Access. Which tool in Panorama should the administrator use first to verify if the security policy is matching and blocking the traffic in real-time?

A.GlobalProtect app diagnostics tab on the endpoint.
B.Prisma Access Insight path quality monitoring.
C.Traffic Logs with a filter for the source user and destination IP, checking the 'Drop Reason' field.
D.Panorama Dynamic Updates status page.
AnswerC

Traffic Logs record the drop reason and allow administrators to immediately see if a security policy rule denied the traffic.

Why this answer

ACC (App-Command Center) and Traffic Logs are used to inspect sessions, but the ACC does not provide real-time session debugging for specific policy rule matches. The Panorama Traffic log with the correct filter or the CLI command 'test security-policy-match' is used to troubleshoot policy matches, but for real-time monitoring of dropped packets on Prisma Access nodes, Traffic Logs filtered by drop cause or using the Real-Time Log Viewer is the most appropriate native UI troubleshooting mechanism.

112
Multi-Selectmedium

Which TWO commands or tools are recommended for troubleshooting routing issues on Prisma Access infrastructure? (Choose two)

Select 2 answers
A.Monitor > Logs > Threat.
B.CLI operational commands such as 'show routing route' or 'show routing protocol bgp' to inspect active routing tables.
C.The Prisma Access monitoring dashboard in Panorama to review BGP peer status and traffic paths.
D.Device > High Availability state monitor.
E.Objects > Custom Objects > URL Filtering.
AnswersB, C

These commands display active route entries, next-hops, and BGP adjacency states.

Why this answer

Routing troubleshooting utilizes dynamic routing operational CLI commands (such as show routing route) and Panorama traffic/routing monitoring tools.

113
Multi-Selectmedium

An administrator is troubleshooting ZTNA connectivity issues for mobile users connecting via Prisma Access. Which TWO tools or log types in Panorama should the administrator check to diagnose user authentication and tunnel establishment problems? (Choose two)

Select 2 answers
A.WildFire submission log
B.System log
C.HIP Match log
D.Data Filtering log
E.Authentication log
AnswersB, E

System logs record daemon events, GlobalProtect gateway connection statuses, and service health messages.

Why this answer

System logs and Authentication logs provide visibility into mobile user login events, GlobalProtect connection handshakes, and SAML/LDAP authentication results.

114
MCQeasy

Which component in Prisma Access is responsible for performing decryption, content inspection, and threat prevention for mobile users?

A.Compute Location
B.GlobalProtect Portal
C.Service Connection
D.Panorama
E.Cloud Identity Engine
AnswerA

Compute locations perform the actual traffic processing for mobile users.

Why this answer

The Service Connection is for branch-to-datacenter traffic, while the Compute Location handles the actual inspection for mobile users.

115
Multi-Selecthard

When designing Security and Inspection Policies for Prisma Access, an administrator needs to ensure optimal performance and security coverage. Which THREE best practices should the administrator follow when implementing Security Policy rules in Panorama for Prisma Access? (Choose three)

Select 3 answers
A.Disable SSL Decryption globally to maximize Prisma Access processing throughput across all mobile user nodes.
B.Configure all Security Policy rules to use 'Any' application to simplify rule maintenance and reduce rule count.
C.Attach appropriate Security Profiles (such as Antivirus, Anti-Spyware, and Vulnerability Protection) to all active Security Policy allow rules.
D.Use App-ID and User-ID in security rules instead of relying solely on IP addresses and port numbers.
E.Place specific application allow rules above broad general rules, and maintain explicit deny rules for known malicious traffic where appropriate.
AnswersC, D, E

Security profiles inspect allowed application traffic for threats, which is a core best practice in Prisma Access.

Why this answer

Prisma Access security best practices include placing explicit block rules at the top, leveraging application-layer filtering rather than relying solely on ports/IPs, and utilizing Security Profiles (antivirus, anti-spyware, URL filtering) across rules.

116
MCQmedium

An administrator wants to configure authentication for mobile users using SAML 2.0 with Prisma Access. Where is the identity provider (IdP) metadata imported and configured?

A.Network > GlobalProtect > Portal > Authentication
B.Panorama > Cloud Services > Authentication > SAML
C.Device > Server Profiles > SAML Identity Provider
D.Objects > Cloud Identity Engine > SAML
AnswerC

SAML IdP server profiles are where metadata is imported and sign-on properties are established.

Why this answer

SAML identity provider server profiles are configured in Panorama under Device or Server Profiles before being assigned to GlobalProtect authentication profiles.

117
Multi-Selectmedium

When managing Security Policies in Prisma Access, which TWO components are essential to ensure that policies are correctly applied to traffic?

Select 2 answers
A.Using source/destination address objects or tags.
B.Enabling SSL inspection on all traffic.
C.Defining the physical port number.
D.Configuring the GlobalProtect client version.
E.Defining source and destination zones.
AnswersA, E

Objects allow for granularity in policy matching.

Why this answer

Security policies require zones and address objects (or user groups) to identify traffic uniquely.

118
MCQeasy

An administrator needs to monitor the volume of traffic passing through a specific Prisma Access Service Connection. Which monitoring tool in Panorama displays aggregated data on bandwidth usage, top applications, and top users?

A.Panorama > Cloud Services > Audit Log.
B.Device > Log Settings.
C.Monitor > ACC (Application Command Center).
D.Policies > QoS.
AnswerC

ACC aggregates traffic logs into visual widgets for analysis of bandwidth, apps, and users across Prisma Access.

Why this answer

The Application Command Center (ACC) in Panorama provides visual summaries of traffic trends, bandwidth usage, top applications, and users.

119
MCQhard

An enterprise deployment of Prisma Access utilizes Kerberos authentication for mobile users. Users report frequent authentication prompt failures when connecting via GlobalProtect from external networks. What is the most likely root cause of Kerberos authentication failure in this scenario?

A.WildFire cloud subscription has expired.
B.The decryption policy is missing an inbound rule.
C.The GlobalProtect client software license is invalid.
D.Lack of direct network line-of-sight or routing from the mobile user's remote location to the internal Active Directory Domain Controllers via a Service Connection.
AnswerD

Kerberos authentication requires direct communication between the client/gateway and the KDC; if Service Connections do not correctly route KDC traffic, authentication fails.

Why this answer

Kerberos relies heavily on direct line-of-sight and UDP/TCP connectivity to Active Directory KDCs (Domain Controllers) along with valid service principal names (SPNs) and time synchronization.

120
Multi-Selecthard

An administrator is setting up the Cloud Identity Engine (CIE) to support user mapping and authentication for Prisma Access. Which THREE components or steps are required for a successful CIE deployment? (Choose three)

Select 3 answers
A.Configure a Directory Service connector to sync users and groups from Active Directory.
B.Configure authentication settings and map user attributes within CIE.
C.Install physical Domain Controllers inside each Prisma Access cloud node.
D.Link the Cloud Identity Engine tenant to the Prisma Access / Panorama instance.
E.Configure BGP peering between CIE and the enterprise DNS servers.
AnswersA, B, D

The directory service connector synchronizes organizational units, users, and groups into CIE.

Why this answer

CIE requires directory service integration, cloud tenant setup, and agent or sync configuration.

121
Multi-Selecthard

Which THREE items must be configured to successfully enforce HIP-based security policies for mobile users?

Select 3 answers
A.Add the HIP Profile to the Security Policy rule.
B.Enable HIP data collection on the GlobalProtect portal.
C.Create a separate GlobalProtect gateway for each security level.
D.Create HIP Objects and Profiles in the Panorama object library.
E.Install an on-premises User-ID agent.
AnswersA, B, D

The policy must be linked to the profile.

Why this answer

HIP requires the agent to be enabled, the objects to be defined, and the security policy to reference them.

122
Multi-Selecthard

An administrator needs to optimize mobile user traffic performance and reduce latency in Prisma Access. Which THREE features or configurations can be utilized to achieve this? (Choose three)

Select 3 answers
A.Configure split tunneling to route non-corporate or high-bandwidth web traffic (e.g., video streaming) directly to the internet.
B.Disable all threat inspection profiles for mobile users to bypass security processing.
C.Enable 'Closest Gateway' selection so users automatically connect to the nearest Prisma Access location.
D.Implement Quality of Service (QoS) policies to prioritize business-critical applications.
E.Route all mobile user traffic through a single centralized headquarters datacenter firewall.
AnswersA, C, D

Split tunneling prevents unnecessary backhauling of non-corporate traffic through Prisma Access nodes.

Why this answer

Traffic optimization for mobile users involves split tunneling, optimal gateway selection, and QoS.

123
MCQeasy

An enterprise requires their mobile users to use a Secure Web Gateway (SWG) service that intercepts all web traffic without requiring explicit browser proxy configurations on each client machine. Which Prisma Access deployment method meets this requirement transparently?

A.GlobalProtect client in transparent tunnel mode forwarding traffic to Prisma Access SWG
B.GRE tunnel forwarding from local ISP routers
C.Static NAT configuration on the branch office gateway
D.GlobalProtect client in explicit proxy mode
AnswerA

Transparent forwarding via the GlobalProtect client routes all traffic securely to Prisma Access SWG without requiring client-side proxy settings.

Why this answer

Prisma Access transparently intercepts web traffic from mobile users via the GlobalProtect app operating in layer-3 tunnel mode, eliminating the need for PAC files or manual proxy settings.

124
MCQmedium

An administrator troubleshooting a Prisma Access mobile user connectivity issue wants to verify whether the GlobalProtect gateway is actively responding to client connection requests. Where can this real-time session and gateway status be verified?

A.Policies > Decryption.
B.Panorama > Cloud Services > Status > Mobile Users > Gateways.
C.Device > Setup > Operations.
D.Objects > Addresses.
AnswerB

This status view shows active gateway instances, region status, and connected mobile user counts.

Why this answer

Gateway status and active sessions can be checked in Panorama under Cloud Services > Status or via operational CLI commands.

125
MCQhard

An administrator troubleshooting a Prisma Access Mobile Users deployment notices authentication failures for users authenticating via SAML to an external IdP. The users report being stuck in an authentication loop. Which log file on Panorama should the administrator examine to troubleshoot SAML response assertion issues?

A.authd.log
B.traffic.log
C.globalProtectPortal.log
D.threat.log
AnswerA

The authd daemon handles authentication processes, including SAML assertion validation and IdP communication.

Why this answer

SAML authentication between Prisma Access (acting as Service Provider) and an external IdP involves authd and pan_sevp logs. Specifically, the authd.log captures SAML authentication requests, responses, and assertion parsing details.

126
Multi-Selecthard

An enterprise is integrating Prisma Access with their corporate infrastructure. Which THREE components can be connected to Prisma Access to provide centralized cloud security inspection? (Choose three)

Select 3 answers
A.Service Connections (corporate data centers or headquarters)
B.Local standalone firewalls operating in hardware bypass mode without cloud connection
C.Public cloud VPCs directly via automated cloud connectors without IPsec or BGP
D.Remote Networks (branch offices via IPsec VPN)
E.Mobile Users running the GlobalProtect app
AnswersA, D, E

Service Connections link Prisma Access back to corporate data centers and internal resources.

Why this answer

Prisma Access connects Mobile Users, Remote Networks (branch offices), and Service Connections (data centers/HQ).

127
Multi-Selecthard

An administrator is troubleshooting a Prisma Access environment where threat prevention profiles are failing to block known malicious file downloads. Which THREE settings or logs should the administrator investigate? (Choose three)

Select 3 answers
A.Check the Threat and WildFire logs to see if the files were inspected, logged, or bypassed due to exclusions.
B.Ensure that SSL Decryption is enabled for the traffic, as encrypted payloads cannot be inspected for malware signatures without decryption.
C.Check the BGP AS number on the Remote Network CPE.
D.Verify the GlobalProtect Portal client timeout setting.
E.Verify that Anti-Spyware, Antivirus, and WildFire analysis profiles are actively attached to the matching Security Policy rules.
AnswersA, B, E

Logs reveal whether the file was scanned, detected, or allowed based on decryption or file size exclusions.

Why this answer

Investigating threat blocking failures requires checking security policy profile assignments, threat logs, decryption status, and WildFire/Antivirus profile configurations.

128
MCQmedium

A security administrator is troubleshooting a URL Filtering policy in Prisma Access where users are able to access a category that should be blocked. Which tool in Panorama should the administrator use to test and verify which URL category a specific website falls under and which policy rule applies?

A.Review the ACC top applications widget.
B.Check the GlobalProtect gateway connection status.
C.Use the URL Filtering lookup tool in Panorama or test via 'test url <website>' in the CLI.
D.Examine the System log for category update errors.
AnswerC

Testing URL categorization confirms how Prisma Access classifies a specific domain and which action is enforced.

Why this answer

The Policy Optimizer or URL Lookup tool helps test and verify URL categories and matching rules.

129
MCQhard

An administrator is troubleshooting a Prisma Access mobile user environment where users are unable to connect because of an invalid certificate error presented by the GlobalProtect Portal. Which configuration element in Panorama should be verified?

A.Verify that the SSL/TLS certificate assigned to the GlobalProtect Portal configuration is valid, not expired, and trusted by the client devices.
B.Check the IPsec crypto profile under Network > Network Profiles > IPsec Crypto.
C.Check the User-ID agent connection timeout settings.
D.Verify the BGP AS number on the Remote Network node.
AnswerA

If the portal certificate is self-signed or untrusted by client machines, GlobalProtect clients will reject the connection immediately.

Why this answer

The GlobalProtect Portal SSL/TLS certificate configuration is tied to the portal configuration profile.

130
Multi-Selecthard

An administrator is troubleshooting a Prisma Access deployment where specific applications are identified as 'incomplete' or 'unknown-tcp' in the Traffic logs. Which THREE factors or troubleshooting steps should be evaluated? (Choose three)

Select 3 answers
A.Verify the expiration date of the GlobalProtect gateway SSL certificate.
B.Check the WildFire subscription license key status.
C.Check for asymmetrical routing where traffic enters through one Prisma Access node/tunnel but exits through another.
D.Examine packet captures to determine if sessions are being terminated before the application handshake (three-way TCP handshake) completes.
E.Verify that security rules and service objects do not prematurely drop traffic before App-ID can inspect enough packets.
AnswersC, D, E

Asymmetrical routing prevents the firewall from seeing both sides of a handshake, leading to 'incomplete' sessions.

Why this answer

'Incomplete' and 'unknown-tcp' sessions typically occur due to insufficient data packets for App-ID identification, asymmetrical routing, or session timeouts before handshakes complete.

131
MCQhard

A network administrator needs to verify that the QoS (Quality of Service) settings applied to Prisma Access mobile users are prioritizing real-time voice and video traffic correctly. Where are QoS profiles applied in the Prisma Access configuration hierarchy in Panorama?

A.Objects -> QoS Profiles -> Global
B.Panorama -> Cloud Services -> Configuration -> QoS Policy
C.GlobalProtect Portal -> Client Settings -> QoS
D.Network -> Interfaces -> Tunnel -> QoS
AnswerB

QoS policies and profiles for Prisma Access are managed under the Cloud Services configuration workflow in Panorama.

Why this answer

QoS profiles in Prisma Access are applied within the QoS policy rules and associated with the Cloud Services mobile user or remote network configuration to prioritize traffic classes.

132
Multi-Selecthard

An administrator is troubleshooting a Prisma Access mobile user issue where users connected via GlobalProtect cannot access local network printers or local subnet resources while connected to the VPN. Which THREE settings should be reviewed in Panorama? (Choose three)

Select 3 answers
A.Verify the BGP AS number on the Service Connection.
B.Check the GlobalProtect Agent configuration regarding 'Access Route' or local network access permissions.
C.Verify the Split Tunnel configuration in the GlobalProtect Client Settings to ensure local subnet exclusions or inclusions are correctly defined.
D.Review the client-side routing table to ensure local subnet gateway routes are preserved when the VPN connects.
E.Check the WildFire file analysis submission timeout settings.
AnswersB, C, D

Access route settings dictate which destination subnets are forced through the tunnel.

Why this answer

Accessing local network resources while on VPN involves split-tunneling configurations, access route pushes, and client settings.

133
MCQeasy

Which action should an administrator take to update the Prisma Access software and plugin versions across the deployment?

A.Device > Software > Prisma Access
B.Policies > Management > Updates
C.Monitor > Software Updates > Cloud
D.Panorama > Plugin > Cloud Services > Updates
AnswerD

Prisma Access plugin and cloud component updates are managed directly from the Panorama Plugin interface.

Why this answer

Panorama manages Prisma Access updates through the Software and Cloud Services plugin update mechanisms.

134
Multi-Selectmedium

Which TWO actions should an administrator take when troubleshooting an IPsec site-to-site tunnel failure between a customer CPE device and a Prisma Access Remote Network node? (Choose two)

Select 2 answers
A.Reconfigure the mobile user SAML authentication profile.
B.Disable all security policy rules across all remote locations.
C.Verify that IKE Phase 1 and Phase 2 proposal parameters (encryption, authentication, Diffie-Hellman groups) match between the CPE and Prisma Access node.
D.Restart the GlobalProtect agent on all remote user endpoints.
E.Check the System and operational logs in Panorama to identify exact IKE negotiation failure reasons.
AnswersC, E

Mismatched encryption or hashing algorithms prevent successful IPsec Security Association establishment.

Why this answer

Troubleshooting IPsec tunnels involves verifying phase 1/2 cryptographic and timer settings as well as checking tunnel monitoring status and Ike/IPsec operational logs.

135
Multi-Selecthard

An administrator is troubleshooting a Prisma Access Remote Network environment where BGP routes from the customer CPE are not being learned by Prisma Access. Which THREE configuration elements should be verified? (Choose three)

Select 3 answers
A.Ensure the Autonomous System (AS) numbers match or are correctly configured for external/internal BGP peering.
B.Confirm that the CPE is actively advertising the correct IP prefixes to the Prisma Access BGP peer.
C.Verify the WildFire cloud analysis subscription status.
D.Verify that the BGP peer IP addresses configured on Prisma Access match the CPE peer addresses.
E.Check the GlobalProtect portal SSL certificate expiration date.
AnswersA, B, D

Mismatched AS numbers prevent BGP session establishment.

Why this answer

BGP troubleshooting requires verifying peer IP addresses, AS numbers, authentication keys, and network prefix advertisements.

136
MCQhard

An architect is designing a Prisma Access deployment where branch offices require high availability using redundant IPSec VPN tunnels to Prisma Access Remote Networks. How does Prisma Access handle active-active redundant tunnels from a single branch router?

A.By utilizing VRRP across the cloud public IP addresses
B.By establishing multiple tunnels terminating on separate SPNs and using BGP multi-path or local preference for failover
C.By enabling Spanning Tree Protocol (STP) over the IPsec tunnel interfaces
D.By configuring LACP bonding directly across the cloud IPSec endpoints
AnswerB

Redundant tunnels terminate on Prisma Access nodes and rely on BGP metrics for active-active or active-passive behavior.

Why this answer

Prisma Access supports redundant IPSec tunnels from branch routers, utilizing BGP to manage path selection and failover between the tunnels.

137
MCQmedium

A network administrator needs to restrict access for remote users to a specific SaaS application based on their device's security posture. Which configuration sequence allows this in Prisma Access?

A.Configure an App-ID override rule and assign the device certificate to the User-ID agent.
B.Enable SSL Forward Proxy and add the device serial number to the GlobalProtect portal whitelist.
C.Assign a dynamic address group to the user and create a custom URL filtering category for the SaaS app.
D.Create a HIP Object, add it to a HIP Profile, and apply it to a Security Policy rule source criteria.
AnswerD

This is the standard workflow to enforce endpoint posture in Security Policies.

Why this answer

Host Information Profile (HIP) objects must be defined, added to a HIP Object Profile, and then referenced in a Security Policy rule.

138
MCQeasy

What is the primary function of the GlobalProtect Portal in a Prisma Access deployment?

A.Terminating the IPSec tunnel from branch sites.
B.Managing Cloud Identity Engine sync.
C.Hosting the GlobalProtect agent software and gateway lists.
D.Performing deep packet inspection.
AnswerC

This is the primary function of the portal.

Why this answer

The Portal provides authentication and the configuration/software updates to the GlobalProtect agent.

139
MCQhard

An architect is sizing a Prisma Access Remote Network location that experiences heavy video streaming traffic. Which factor is most critical when determining the required bandwidth license for this location?

A.The peak aggregate throughput of all users at the branch location
B.The total number of IP addresses in the branch local DHCP scope
C.The number of active BGP peers configured on the branch router
D.The maximum transmission unit (MTU) size configured on the IPSec tunnel
AnswerA

Bandwidth provisioning in Prisma Access is based on peak aggregate throughput requirements.

Why this answer

Remote Network bandwidth must be provisioned based on the peak aggregate throughput expected from all users behind the branch router.

140
Multi-Selectmedium

An administrator is configuring Prisma Access SWG and needs to implement granular control over file sharing and collaboration tools. Which TWO SaaS Security features can be configured in Prisma Access to achieve this? (Choose two)

Select 2 answers
A.IPsec crypto profile selection for branch offices
B.Shadow IT discovery and risk scoring of unapproved cloud applications
C.GlobalProtect client software version deployment rules
D.SaaS application activity controls to restrict specific actions like sharing files externally
E.WMI-based user mapping polling intervals
AnswersB, D

Prisma Access discovers unauthorized cloud apps and rates their risk based on security criteria.

Why this answer

Prisma Access CASB allows administrators to discover shadow IT, control tenant access, and inspect file activities.

141
Multi-Selectmedium

An administrator is reviewing the operational health and logs of Prisma Access. Which TWO monitoring tools or log types are available within Panorama for troubleshooting security events and traffic flows? (Choose two)

Select 2 answers
A.Traffic and Threat logs
B.Active Directory replication event logs
C.Local hypervisor resource utilization logs
D.Switch spanning-tree topology tables
E.HIP Match logs
AnswersA, E

Traffic and Threat logs record all session establishment details and security inspection verdicts.

Why this answer

Panorama provides traffic, threat, and HIP match logs alongside ACC dashboards for visibility.

142
MCQeasy

An administrator needs to verify the license status and active subscriptions (such as WildFire, Threat Prevention, and URL Filtering) for Prisma Access in Panorama. Which menu path should be used?

A.Monitor > Logs > System.
B.Objects > Applications.
C.Panorama > Cloud Services > Setup > Licenses or Panorama > License.
D.Policies > NAT.
AnswerC

Panorama tracks Prisma Access licenses and active feature subscriptions under the Cloud Services setup or license management views.

Why this answer

License information in Panorama is managed under Panorama > Device Deployment > Licenses or Cloud Services deployment status.

143
MCQeasy

Where do administrators configure service connections in Prisma Access to connect the cloud security infrastructure to the organization's data center or headquarters?

A.Network > Interfaces > Tunnel
B.Policies > QoS > Service Connections
C.Panorama > Cloud Services > Configuration > Service Connections
D.Device > Cloud Services > GlobalProtect
AnswerC

This menu path is used to define service connections, including peer IP addresses, BGP settings, and bandwidth.

Why this answer

Service connections are configured in the Panorama Cloud Services plugin to establish secure tunnels back to corporate datacenters.

144
MCQeasy

When deploying Prisma Access, which component acts as the central management plane to push security policies, configurations, and software updates to all cloud-managed SPNs?

A.Panorama
B.GlobalProtect Portal
C.AWS Transit Gateway Manager
D.Prisma Access Cloud Controller
AnswerA

Panorama is the centralized management platform for Prisma Access.

Why this answer

Panorama acts as the central management plane for Prisma Access.

145
MCQmedium

An organization requires traffic from remote users to specific SaaS applications to bypass the Prisma Access cloud security processing nodes and go directly to the internet. Which feature should the administrator configure?

A.Explicit Proxy PAC file routing
B.SD-WAN Traffic Steering Policies
C.GlobalProtect Split Tunneling based on Access Routes and Domains
D.SSL Decryption Exclusion Objects
AnswerC

Split tunneling configuration allows specific traffic domains to bypass the GlobalProtect tunnel.

Why this answer

Prisma Access allows Split Tunneling based on domains or destinations so that specific traffic (like video streaming or trusted SaaS) bypasses the VPN tunnel.

146
Multi-Selecthard

An engineer is troubleshooting a routing issue where a remote network branch connected to Prisma Access cannot reach another remote network branch (branch-to-branch routing). Which THREE configuration items must be verified to ensure successful branch-to-branch traffic flow? (Choose three)

Select 3 answers
A.Verify that local branch DHCP lease times are set to 8 hours
B.Verify that Security Policy rules permit traffic between the respective branch zones
C.Confirm that branch routers are advertising their local subnets via BGP to Prisma Access
D.Check that all mobile user clients have disabled split tunneling
E.Ensure 'Branch-to-Branch' routing is enabled in the Prisma Access infrastructure settings in Panorama
AnswersB, C, E

Firewall security policies must allow inter-branch traffic.

Why this answer

Branch-to-branch routing in Prisma Access requires explicit configuration, including enabling branch-to-branch traffic in Panorama, ensuring proper security policies permit the traffic, and correct route advertisement.

147
MCQhard

An enterprise user reports that when connected to Prisma Access Mobile Users, certain internal applications load extremely slowly or fail to render images. Investigation reveals that packet fragmentation is occurring. Which Prisma Access setting should the administrator adjust to mitigate this fragmentation issue for mobile users?

A.Change the mobile user IP pool subnet mask from /24 to /16.
B.Disable WildFire file forwarding for large files.
C.Increase the decryption profile timeout value.
D.Configure TCP MSS adjustment on the GlobalProtect tunnel settings or reduce the tunnel interface MTU.
AnswerD

Adjusting MSS or MTU on the GlobalProtect tunnel ensures packets fit within the encapsulation overhead without requiring fragmentation.

Why this answer

Adjusting the MTU or enabling TCP MSS clamping on the GlobalProtect gateway configuration resolves fragmentation issues for mobile users.

148
MCQmedium

A network engineer is configuring remote user access in Prisma Access and needs to ensure that internal corporate DNS resolution is utilized when users are connected via the GlobalProtect app. Where must the engineer configure the primary and secondary internal DNS server IP addresses?

A.In the Prisma SD-WAN DNS proxy forwarding table
B.In the Panorama GlobalProtect Client Settings configuration under Network Settings
C.Directly on the remote user local machine registry
D.In the cloud Managed Security Services Provider (MSSP) portal
AnswerB

Internal DNS servers assigned to the GlobalProtect agent are configured within the Client Settings.

Why this answer

DNS server IPs for remote users are configured in the GlobalProtect client configuration within Panorama under Cloud Services > Configuration > Users > GlobalProtect.

149
Multi-Selecthard

A security engineer is troubleshooting traffic inspection issues in Prisma Access FWaaS. Traffic between two mobile users is bypassing security policy inspection. Which THREE factors could cause intra-zone or inter-user traffic to bypass security inspection in Prisma Access? (Choose three)

Select 3 answers
A.Security policy rules configured with the 'App-Override' or custom bypass settings for specific applications.
B.GlobalProtect portal banner message customization.
C.An explicit Decryption rule configured with 'No Decrypt' action for sensitive categories.
D.Client split-tunneling configured to send specific traffic directly to the local internet rather than through Prisma Access.
E.Panorama template commit pending status on Remote Networks.
AnswersA, C, D

App-Override rules bypass deep packet inspection and signature analysis for matching traffic.

Why this answer

Traffic bypassing inspection can be caused by explicit decryption bypass rules, clientless or split-tunnel configurations, or specific application bypass features.

150
MCQmedium

An enterprise wants to ensure that all internet-bound traffic from mobile users is decrypted and inspected for malware and sensitive data using Prisma Access SWG. Which GlobalProtect client traffic forwarding configuration ensures that all traffic is sent to Prisma Access?

A.Explicit Proxy local bypass mode
B.Split Tunnel mode based on destination subnets
C.Client-less Portal mode
D.Tunnel All Traffic mode
AnswerD

Tunnel All Traffic mode routes all client internet and corporate traffic through Prisma Access for complete SWG inspection.

Why this answer

Tunnel all traffic mode routes all client traffic through the secure GlobalProtect tunnel to Prisma Access.

Page 1

Page 2 of 3

Page 3

All pages