Courseiva
Prisma Access TroubleshootingmediumMultiple ChoiceObjective-mapped

SSE-Engineer Prisma Access Troubleshooting Practice Question

An administrator configures a new Service Connection in Prisma Access to allow mobile users to access resources in the corporate data center. However, traffic from mobile users cannot reach the data center. The administrator confirms that the IPsec tunnel is up. What is the most likely cause of this issue in Panorama?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The internal subnet routes associated with the Service Connection have not been added to the Mobile Users Explicit Proxy or Split Tunnel configuration.

When setting up Service Connections, administrators must update the Mobile Users explicit proxy or explicit routing settings (specifically pushing internal routes via the GlobalProtect agent config) so that clients know to send data center traffic through the Prisma Access tunnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Panorama requires a reboot to activate Service Connections.

    Why it's wrong here

    Panorama configuration pushes do not require a system reboot to apply networking settings.

  • The internal subnet routes associated with the Service Connection have not been added to the Mobile Users Explicit Proxy or Split Tunnel configuration.

    Why this is correct

    Mobile users will not route traffic destined for the corporate data center into Prisma Access unless the corresponding internal subnets are defined in their split tunnel / routing configuration.

  • The GlobalProtect client version is outdated on all endpoints.

    Why it's wrong here

    While client updates are recommended, they do not inherently block routing across an established Service Connection if basic routing rules are correct.

  • The WildFire public cloud subscription has expired.

    Why it's wrong here

    WildFire subscription expiration impacts malware analysis, not basic routing over Service Connections.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This SSE-Engineer question is part of Courseiva's 203-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This SSE-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSE-Engineer exam.