SSE-Engineer Prisma Access Services Practice Question
An administrator is troubleshooting a connectivity issue where remote mobile users cannot reach internal private applications via Prisma Access ZTNA. Which THREE diagnostic steps or verification checks should the administrator perform? (Choose three)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the GlobalProtect app on the user endpoint has successfully established a secure tunnel and updated its Host Information Profile (HIP)
Troubleshooting Prisma Access ZTNA connectivity involves verifying the GlobalProtect connection status and HIP report, ensuring the Prisma Access App Connector is online and reachable, and checking the Security Policy rules for App-ID blocks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the GlobalProtect app on the user endpoint has successfully established a secure tunnel and updated its Host Information Profile (HIP)
Why this is correct
If the GlobalProtect tunnel is down or HIP checks fail, the user will be blocked from accessing ZTNA private applications.
- ✓
Check the status of the Prisma Access App Connectors in the management plane to ensure they are connected and healthy
Why this is correct
App Connectors bridge Prisma Access to the internal network; if they are offline, private application traffic cannot reach internal destinations.
- ✗
Reboot the physical public cloud provider datacenter hypervisor hosting the tenant
Why it's wrong here
Cloud hypervisors are managed entirely by Palo Alto Networks infrastructure operations; tenant administrators have no access to reboot them.
- ✓
Review the Prisma Access Traffic and Threat logs to confirm whether security policy rules are dropping or allowing the application traffic
Why this is correct
Traffic logs reveal if sessions are being blocked by security rules, helping isolate misconfigured App-ID rules or missing policies.
- ✗
Reconfigure the local ISP router's BGP autonomous system number to match the Prisma Access gateway
Why it's wrong here
Mobile remote users connect via GlobalProtect client software over the internet, not via BGP peering with their local ISP.
About these practice questions
Courseiva writes every SSE-Engineer question from scratch — 203 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This SSE-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSE-Engineer exam.