Courseiva
Prisma Access TroubleshootinghardMultiple SelectObjective-mapped

SSE-Engineer Prisma Access Troubleshooting Practice Question

An enterprise has deployed Prisma Access with multiple remote networks and mobile users. An administrator notices that threat intelligence feeds (such as malicious IP lists and dynamic address groups) are not updating. Which THREE components should be inspected to resolve this update failure? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check External Dynamic List (EDL) URLs and ensure that Prisma Access nodes can successfully reach the external EDL hosting servers.

Threat intelligence and dynamic updates require verifying Panorama internet connectivity, dynamic update schedules, and external dynamic list (EDL) reachability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify the BGP ASN configured on the Service Connection.

    Why it's wrong here

    BGP ASN settings control routing adjacencies, not threat intelligence feed retrieval.

  • Check External Dynamic List (EDL) URLs and ensure that Prisma Access nodes can successfully reach the external EDL hosting servers.

    Why this is correct

    If EDLs point to external URLs that are blocked or unreachable, dynamic lists fail to populate.

  • Verify that Panorama has outbound internet access to download threat feeds and dynamic updates from Palo Alto Networks servers.

    Why this is correct

    Panorama requires internet access to fetch dynamic updates and distribute them to Prisma Access nodes.

  • Inspect the Dynamic Update schedule and status in Panorama under Device Deployment to ensure updates are actively scheduled and applied.

    Why this is correct

    Misconfigured update schedules prevent regular retrieval of threat signatures and feeds.

  • Check the GlobalProtect portal certificate expiration date.

    Why it's wrong here

    GlobalProtect certificates govern client SSL trust, not threat feed downloads.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 203 original SSE-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This SSE-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSE-Engineer exam.