Courseiva

SSE-Engineer · domain

Prisma Access Services

Practise Certified Security Service Edge Engineer (SSE-Engineer) Prisma Access Services practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

55 questions12 easy22 medium21 hard

Focused practice

Practice Prisma Access Services questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Prisma Access Services

Prisma Access Services questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Prisma Access Services exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Prisma Access Services questions (55)

Click any question to see the full explanation, or start a practice session above.

1

An administrator notices that certain mobile users connecting via Prisma Access are experiencing intermittent authentication timeouts when authenticating via SAML 2.0. Where should the administrator check to verify the Identity Provider (IdP) connectivity status and SAML assertion errors within Panorama?

Hard
2

Which Prisma Access feature enables enterprises to inspect and secure traffic between different virtual networks or cloud environments connected to the cloud service?

Easy
3

An organization is migrating their branch offices to Prisma Access Firewall as a Service (FWaaS). What is the primary method used to connect a physical branch office location to the Prisma Access cloud infrastructure securely?

Easy
4

When configuring Prisma Access via Panorama, which administrative role or permission is required to push configuration changes to the cloud infrastructure?

Easy
5

An administrator configuring Prisma Access ZTNA wants to view real-time metrics regarding active mobile user connections, bandwidth consumption per region, and tunnel status. Which tool provides this specific operational dashboard?

Medium
6

An administrator is designing a Prisma Access Secure Web Gateway (SWG) and CASB architecture. Which THREE capabilities can be enforced natively through Prisma Access SWG and inline CASB policies? (Choose three)

Hard
7

Which Prisma Access service capability provides secure, least-privilege remote access for third-party contractors who cannot install the GlobalProtect agent on their managed or unmanaged devices?

Easy
8

An organization requires that Prisma Access Secure Web Gateway inspects all inbound and outbound TLS traffic for employees browsing external websites. However, HR and healthcare applications must be bypassed due to privacy regulations. Where in Panorama must the administrator configure the exception for these categories?

Medium
9

An administrator is configuring authentication for Prisma Access mobile users. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)

Medium
10

An enterprise is deploying Prisma Access Service Connections to connect corporate data centers to the cloud security platform. Which THREE configuration parameters must be correctly specified on Panorama for a Service Connection? (Choose three)

Hard
11

An administrator is troubleshooting a Prisma Access deployment where mobile users are intermittently disconnected when moving between trusted Wi-Fi networks and cellular connections. Which GlobalProtect client setting in Prisma Access helps maintain session persistence and fast reconnection during network roaming?

Hard
12

An administrator is configuring Prisma Access Remote Networks to connect branch offices to the cloud security backbone. Which TWO configuration steps are required on Panorama to establish a functional Remote Network connection? (Choose two)

Medium
13

An administrator is setting up Prisma Access and needs to ensure that mobile users connecting from managed corporate laptops can access internal resources, while unmanaged contractor laptops are restricted to web-based applications only. Which Prisma Access mechanism distinguishes between managed and unmanaged endpoints during connection?

Hard
14

An administrator is configuring Prisma Access Secure Web Gateway and wants to restrict access to high-risk web categories. Which TWO options represent configurable actions within a Prisma Access URL Filtering profile? (Choose two)

Medium
15

A security architect is designing a Prisma Access FWaaS deployment and needs to ensure robust security posture across all zones (Mobile Users, Remote Networks, Service Connections, and Internet). Which THREE security profile types should be attached to Security Policy rules to ensure comprehensive threat prevention? (Choose three)

Hard
16

An administrator is configuring Prisma Access Firewall as a Service (FWaaS) to protect outbound internet traffic from remote networks. They want to ensure that known command-and-control (C2) traffic and vulnerability exploits are blocked dynamically in real time. Which security profile should be applied to the security policy rules?

Medium
17

A security architect is designing a CASB inline policy in Prisma Access. The requirement is to restrict corporate users from logging into personal instances of sanctioned SaaS applications (e.g., personal Microsoft 365 or Google Workspace) while allowing access to corporate-owned tenants. Which feature enables this control?

Hard
18

An organization wants to restrict access to a sensitive internal financial database so that only users belonging to the 'Finance-Dept' Active Directory group and connecting from compliant corporate laptops can access it. Which Prisma Access security feature combines user identity, device posture, and application access control?

Medium
19

A security engineer is configuring a Prisma Access Remote Network location with redundant IPsec tunnels to ensure high availability. What configuration requirement must be met on the customer premise equipment (CPE) router to support dynamic routing over these redundant tunnels?

Medium
20

Which log category in Prisma Access records events when a user's host information profile (HIP) changes or fails a compliance check?

Easy
21

An enterprise wants to implement Firewall as a Service (FWaaS) using Prisma Access to protect inter-branch traffic and internet traffic. Which Panorama template type is primarily used to push network and device configurations to Prisma Access nodes?

Easy
22

An administrator needs to configure Prisma Access ZTNA to verify endpoint hygiene before granting access to internal applications. Which TWO posture checks can be evaluated using GlobalProtect Host Information Profiles (HIP)? (Choose two)

Medium
23

A deployment of Prisma Access requires ZTNA 2.0 posture check enforcement for remote users. The administrator must ensure that mobile devices attempting to connect to internal corporate apps are evaluated for disk encryption and active endpoint protection agents prior to tunnel establishment. Which component performs this real-time device posture assessment?

Hard
24

Which component of Prisma Access is responsible for providing centralized management, monitoring, and reporting for all SWG, ZTNA, CASB, and FWaaS features?

Easy
25

An organization is deploying Prisma Access CASB and Secure Web Gateway features. Which THREE capabilities are provided by Prisma Access Inline CASB compared to out-of-band SaaS Security API? (Choose three)

Hard
26

A Prisma Access administrator needs to implement ZTNA 2.0 continuous trust verification for mobile users accessing internal private applications. Which feature ensures that continuous validation of both user identity and device posture occurs throughout the session, rather than only at initial authentication?

Hard
27

A security engineer is troubleshooting a ZTNA connection issue where remote users running GlobalProtect are unable to reach internal applications hosted behind a Prisma Access Remote Network. The mobile users and remote networks are in the same region, but direct branch-to-branch routing is failing. Which Prisma Access feature must be verified to ensure direct traffic flow between mobile users and remote networks without backhauling to the cloud service nodes?

Hard
28

A security analyst is investigating a Prisma Access FWaaS alert indicating a brute-force attack against an internal server published via a Service Connection. Which security profile should be tuned to detect and block this network-layer attack signature?

Medium
29

An administrator is configuring Prisma Access Secure Web Gateway and wants to ensure that newly registered malicious domains are blocked automatically without waiting for manual signature updates. Which Palo Alto Networks security service provides real-time IP and domain threat intelligence to Prisma Access?

Medium
30

An administrator is troubleshooting ZTNA connectivity issues for mobile users connecting via Prisma Access. Which TWO tools or log types in Panorama should the administrator check to diagnose user authentication and tunnel establishment problems? (Choose two)

Medium
31

An enterprise requires their mobile users to use a Secure Web Gateway (SWG) service that intercepts all web traffic without requiring explicit browser proxy configurations on each client machine. Which Prisma Access deployment method meets this requirement transparently?

Easy
32

An enterprise is integrating Prisma Access with their corporate infrastructure. Which THREE components can be connected to Prisma Access to provide centralized cloud security inspection? (Choose three)

Hard
33

A network administrator needs to verify that the QoS (Quality of Service) settings applied to Prisma Access mobile users are prioritizing real-time voice and video traffic correctly. Where are QoS profiles applied in the Prisma Access configuration hierarchy in Panorama?

Hard
34

An administrator is configuring Prisma Access SWG and needs to implement granular control over file sharing and collaboration tools. Which TWO SaaS Security features can be configured in Prisma Access to achieve this? (Choose two)

Medium
35

A security engineer is troubleshooting traffic inspection issues in Prisma Access FWaaS. Traffic between two mobile users is bypassing security policy inspection. Which THREE factors could cause intra-zone or inter-user traffic to bypass security inspection in Prisma Access? (Choose three)

Hard
36

An enterprise wants to ensure that all internet-bound traffic from mobile users is decrypted and inspected for malware and sensitive data using Prisma Access SWG. Which GlobalProtect client traffic forwarding configuration ensures that all traffic is sent to Prisma Access?

Medium
37

Which log type in Prisma Access should an administrator examine to review details about blocked URLs, category ratings, and user web-browsing attempts?

Easy
38

When designing a Prisma Access deployment for remote workers, which component authenticates the user and assigns the appropriate GlobalProtect gateway connection based on geographic location?

Easy
39

An administrator notices that certain SaaS applications are not being accurately identified or controlled by Prisma Access CASB inline policies due to domain fronting and complex URL structures. Which feature should the administrator configure in Prisma Access to ensure deep application identification and decryption of this traffic?

Medium
40

An enterprise is deploying Prisma Access and wants to ensure that user identity mapping is gathered efficiently from Microsoft Entra ID (formerly Azure AD) without deploying physical User-ID agents inside the cloud network. Which integration method should be used?

Hard
41

A company requires that Prisma Access FWaaS inspects all inter-zone traffic between two different remote branch offices connected via Prisma Access. By default, how does Prisma Access handle traffic between two Remote Networks attached to the same service region?

Hard
42

An enterprise using Prisma Access has configured a Service Connection to their primary data center. Users at remote branches report that they cannot reach internal applications hosted in the data center. Upon checking Panorama, the Service Connection status shows 'Connected', but routing is failing. What configuration step is required on Prisma Access to advertise the remote network subnets to the data center?

Hard
43

An organization requires that all DNS queries from Prisma Access mobile users be inspected and filtered for malicious domains before resolving. Where in Panorama is Prisma Access DNS Security configured?

Hard
44

When configuring Prisma Access for ZTNA 2.0 to control access to private applications, which TWO components or configurations are mandatory for establishing least-privileged application access? (Choose two)

Medium
45

Which security feature in Prisma Access SWG inspects downloaded executable files and documents against a cloud-based behavioral sandbox to identify zero-day malware?

Easy
46

A network engineer is configuring a Service Connection in Prisma Access to connect the cloud security infrastructure back to the corporate data center. Which routing protocol is supported natively by Prisma Access to dynamically exchange routes over the IPsec VPN tunnel?

Medium
47

An organization is deploying Prisma Access for mobile users and needs to ensure that users in Europe connect to European cloud nodes while users in North America connect to North American nodes. How does Prisma Access automatically achieve this geographic routing?

Medium
48

An administrator wants to ensure high availability and resilient connectivity for mobile users connecting to Prisma Access. Which TWO features or mechanisms are utilized by Prisma Access to ensure reliable mobile user access? (Choose two)

Medium
49

An administrator needs to configure Prisma Access Remote Networks to route specific corporate traffic to a local data center while sending internet-bound traffic directly through Prisma Access. Which configuration component in Panorama is used to define this split-tunneling behavior?

Medium
50

An enterprise is planning a Prisma Access deployment and wants to optimize performance and redundancy for Remote Networks. Which THREE best practices should the network architect follow when designing IPsec connections to Prisma Access? (Choose three)

Hard
51

An administrator is troubleshooting a connectivity issue where remote mobile users cannot reach internal private applications via Prisma Access ZTNA. Which THREE diagnostic steps or verification checks should the administrator perform? (Choose three)

Hard
52

An administrator is troubleshooting a CASB inline policy where a specific file upload to an unapproved SaaS application was not blocked. Upon checking the Security policy, the rule has the correct application identified. What is the most likely reason the inline action failed to trigger?

Medium
53

An administrator is setting up Prisma Access logging and monitoring. Which THREE logs or reporting features in Panorama provide insights into SWG, ZTNA, and CASB activities? (Choose three)

Hard
54

An administrator wants to deploy Secure Web Gateway (SWG) capabilities in Prisma Access to prevent users from uploading company proprietary data to unauthorized cloud storage applications. Which Prisma Access profile type should be applied to the Security Policy rules to achieve this?

Easy
55

An administrator wants to configure Prisma Access Secure Web Gateway to block access to sites categorized as 'Gambling' during working hours, but allow them during lunch breaks. Which Panorama feature enables time-based policy enforcement?

Medium

Frequently asked questions

What does the Prisma Access Services domain cover on the SSE-Engineer exam?
Prisma Access Services questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 55 Prisma Access Services questions in the SSE-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Prisma Access Services questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.