SSE-Engineer · domain
Prisma Access Services
Practise Certified Security Service Edge Engineer (SSE-Engineer) Prisma Access Services practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Prisma Access Services questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Prisma Access Services
Prisma Access Services questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Prisma Access Services exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Prisma Access Services questions (55)
Click any question to see the full explanation, or start a practice session above.
An administrator notices that certain mobile users connecting via Prisma Access are experiencing intermittent authentication timeouts when authenticating via SAML 2.0. Where should the administrator check to verify the Identity Provider (IdP) connectivity status and SAML assertion errors within Panorama?
Hard2Which Prisma Access feature enables enterprises to inspect and secure traffic between different virtual networks or cloud environments connected to the cloud service?
Easy3An organization is migrating their branch offices to Prisma Access Firewall as a Service (FWaaS). What is the primary method used to connect a physical branch office location to the Prisma Access cloud infrastructure securely?
Easy4When configuring Prisma Access via Panorama, which administrative role or permission is required to push configuration changes to the cloud infrastructure?
Easy5An administrator configuring Prisma Access ZTNA wants to view real-time metrics regarding active mobile user connections, bandwidth consumption per region, and tunnel status. Which tool provides this specific operational dashboard?
Medium6An administrator is designing a Prisma Access Secure Web Gateway (SWG) and CASB architecture. Which THREE capabilities can be enforced natively through Prisma Access SWG and inline CASB policies? (Choose three)
Hard7Which Prisma Access service capability provides secure, least-privilege remote access for third-party contractors who cannot install the GlobalProtect agent on their managed or unmanaged devices?
Easy8An organization requires that Prisma Access Secure Web Gateway inspects all inbound and outbound TLS traffic for employees browsing external websites. However, HR and healthcare applications must be bypassed due to privacy regulations. Where in Panorama must the administrator configure the exception for these categories?
Medium9An administrator is configuring authentication for Prisma Access mobile users. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)
Medium10An enterprise is deploying Prisma Access Service Connections to connect corporate data centers to the cloud security platform. Which THREE configuration parameters must be correctly specified on Panorama for a Service Connection? (Choose three)
Hard11An administrator is troubleshooting a Prisma Access deployment where mobile users are intermittently disconnected when moving between trusted Wi-Fi networks and cellular connections. Which GlobalProtect client setting in Prisma Access helps maintain session persistence and fast reconnection during network roaming?
Hard12An administrator is configuring Prisma Access Remote Networks to connect branch offices to the cloud security backbone. Which TWO configuration steps are required on Panorama to establish a functional Remote Network connection? (Choose two)
Medium13An administrator is setting up Prisma Access and needs to ensure that mobile users connecting from managed corporate laptops can access internal resources, while unmanaged contractor laptops are restricted to web-based applications only. Which Prisma Access mechanism distinguishes between managed and unmanaged endpoints during connection?
Hard14An administrator is configuring Prisma Access Secure Web Gateway and wants to restrict access to high-risk web categories. Which TWO options represent configurable actions within a Prisma Access URL Filtering profile? (Choose two)
Medium15A security architect is designing a Prisma Access FWaaS deployment and needs to ensure robust security posture across all zones (Mobile Users, Remote Networks, Service Connections, and Internet). Which THREE security profile types should be attached to Security Policy rules to ensure comprehensive threat prevention? (Choose three)
Hard16An administrator is configuring Prisma Access Firewall as a Service (FWaaS) to protect outbound internet traffic from remote networks. They want to ensure that known command-and-control (C2) traffic and vulnerability exploits are blocked dynamically in real time. Which security profile should be applied to the security policy rules?
Medium17A security architect is designing a CASB inline policy in Prisma Access. The requirement is to restrict corporate users from logging into personal instances of sanctioned SaaS applications (e.g., personal Microsoft 365 or Google Workspace) while allowing access to corporate-owned tenants. Which feature enables this control?
Hard18An organization wants to restrict access to a sensitive internal financial database so that only users belonging to the 'Finance-Dept' Active Directory group and connecting from compliant corporate laptops can access it. Which Prisma Access security feature combines user identity, device posture, and application access control?
Medium19A security engineer is configuring a Prisma Access Remote Network location with redundant IPsec tunnels to ensure high availability. What configuration requirement must be met on the customer premise equipment (CPE) router to support dynamic routing over these redundant tunnels?
Medium20Which log category in Prisma Access records events when a user's host information profile (HIP) changes or fails a compliance check?
Easy21An enterprise wants to implement Firewall as a Service (FWaaS) using Prisma Access to protect inter-branch traffic and internet traffic. Which Panorama template type is primarily used to push network and device configurations to Prisma Access nodes?
Easy22An administrator needs to configure Prisma Access ZTNA to verify endpoint hygiene before granting access to internal applications. Which TWO posture checks can be evaluated using GlobalProtect Host Information Profiles (HIP)? (Choose two)
Medium23A deployment of Prisma Access requires ZTNA 2.0 posture check enforcement for remote users. The administrator must ensure that mobile devices attempting to connect to internal corporate apps are evaluated for disk encryption and active endpoint protection agents prior to tunnel establishment. Which component performs this real-time device posture assessment?
Hard24Which component of Prisma Access is responsible for providing centralized management, monitoring, and reporting for all SWG, ZTNA, CASB, and FWaaS features?
Easy25An organization is deploying Prisma Access CASB and Secure Web Gateway features. Which THREE capabilities are provided by Prisma Access Inline CASB compared to out-of-band SaaS Security API? (Choose three)
Hard26A Prisma Access administrator needs to implement ZTNA 2.0 continuous trust verification for mobile users accessing internal private applications. Which feature ensures that continuous validation of both user identity and device posture occurs throughout the session, rather than only at initial authentication?
Hard27A security engineer is troubleshooting a ZTNA connection issue where remote users running GlobalProtect are unable to reach internal applications hosted behind a Prisma Access Remote Network. The mobile users and remote networks are in the same region, but direct branch-to-branch routing is failing. Which Prisma Access feature must be verified to ensure direct traffic flow between mobile users and remote networks without backhauling to the cloud service nodes?
Hard28A security analyst is investigating a Prisma Access FWaaS alert indicating a brute-force attack against an internal server published via a Service Connection. Which security profile should be tuned to detect and block this network-layer attack signature?
Medium29An administrator is configuring Prisma Access Secure Web Gateway and wants to ensure that newly registered malicious domains are blocked automatically without waiting for manual signature updates. Which Palo Alto Networks security service provides real-time IP and domain threat intelligence to Prisma Access?
Medium30An administrator is troubleshooting ZTNA connectivity issues for mobile users connecting via Prisma Access. Which TWO tools or log types in Panorama should the administrator check to diagnose user authentication and tunnel establishment problems? (Choose two)
Medium31An enterprise requires their mobile users to use a Secure Web Gateway (SWG) service that intercepts all web traffic without requiring explicit browser proxy configurations on each client machine. Which Prisma Access deployment method meets this requirement transparently?
Easy32An enterprise is integrating Prisma Access with their corporate infrastructure. Which THREE components can be connected to Prisma Access to provide centralized cloud security inspection? (Choose three)
Hard33A network administrator needs to verify that the QoS (Quality of Service) settings applied to Prisma Access mobile users are prioritizing real-time voice and video traffic correctly. Where are QoS profiles applied in the Prisma Access configuration hierarchy in Panorama?
Hard34An administrator is configuring Prisma Access SWG and needs to implement granular control over file sharing and collaboration tools. Which TWO SaaS Security features can be configured in Prisma Access to achieve this? (Choose two)
Medium35A security engineer is troubleshooting traffic inspection issues in Prisma Access FWaaS. Traffic between two mobile users is bypassing security policy inspection. Which THREE factors could cause intra-zone or inter-user traffic to bypass security inspection in Prisma Access? (Choose three)
Hard36An enterprise wants to ensure that all internet-bound traffic from mobile users is decrypted and inspected for malware and sensitive data using Prisma Access SWG. Which GlobalProtect client traffic forwarding configuration ensures that all traffic is sent to Prisma Access?
Medium37Which log type in Prisma Access should an administrator examine to review details about blocked URLs, category ratings, and user web-browsing attempts?
Easy38When designing a Prisma Access deployment for remote workers, which component authenticates the user and assigns the appropriate GlobalProtect gateway connection based on geographic location?
Easy39An administrator notices that certain SaaS applications are not being accurately identified or controlled by Prisma Access CASB inline policies due to domain fronting and complex URL structures. Which feature should the administrator configure in Prisma Access to ensure deep application identification and decryption of this traffic?
Medium40An enterprise is deploying Prisma Access and wants to ensure that user identity mapping is gathered efficiently from Microsoft Entra ID (formerly Azure AD) without deploying physical User-ID agents inside the cloud network. Which integration method should be used?
Hard41A company requires that Prisma Access FWaaS inspects all inter-zone traffic between two different remote branch offices connected via Prisma Access. By default, how does Prisma Access handle traffic between two Remote Networks attached to the same service region?
Hard42An enterprise using Prisma Access has configured a Service Connection to their primary data center. Users at remote branches report that they cannot reach internal applications hosted in the data center. Upon checking Panorama, the Service Connection status shows 'Connected', but routing is failing. What configuration step is required on Prisma Access to advertise the remote network subnets to the data center?
Hard43An organization requires that all DNS queries from Prisma Access mobile users be inspected and filtered for malicious domains before resolving. Where in Panorama is Prisma Access DNS Security configured?
Hard44When configuring Prisma Access for ZTNA 2.0 to control access to private applications, which TWO components or configurations are mandatory for establishing least-privileged application access? (Choose two)
Medium45Which security feature in Prisma Access SWG inspects downloaded executable files and documents against a cloud-based behavioral sandbox to identify zero-day malware?
Easy46A network engineer is configuring a Service Connection in Prisma Access to connect the cloud security infrastructure back to the corporate data center. Which routing protocol is supported natively by Prisma Access to dynamically exchange routes over the IPsec VPN tunnel?
Medium47An organization is deploying Prisma Access for mobile users and needs to ensure that users in Europe connect to European cloud nodes while users in North America connect to North American nodes. How does Prisma Access automatically achieve this geographic routing?
Medium48An administrator wants to ensure high availability and resilient connectivity for mobile users connecting to Prisma Access. Which TWO features or mechanisms are utilized by Prisma Access to ensure reliable mobile user access? (Choose two)
Medium49An administrator needs to configure Prisma Access Remote Networks to route specific corporate traffic to a local data center while sending internet-bound traffic directly through Prisma Access. Which configuration component in Panorama is used to define this split-tunneling behavior?
Medium50An enterprise is planning a Prisma Access deployment and wants to optimize performance and redundancy for Remote Networks. Which THREE best practices should the network architect follow when designing IPsec connections to Prisma Access? (Choose three)
Hard51An administrator is troubleshooting a connectivity issue where remote mobile users cannot reach internal private applications via Prisma Access ZTNA. Which THREE diagnostic steps or verification checks should the administrator perform? (Choose three)
Hard52An administrator is troubleshooting a CASB inline policy where a specific file upload to an unapproved SaaS application was not blocked. Upon checking the Security policy, the rule has the correct application identified. What is the most likely reason the inline action failed to trigger?
Medium53An administrator is setting up Prisma Access logging and monitoring. Which THREE logs or reporting features in Panorama provide insights into SWG, ZTNA, and CASB activities? (Choose three)
Hard54An administrator wants to deploy Secure Web Gateway (SWG) capabilities in Prisma Access to prevent users from uploading company proprietary data to unauthorized cloud storage applications. Which Prisma Access profile type should be applied to the Security Policy rules to achieve this?
Easy55An administrator wants to configure Prisma Access Secure Web Gateway to block access to sites categorized as 'Gambling' during working hours, but allow them during lunch breaks. Which Panorama feature enables time-based policy enforcement?
MediumOther domains
All SSE-Engineer exam domains
Frequently asked questions
- What does the Prisma Access Services domain cover on the SSE-Engineer exam?
- Prisma Access Services questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 55 Prisma Access Services questions in the SSE-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Prisma Access Services questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.